Tricky CAPTCHA Caught Dropping Lumma Stealer Malware

October 22, 2024 at 12:31PM Lumma Stealer has launched a campaign using malicious CAPTCHA pages to prompt malware downloads. This malware aims to steal sensitive data. Researchers emphasize the need for security teams to adopt continuous monitoring and adapt defenses against evolving threats like Lumma Stealer, using a multilayered approach for effective protection. ### Meeting … Read more

Akira ransomware is encrypting victims again following pure extortion fling

October 22, 2024 at 11:36AM Akira ransomware is returning to traditional encryption tactics after a hiatus from double extortion. Researchers note a shift towards operational efficiency and tactical adaptability, suspecting the development of a new encryptor. Akira targets vulnerabilities, particularly on ESXi and Linux systems, leveraging compromised credentials and phishing techniques to exploit networks. ### … Read more

Latrodectus Malware Increasingly Used by Cybercriminals

October 22, 2024 at 06:45AM SecurityWeek offers comprehensive coverage of cybersecurity news, including threats, data breaches, and risk management. The platform also features webcasts, virtual events, and an ICS Cybersecurity Conference. Subscribe to their Daily Briefing Newsletter for updates on the latest cybersecurity insights and trends. Unsubscription is available anytime. ### Meeting Takeaways **1. Overview … Read more

Attackers Target Exposed Docker Remote API Servers With perfctl Malware

October 21, 2024 at 11:30AM Attacks on exposed Docker Remote API servers deploy the perfctl malware through probing and payload execution. Attackers create containers, execute Base64 encoded payloads, and use evasion tactics to avoid detection. Recommendations to enhance security include strong access controls, regular monitoring, and adherence to container security best practices. ### Meeting Takeaways … Read more

THN Cybersecurity Recap: Top Threats, Tools and News (Oct 14 – Oct 20)

October 21, 2024 at 08:24AM This week’s cybersecurity recap highlights increasing hacker tactics targeting seemingly secure systems while security experts develop advanced protective measures. Notable incidents include Apple’s macOS flaw and the weaponization of legitimate tools. Keeping devices updated is essential for protection. The FIDO Alliance aims to enhance passkey transfer across platforms. ### Meeting … Read more

North Korean APT Exploited IE Zero-Day in Supply Chain Attack

October 18, 2024 at 07:25AM SecurityWeek provides extensive coverage of cybersecurity topics, including malware, cyberwarfare, data breaches, and various security domains like IoT and cloud security. It also offers events, webcasts, and newsletters for staying updated on the latest threats and expert insights, along with resources like the ICS Cybersecurity Conference and CISO forums. **Meeting … Read more

BianLian ransomware claims attack on Boston Children’s Health Physicians

October 17, 2024 at 11:39AM The BianLian ransomware group has attacked Boston Children’s Health Physicians, threatening to release stolen data unless a ransom is paid. The breach affects current and former employees, patients, and guarantors, exposing sensitive information. BHCP notified affected individuals and confirmed their electronic medical records remain secure. ### Meeting Takeaways: 1. **Ransomware … Read more

Top 5 Cloud Security Automations for SecOps Teams

October 17, 2024 at 10:39AM Blink Ops automates security operations, transforming tedious tasks into efficient workflows. By integrating with platforms like AWS and Wiz, it allows users to monitor vulnerabilities, detect incidents, and enforce S3 encryption easily. This automation helps security teams save time and minimize human error while focusing on critical security initiatives. ### … Read more

Iranian Hackers Use Brute Force in Critical Infrastructure Attacks

October 17, 2024 at 07:39AM SecurityWeek Network offers comprehensive cybersecurity news, resources, and events, including webcasts and the ICS Cybersecurity Conference. Topics covered range from malware and ransomware to data protection and risk management. Subscribe for daily updates on threats and industry insights or opt-out anytime. ### Meeting Takeaways 1. **Cybersecurity News**: SecurityWeek offers the … Read more

Organizations Warned of Exploited SolarWinds Web Help Desk Vulnerability

October 16, 2024 at 06:19AM SecurityWeek offers extensive coverage of cybersecurity topics, including threats, incidents, and strategies. It features webcasts, events, and resources related to various sectors like industrial cybersecurity and risk management. Users can subscribe to a daily briefing newsletter for updates or unsubscribe at their convenience. ### Meeting Takeaways 1. **Overview of SecurityWeek … Read more