CISA: AWS, Microsoft 365 Accounts Under Active ‘Androxgh0st’ Attack

January 17, 2024 at 01:21PM The FBI and CISA have issued an alert about a malware campaign targeting Apache webservers and websites using the Laravel Web application framework. The campaign aims to steal credentials for high-profile applications such as AWS, Microsoft 365, Twilio, and SendGrid. The threat actors use a known malware called “Androxgh0st” to … Read more

Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows

January 15, 2024 at 11:44AM The Guardio Labs research team has revealed a security flaw, dubbed MyFlaw, in the Opera web browser for Windows and macOS, allowing execution of files on the operating system. The flaw exploits the My Flow feature, prompting updates on Nov 22, 2023, to address it. The vulnerability emphasizes the need … Read more

Turkish APT ‘Sea Turtle’ Resurfaces to Spy on Kurdish Opposition

January 9, 2024 at 12:38PM A group affiliated with the Turkish government has increased politically driven cyber-espionage activities targeting Kurdish opposition groups in Europe, the Middle East, and North Africa. Sea Turtle, previously dormant, has resurfaced, carrying out campaigns targeting organizations in the Netherlands. The attacks focus on reaching websites associated with Kurds and the … Read more

Albanian Parliament and One Albania Telecom Hit by Cyber Attacks

December 29, 2023 at 09:30AM Albanian government institutions and telecom company One Albania were recently hit by cyber attacks, according to the country’s cyber security authority. One Albania assured that its services were unaffected. The attacks, attributed to an Iranian hacker group, have prompted a review and strengthening of cyber security strategies. This follows previous … Read more

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

December 22, 2023 at 12:42PM A rogue WordPress plugin discovered by threat hunters poses a Magecart campaign threat, creating bogus admin users and injecting malicious code to steal credit card data. The plugin hides in the mu-plugins directory and enables sustained access to the target. This revelation comes amid growing concerns about digital skimming and … Read more

ESET Patches High-Severity Vulnerability in Secure Traffic Scanning Feature

December 21, 2023 at 08:33AM ESET releases patches to fix a high-severity vulnerability in its endpoint and server security products. The flaw, CVE-2023-5594, affected the SSL/TLS protocol scanning feature and could make web browsers trust untrustworthy sites. The patch is automatically rolling out via product updates since November 21, with no user interaction required. ESET … Read more

Mozilla decides Trusted Types is a worthy security feature

December 21, 2023 at 06:06AM Mozilla has revised its position to implement Trusted Types in its Firefox browser, aiming to decrease web attacks relying on injected code. This technology addresses DOM-XSS, reducing the common vulnerability. Still undergoing technical improvements, it’s expected to enhance web security when widely adopted. Tech giants like Google, Meta, and Microsoft … Read more

New ‘GambleForce’ Threat Actor Behind String of SQL Injection Attacks

December 14, 2023 at 05:20PM Group-IB has detected a new threat group, “GambleForce,” engaged in SQL injection attacks on organizations in the Asia-Pacific region. This group has targeted various sectors, including gambling, government, retail, travel, and job websites, using publicly available penetration-testing tools. The threat actor’s activities have led to data breaches in multiple organizations, … Read more

New Hacker Group ‘GambleForce’ Tageting APAC Firms Using SQL Injection Attacks

December 14, 2023 at 02:18AM From September 2023, hacker group GambleForce conducted SQL injection attacks in APAC, targeting 24 organizations in gambling, government, retail, and travel sectors. They used tools like dirsearch, sqlmap, and Cobalt Strike, and exploited a Joomla CMS flaw. Group-IB discovered and took down the group’s C2 server and notified the victims. … Read more

Apple emergency updates fix recent zero-days on older iPhones

December 11, 2023 at 02:28PM Apple has issued emergency security updates for two zero-day flaws in iOS, iPadOS, tvOS, and watchOS. The CVE-2023-42916 and CVE-2023-42917 vulnerabilities in the WebKit browser engine allowed attackers to access sensitive data and execute arbitrary code. Security researcher Clément Lecigne discovered and reported both flaws. CISA ordered Federal Civilian Executive … Read more