Skip to content

News

Russian Sandworm hackers pose as Ukrainian telcos to drop malware

Russian Sandworm hackers pose as Ukrainian telcos to drop malware

"The Russian state-sponsored hacking group known as Sandworm (aka: Quedagh, Voodoo Bear, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna) has been observed masquerading as telecommunication providers to target Ukrainian entities with malware." Sandworm is a state-backed threat actor attributed by the US government as part

Members Public
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities

A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities

TrendMicro have recently observed malicious actors exploiting both recently disclosed and older Oracle WebLogic Server vulnerabilities to deliver cryptocurrency-mining malware. Oracle WebLogic Server is typically used for developing and deploying high-traffic enterprise applications on cloud environments and engineered and conventional systems. One of the older vulnerabilities that is still being

Members Public
Russian Cyberwarfare: Unpacking the Kremlin’s Capabilities

Russian Cyberwarfare: Unpacking the Kremlin’s Capabilities

The Center for European Policy Analysis (CEPA) recently published a 38-page study, Russian Cyberwarfare: Unpacking the Kremlin’s Capabilities by two esteemed researchers, Irina Borogan and Andrei Soldatov. The opening premise is that Russia has not demonstrated its cyber warfare adroitness in support of its invasion of Ukraine. Whether the

Members Public
Uber hacked, internal systems breached and vulnerability reports stolen

Uber hacked, internal systems breached and vulnerability reports stolen

Uber suffered a cyberattack Thursday afternoon with an allegedly 18-year-old hacker downloading HackerOne vulnerability reports and sharing screenshots of the company's internal systems, email dashboard, and Slack server. Other systems accessed by the hacker include the company's Amazon Web Services console, VMware vSphere/ESXi virtual machines,

Members Public
Lorenz Ransomware Exploit Mitel VoIP Systems to Breach Business Networks

Lorenz Ransomware Exploit Mitel VoIP Systems to Breach Business Networks

The operators behind the Lornenz ransomware operation have been observed exploiting a now-patched critical security flaw in Mitel MiVoice Connect to obtain a foothold into target environments for follow-on malicious activities. "Initial malicious activity originated from a Mitel appliance sitting on the network perimeter," researchers from cybersecurity firm

Members Public
FBI Warns of Unpatched and Outdated Medical Device Risks

FBI Warns of Unpatched and Outdated Medical Device Risks

The FBI is warning healthcare facilities of the risks associated with unpatched and outdated medical devices. Security flaws in medical devices could adversely impact the operations of healthcare facilities, while also affecting the safety of patients and data confidentiality and integrity, the FBI says. Both hardware design and device software

Members Public
US govt sanctions ten Iranians linked to ransomware attacks

US govt sanctions ten Iranians linked to ransomware attacks

The Treasury Department's Office of Foreign Assets Control (OFAC) announced sanctions today against ten individuals and two entities affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) for their involvement in ransomware attacks. Their malicious activity is tracked and overlaps with state-sponsored hacking groups tracked by cybersecurity

Members Public
Pro-Russian Hacktivist Groups Target Ukraine Supporters

Pro-Russian Hacktivist Groups Target Ukraine Supporters

As the war in Ukraine rages on, unseen but related battles occur daily across the globe. These confrontations stem from pro-Russian hacktivist groups targeting countries that support Ukraine, likely with support from the Kremlin. These hacktivists have been targeting a wide swath of industries and sectors, including aviation, energy, financial,

Members Public
Opsec Mistakes Reveal Iranian COBALT MIRAGE Threat Actors

Opsec Mistakes Reveal Iranian COBALT MIRAGE Threat Actors

Artifacts exposed personas and companies associated with the Iranian threat group. Secureworks® Counter Threat Unit™ (CTU) analysis of a June 2022 ransomware incident revealed details about Iranian COBALT MIRAGE threat group operations. Despite CTU™ researchers publicly disclosing COBALT MIRAGE tactics, techniques, and procedures (TTPs) in May 2022, the threat actors

Members Public
Chinese hackers create Linux version of the SideWalk Windows malware

Chinese hackers create Linux version of the SideWalk Windows malware

State-backed Chinese hackers have developed a Linux variant for the SideWalk backdoor used against Windows systems belonging to targets in the academic sector. The malware is attributed with high confidence to the SparklingGoblin threat group, also tracked as Earth Baku, which is believed to be connected to the APT41 cyberespionage

Members Public