August 05, 2022
New attack framework Manjusaka is similar to Cobalt Strike
Researchers have observed a new post-exploitation attack framework in the wild. Manjusaka, as it's called, can be deployed as an alternative to the popular Cobalt Strike toolset — or parallel to it for redundancy.
July 30, 2022
Report: Attackers scan for vulnerabilities within 15 minutes of CVE disclosure
A new report from Palo Alto's Unit 42 found it only takes 15 minutes after the publication of a new CVE for the first cybercriminals to begin scanning potentially vulnerable targets. Within a few hours, the first active exploitation attempts have already started.
July 29, 2022
QBot malware uses Windows Calculator to side-load attacks
Security researchers have discovered that QBot malware is now using the legitimate Windows Calculator app for DLL side-loading attacks. The method continues to be used in current malspam campaigns.
July 29, 2022
LockBit ransomware hits numerous victims, including two townships
The Canadian town of St. Marys, Ontario, has been hit by a ransomware attack that locked staff out of internal systems and encrypted data. The small town of around 7,500 residents appears to be the second such target to be attacked by LockBit in just over a week.
July 27, 2022
Version 4.2 of malicious shortcut generator MLNK Builder emerges on dark web
A new version of MLNK Builder, a link generation tool popular among cybercriminals, has emerged on the dark web. The updated feature set focuses on antivirus evasion and masquerading techniques, using icons of popular legitimate applications and file formats.
July 26, 2022
Symbiote: A new stealthy malware for Linux
Symbiote is a new Linux malware that steals users’ data and provides a backdoor to threat actors. It was discovered in June, 2022 and is characterized as a very stealthy malware. It uses a lot of evasion techniques, such as hooking functions, capturing TCP traffic and hiding its own files. It collects users' data and exfiltrates it on DNS servers.
July 25, 2022
Building materials firm Knauf hit by Black Basta ransomware
The Knauf Group, a German-based multinational producer of construction materials, has announced that it's been the target of a cyberattack. The incident took place on the night of June 29, forcing its global IT team to shut down email systems, although communications were still possible via mobile devices and Microsoft Teams.
July 25, 2022
European data centers running hot
An ongoing heatwave in Europe has sent temperatures above 40 degrees Celsius / 110 degrees Fahrenheit. Among other problems, this has stressed cooling systems at various data centers across the continent. Oracle and Google have both had to contend with heat-related failures in their UK cloud data centers.
July 22, 2022
CloudMensis: a new macOS threat
In April 2022, ESET researchers found a yet-unknown backdoor on macOS. It was named CloudMensis due to the fact that it uses different public cloud storage for C2
communication. CloudMensis looks for different types of documents, captures keyboard input, searches local emails and can take screen captures.
July 19, 2022
U.S. healthcare organizations targeted with Maui ransomware
The FBI, CISA and U.S. Department of the Treasury have issued a joint advisory warning of alleged North-Korean-backed threat actors using Maui ransomware in attacks against healthcare and public health (HPH) organizations.
July 19, 2022
Bandai Namco hit by BlackCat ransomware
The Japanese video game giant Bandai Namco, known for publishing franchises like Elden Ring, Pac-Man and Tekken, has been hit by BlackCat/AlphV ransomware.
July 19, 2022
IT services giant SHI hit by cyberattack
SHI International, one of the world’s 15 largest IT service providers (with over 5,000 employees and annual sales of $12.3 billion in 2021), has fallen victim to a "coordinated and professional malware attack."