Advertisement
Telegram tdata Credential Harvesting: Risks and Mitigation Strategies
Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.
Microsoft Defender Binaries Exploited as Attack Tools
Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.
Mustang Panda Targets Indian Banks with New LOTUSLITE Variant
Mustang Panda deploys a new LOTUSLITE malware variant against Indian financial institutions and South Korean policy entities for cyber espionage operations.
BlackCat Ransomware Negotiator Scheme: Insider Threat Implications
A ransomware negotiator's guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.
Scattered Spider Member Tylerb Pleads Guilty: Smishing Analysis
Tyler Robert Buchanan's guilty plea exposes Scattered Spider smishing tactics that compromised 12+ tech firms and stole millions in cryptocurrency.
Security Expert Aids BlackCat Ransomware, Exposing IR Risks
A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.
Advertisement
SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.
Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks
Angelo Martino pleaded guilty to collaborating with BlackCat (ALPHV) ransomware operators, facilitating credential-based breaches and high-stakes negotiations.
Grupo Seguritech: Risks of Mexico’s Surveillance Expansion
An analysis of Grupo Seguritech's expansion into the US market, evaluating the security and privacy implications of international surveillance infrastructure.
Chinese APT Targeting Indian Banks and Korean Policy Circles
Chinese state-sponsored threat actors are conducting cyber-espionage against Indian financial institutions and South Korean policy entities using recycled TTPs.
Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks
A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.
Satoshi Nakamoto Identity: Adam Back and Bitcoin's Origins
Explores the resurfaced speculation that Adam Back is Satoshi Nakamoto, examining the evidence and implications for Bitcoin's ethos.
KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group
KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.
WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies
WhatsApp's metadata leakage allows strangers to infer limited user information without interaction, potentially aiding targeted social engineering or other malicious…
Scattered Spider Member Tyler Buchanan Pleads Guilty in US
Tyler Buchanan, a British national linked to the Scattered Spider cybercrime group, pleaded guilty in the US to charges of hacking, fraud, and cryptocurrency theft.
Beyond Backups: Essential BCDR for Ransomware & Operational Resilience
Learn why traditional data backups are insufficient for business continuity. This analysis highlights the critical role of BCDR in mitigating ransomware and outage…
Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs & Mitigations
Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.
Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks
Analysis of the Vercel infrastructure compromise, QEMU-based evasion techniques, and the rise of Android RATs leveraging update channels for delivery.
ZionSiphon Malware: Detecting OT Threats to Israeli Water Systems
ZionSiphon malware targets Israeli water treatment and desalination infrastructure, establishing persistence and scanning local subnets for OT services.
Apple ID Alerts Abused for Phishing via Legitimate Servers
Threat actors are exploiting Apple's account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.
Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec
Analysis of Tycoon 2FA's declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.
Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack
Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.
Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet
Security researchers identify Nexcorium, a new Mirai variant targeting TBK DVRs and EoL TP-Link routers via CVE-2024-3721 for large-scale DDoS attacks.
Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA
Tycoon 2FA Phishers are now leveraging device code phishing to bypass multi-factor authentication, granting them unauthorized account access.