North Korea's Lazarus Group Deploys New Kaolin RAT via Fake Job Lures.
The North Korea-linked threat actor known as Lazarus Group employed its time-tested fabricated job lures to deliver a new remote access trojan called Kaolin RAT as part of attacks targeting individuals.
Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites
Threat actors are attempting to actively exploit a critical security flaw in the ValvePress Automatic plugin for WordPress that could allow site takeovers.
Palo Alto Networks Outlines Remediation for Critical PAN-OS Flaw Under Attack
Palo Alto Networks has shared remediation guidance for a recently disclosed critical security flaw impacting PAN-OS that has come under active exploitation.
New 'Brokewell' Android Malware Spread Through Fake Browser Updates
Fake browser updates are being used to push a previously undocumented Android malware called Brokewell.
05 Critical Endpoint Security Tips You Should Know
1. Know Your Endpoints
2. Develop a Proactive Patch Strategy #
3. Add an Extra Layer of Defense with MFA#
4. Embrace the Principle of Least Privilege#
5. Layer Up Your Endpoint Defenses#
Severe Flaws Disclosed in Brocade SANnav SAN Management Software
Several security vulnerabilities disclosed in Brocade SANnav storage area network (SAN) management application could be exploited to compromise susceptible appliances.
Bogus npm Packages Used to Trick Software Developers into Installing Malware
An ongoing social engineering campaign is targeting software developers with bogus npm packages under the guise of a job interview to trick them into downloading a Python backdoor.
Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw
Cybersecurity researchers have discovered a targeted operation against Ukraine that has been found leveraging a nearly seven-year-old flaw in Microsoft Office to deliver Cobalt Strike on compromised systm
Okta Warns of Unprecedented Surge in Proxy-Driven Credential Stuffing Attacks
Identity and access management (IAM) services provider Okta has warned of a spike in the "frequency and scale" of credential stuffing attacks aimed at online services.
PlanetStealer is announced It steals passwords, cookies, autofills, crypto wallet files, config files and more. Price: $75 (1 week), $200 (1 month) #DarkWeb
#Spain ๐ช๐ธ - Allegedly, Database of a notary collage in Spain is on sale Threat actor claims to have 150GB of sensitive documents, including 400 passports, contracts and more. Starting price: $1000 #DarkWeb
A threat actor claims to be selling root (Windows and database) access to a European gambling company The company has a revenue of $5 billion. Price: $55,000 #DarkWeb
The New Ransomware Victim of CLOP: https://t.co/mAbQCB40d4 ---- DailyDarkWeb ------ Group: #CLOPCompany: http://THAISUMMIT.USCountry: # Description: Thai Summit Group is a manufacturer of automotive metal forming, ... Date: 2024-03-03 #DarkWeb#Darkweb_info
The New Ransomware Victim of CLOP: https://t.co/TsuXpxAqHN ---- DailyDarkWeb ------ Group: #CLOPCompany: http://THESAFIRCHOICE.COMCountry: # Description: Our experienced trial attorneys will expertly guide you through t... Date: 2024-03-03 #DarkWeb
The New Ransomware Victim of MEDUSA: Sophiahemmet University ---- DailyDarkWeb ------ Group: #MEDUSACompany: Sophiahemmet University Country: # Description: ... 30 Asia 2016 list. She is also trained in palliative care phi... Date: 2024-03-03 #DarkWeb
The New Ransomware Victim of MEDUSA: Chris Argiropoulos Professiona ---- DailyDarkWeb ------ Group: #MEDUSACompany: Chris Argiropoulos Professiona Country: # Description: Feb 18, 2024 ... Realcrowd crunchbase meerkat. Fiber speed test n... Date: 2024-03-03 #DarkWeb