Have some tips? Write it down and share it to your friends!
Click Login Now button to start!
News
Cyber Security Related News
A recent phishing campaign targets U.S. organizations, aiming to deploy the NetSupport RAT, a remote access trojan. Tracked by Israeli cybersecurity firm Perception Point as Operation PhantomBlu, this campaign employs a sophisticated method by exploiting Microsoft Office's Object Linking and Embedding (OLE) template manipulation to execute malicious code, avoiding detection. NetSupport RAT, derived from the legitimate tool NetSupport Manager,...
March 26, 2024 01:49 (on 3/26/24) | 0 |
2 minutes read
Cybersecurity researchers have identified critical vulnerabilities within the third-party plugin ecosystem for OpenAI ChatGPT, shedding light on potential avenues for threat actors to exploit and gain unauthorized access to sensitive data. Recent findings from Salt Labs highlight security flaws within the ChatGPT platform itself and its accompanying plugin infrastructure, posing significant risks to user privacy and data...
March 18, 2024 22:17 (on 3/19/24) | 0 |
2 minutes read
The U.S. Department of Justice (DoJ) has unveiled charges against Linwei Ding, a 38-year-old Chinese national, and a California resident, for their alleged involvement in stealing proprietary information from Google while clandestinely collaborating with two Chinese tech firms. The indictment alleges that Ding, a former Google engineer, clandestinely siphoned off sensitive trade secrets to his account, facilitating the Chinese companies'...
March 13, 2024 01:25 (on 3/13/24) | 0 |
2 minutes read
A U.S. judge has mandated that NSO Group relinquish its source code for Pegasus and other remote access trojans to Meta as part of Meta's ongoing legal dispute with the Israeli spyware vendor.
This decision represents a significant legal triumph for Meta, which initiated the lawsuit in October 2019, accusing NSO Group of exploiting its infrastructure to distribute spyware to roughly 1,400...
March 4, 2024 22:13 (on 3/5/24) | 0 |
2 minutes read
Meta Platforms has disclosed a comprehensive set of measures aimed at curtailing the activities of eight companies operating within the surveillance industry across Italy, Spain, and the United Arab Emirates. These actions were detailed in Meta's Adversarial Threat Report for the fourth quarter of 2023 and were specifically designed to address the proliferation of spyware targeting devices running iOS, Android, and Windows operating systems. The...
February 19, 2024 19:47 (on 2/20/24) | 2 |
3 minutes read
Since early 2023, a clandestine threat group known as ResumeLooters has been systematically targeting employment agencies and retail companies, predominantly located within the Asia-Pacific (APAC) region. This group's nefarious activities, previously undocumented, have caught the attention of cybersecurity experts at Singapore-based Group-IB. Their analysis reveals a sophisticated operation aimed at stealing sensitive data for financial...
February 12, 2024 20:50 (on 2/13/24) | 0 |
2 minutes read
Google has launched a new pilot program in Singapore aimed at bolstering security measures against the installation of certain Android apps that exploit permissions to gain unauthorized access to sensitive data and one-time passwords. This initiative, integrated into Google Play Protect, seeks to automatically block the installation of such apps when users attempt to download them from external sources like web browsers, messaging apps, or file...
February 8, 2024 19:27 (on 2/9/24) | 0 |
2 minutes read
Chinese users face a targeted malvertising campaign through malicious Google ads promoting restricted messaging apps like Telegram. Malwarebytes' Jérôme Segura revealed that threat actors exploit Google advertiser accounts to create these deceptive ads, leading users to download Remote Administration Trojans (RATs). The ongoing campaign, known as FakeAPP, is a continuation of a prior assault that initially targeted Hong Kong users searching for...
January 29, 2024 20:18 (on 1/30/24) | 0 |
2 minutes read
On Friday, Microsoft publicly disclosed that it had fallen victim to a sophisticated nation-state attack targeting its corporate systems. This breach resulted in the unauthorized access and theft of emails and attachments belonging to senior executives, as well as individuals within the company's cybersecurity and legal departments. The orchestrator of this attack was identified as the Russian advanced persistent threat group Midnight Blizzard,...
January 22, 2024 20:42 (on 1/23/24) | 0 |
2 minutes read
Thousands of WordPress websites, utilizing an insecure version of the Popup Builder plugin, have fallen victim to a malware named Balada Injector. Discovered by Doctor Web in January 2023, the attack operates through periodic waves exploiting vulnerabilities in WordPress plugins. These attacks insert backdoors designed to redirect visitors to deceptive tech support pages, fake lottery winnings, and push notification scams. Sucuri's subsequent...
January 15, 2024 19:56 (on 1/16/24) | 1 |
2 minutes read