Blog
New Bifrost Variant Uses Domain Deception Tactic to Deceive Users
The latest variant of BIFROSE masquerades as VMware by reaching out to a deceptive domain. There has been a spike in BIFROSE activity since October 2023, and a new Arm version of the malware has been discovered.
Researchers Found a Zero-Click Facebook Account Takeover
The critical vulnerability in Facebook's password reset process involved a rate-limiting issue in a specific endpoint, which could be exploited to brute-force a nonce and gain access to a user's account.
Update: Irish Foreign Affairs Ministry Says ‘No Evidence’ of Cyber Breach Following Extortion Claim
The Department of Foreign Affairs in Ireland has found no evidence to support the claim of a cyber extortion group called Mogilevich that it stole data from their IT systems.
New Phishing Kit Leverages SMS, Voice Calls to Target Cryptocurrency Users
A novel phishing kit has been observed impersonating the login pages of well-known cryptocurrency services as part of an attack cluster designed to primarily target mobile devices. “This kit enables attackers to build carbon copies of single sign-on (SSO) pages, then...
Abyss Locker Ransomware Attacks Both Windows And Linux Users
This ransomware steals and encrypts files, demanding ransom for decryption and not releasing stolen data. It is based on the HelloKitty ransomware source code and has been observed in various regions.
Abyss Locker Ransomware Attacks Both Windows And Linux Users
This ransomware steals and encrypts files, demanding ransom for decryption and not releasing stolen data. It is based on the HelloKitty ransomware source code and has been observed in various regions.
New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion
Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost) that uses a deceptive domain mimicking VMware. "This latest version of Bifrost aims to bypass security measures and compromise targeted systems,"...
4 Instructive Postmortems on Data Downtime and Loss
More than a decade ago, the concept of the ‘blameless’ postmortem changed how tech companies recognize failures at scale. John Allspaw, who coined the term during his tenure at Etsy, argued postmortems were all about controlling our natural reaction to an incident,...
Chinese PC-Maker Acemagic Shipped Machines Infected with Malware
The company attributed the infection to software adjustments made by developers to reduce boot times, which inadvertently affected network settings and omitted digital signatures.
Epic Games Says “Zero Evidence” of Hacking by Mogilevich Gang
Epic Games found no evidence of a cyberattack or data theft after the Mogilevich group claimed to have breached their servers. The group offered to sell stolen data for $15,000 but only shared samples with those who proved they had the funds.
FREE GUIDE