Blog
NS-STEALER Uses Discord Bots to Exfiltrate Your Secrets from Popular Browsers
The malware exfiltrates sensitive information including screenshots, cookies, autofill credentials, system info, installed programs, tokens, and sessions, and uploads the collected data to a Discord bot channel.
~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active Exploitation
Malicious actors have begun to actively exploit a recently disclosed critical security flaw impacting Atlassian Confluence Data Center and Confluence Server, within three days of public disclosure. Tracked as CVE-2023-22527 (CVSS score: 10.0), the vulnerability...
Finland: Prosecutors Add to Evidence Against Alleged Vastaamo Hacker
Prosecutors have traced the cryptocurrency wallet used for extortion to the bank account of Aleksanteri Kivimäki, the accused in the psychotherapy clinic data breach case.
New Chae$ 4.1 Malware Hides in Driver Downloads
The infection chain begins with deceptive emails and websites, ultimately leading to the activation of the Chae$ 4.1 malware, highlighting the importance of cautious online behavior.
Info Stealing Packages Hidden in PyPI
Malicious Python packages on PyPI, such as nigpal, figflix, and seGMM, have been identified, with payloads designed to steal sensitive information from victims' devices, particularly targeting Windows users.
Update: Hackers Start Exploiting Critical Atlassian Confluence RCE Flaw
Organizations with outdated Confluence instances should treat them as potentially compromised, look for signs of exploitation, perform a thorough cleanup, and update to a safe version to mitigate the risk.
Apple Issues Patch for Critical Zero-Day in iPhones, Macs – Update Now
Apple on Monday released security updates for iOS, iPadOS, macOS, tvOS, and Safari web browser to address a zero-day flaw that has come under active exploitation in the wild. The issue, tracked as CVE-2024-23222, is a type confusion bug that could be exploited by a...
North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor
Media organizations and high-profile experts in North Korean affairs have been at the receiving end of a new campaign orchestrated by a threat actor known as ScarCruft in December 2023. "ScarCruft has been experimenting with new infection chains, including the use of...
MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries
Several public and popular libraries abandoned but still used in Java and Android applications have been found susceptible to a new software supply chain attack method called MavenGate. "Access to projects can be hijacked through domain name purchases and since most...
DDoS Barrage Hits Monobank, Ukraine’s Largest Mobile Bank, in Unprecedented Attack
A series of denial of service (DDoS) attacks hit Monobank, Ukraine's largest mobile-only bank, with the CEO confirming a staggering 580 million service requests during one attack.
FREE GUIDE