Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

SideWinder Uses Server-side Polymorphism to Attack Pakistan Government Officials — and Is Now Targeting Turkey

May 3, 2023October 14, 2025 Securonix

SideWinder has been observed employing server-side polymorphism to deliver campaigns against Pakistan government officials, and the operation is now targeting Turkey. Campaigns rely on dynamically generated payloads delivered via malicious RTF attachments and …

Read More
Threat Research

AndoryuBot – New Botnet Campaign Targets Ruckus Wireless Admin Remote Code Execution Vulnerability (CVE-2023-25717)b| FortiGuard Labs

May 3, 2023October 14, 2025 Securonix

Fortinet FortiGuard Labs documents a new botnet named AndoryuBot that targets Ruckus Wireless Access Points via CVE-2023-25717 to gain control of devices. The malware then uses a SOCKS-based C2, downloads a propagation script, and implements DDoS capabilities.…

Read More
Threat Research

Promising Jobs at the U.S. Postal Service, ‘US Job Services’ Leaks Customer Data – Krebs on Security

May 1, 2023October 16, 2025 Securonix

A Georgia-based online operation promised USPS jobs and exposed a backend database with nearly 900,000 customers. Investigators traced the scheme to US Job Services and Next Level Support, with ties to a Pakistan-based developer and a Tennessee telemarketing f…

Read More
Threat Research

Cyble – Sophisticated DarkWatchMan RAT Spreads Through Phishing Sites

May 1, 2023October 22, 2025 Securonix

DarkWatchman is spread via phishing sites that imitate CryptoPro CSP to deliver the malware, which stores data in the Windows Registry and uses a staged execution flow to deploy a RAT and a keylogger while avoiding disk writes. The campaign targets Russian use…

Read More
Threat Research

Uncovering drIBAN fraud operations 1 | Cleafy Labs

May 1, 2023October 21, 2025 Securonix

drIBAN is a web-inject kit used in Italian corporate banking fraud, paired with the sLoad loader to infect Windows workstations and bypass anti-fraud measures. The operation evolved into an APT-like campaign with persistence, LOLBins, DNS checks, and Ramnit pa…

Read More
Threat Research

Clean Rooms, Nuclear Missiles, and SideCopy, Oh My! | FortiGuard Labs

May 1, 2023October 17, 2025 Securonix

Fortinet researchers detail a SideCopy-linked operation that uses decoys and HTA-based payloads to deploy a multi-stage Windows malware chain aimed at defense-sector targets. The campaign blends phishing, LOL decoys, DLL side-loading, in-memory execution, and …

Read More
Threat Research

Netskope Threat Coverage: CrossLock Ransomware

May 1, 2023October 20, 2025 Securonix

CrossLock is a Go-based ransomware group that emerged in April 2023, targeting a Brazilian digital certifier and operating with a Go-based encryptor. It uses a double-extortion model by threatening to leak stolen data on a deep web site if the ransom isn’t pai…

Read More
Threat Research

A doubled “Dragon Breath” adds new air to DLL sideloading attacks

May 1, 2023October 16, 2025 Securonix

Two-stage DLL sideloading campaigns build on classic sideloading by introducing a second clean application that auto-executes a malicious loader, which then runs the final payload. The operation, linked to Dragon Breath/Golden Eye Dog, targets online-gambling …

Read More
Threat Research

Cyble – New KEKW Malware Variant Identified In PyPI Package Distribution

May 1, 2023October 16, 2025 Securonix

Cyble Research and Intelligence Labs (CRIL) uncovered a KEKW malware variant spreading via malicious PyPI wheel packages, combining stealer and clipper capabilities to harvest browser data and hijack cryptocurrency transactions. Python security teams quickly r…

Read More
Threat Research

New Mustang Panda’s campaing against Australia

April 30, 2023October 17, 2025 Securonix

Mustang Panda-linked actors are linked to a targeted campaign against Australia amid the AUKUS security pact, using a ZIP-based lure that delivers a DLL payload via DLL side-loading to achieve persistence and enable PlugX deployment. The operation highlights C…

Read More
Threat Research

The malware threat landscape: NodeStealer, DuckTail, and more

April 30, 2023October 17, 2025 Securonix

Security researchers detail persistent malware campaigns like NodeStealer and Ducktail that abuse browser extensions, ads, and social media to compromise business accounts and run unauthorized ads. They describe how these custom families persist, steal browser…

Read More
Threat Research

BouldSpy: Android Spyware Tied to Iranian Police Targets Minorities | Threat Intel

April 27, 2023October 17, 2025 Lookout

Lookout researchers uncovered BouldSpy, an Android surveillance tool attributed with moderate confidence to Iran’s Law Enforcement Command (FARAJA) that has been used to target minorities and collect extensive device data. The spyware installs via physical acc…

Read More
Threat Research

HiddenAds Spread via Android Gaming Apps on Google Play | McAfee Blog

April 27, 2023October 17, 2025 McAfee

Authored by Dexter Shin  Minecraft is a popular video game that can be played on a desktop or mobile. This…
The post HiddenAds Spread via Android Gaming Apps on Google Play appeared first on McAfee Blog….

Read More
Threat Research

Raspberry Robin: A global USB malware campaign providing access to ransomware operators

April 27, 2023October 18, 2025 Securonix

Raspberry Robin is a global USB-based malware campaign that acts as a loader, delivering ransomware operators and other loaders to target networks. It propagates via infected USB drives, uses legitimate Windows binaries to execute payloads, and relies on compr…

Read More
Threat Research

Polish Healthcare Industry Targeted by Vidar Infostealer Likely Linked to Djvu Ransomware

April 27, 2023October 15, 2025 Securonix

Two sentences summarizing the content here. EclecticIQ links a spearphishing campaign against Poland’s healthcare sector to Vidar Infostealer, with overlaps to Djvu and LockBit 2.0 ransomware activity, and describes how Vidar collects sensitive data and exfilt…

Read More

Posts pagination

Previous 1 … 410 411 412 … 490 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.