Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Cyble – Print Management Software PaperCut Actively Exploited In The Wild

April 21, 2023October 16, 2025 Securonix

PaperCut CVE-2023-27350 and CVE-2023-27351 allow remote code execution and authentication bypass on PaperCut MF/NG servers, with unpatched systems actively exploited in the wild. The article highlights PoC dispersion via hacktivist channels and rising ransomwa…

Read More
Threat Research

Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware

April 21, 2023October 14, 2025 Securonix

BellaCiao is a highly customized dropper linked to Charming Kitten (APT35) that targets US, European, Middle Eastern, and Indian victims with victim-specific data and C2 communication. The implant combines a tailored payload, a DNS-based command channel, and m…

Read More
Threat Research

Activity Targeting Crypto Asset Exchangers for Parallax RAT Infection – JPCERT/CC Eyes

April 20, 2023October 17, 2025 admin

JPCERT/CC documented an attack around February 2023 that targeted a crypto asset exchanger with Parallax RAT delivered via spam emails directing victims to a Google Drive link. The operation used OneNote files with embedded VBS, a PowerShell payload, Windows s…

Read More
Threat Research

Educated Manticore – Iran Aligned Threat Actor Targeting Israel via Improved Arsenal of Tools – Check Point Research

April 20, 2023October 21, 2025 Securonix

Educated Manticore is an Iran-aligned threat cluster that has evolved its toolset to deploy a newer PowerLess variant via ISO-based lures targeting Israel. The operation uses a multi-stage infection chain with a mixed-mode .NET loader and in-memory execution t…

Read More
Threat Research

Package names repurposed to push malware on PyPI

April 20, 2023October 15, 2025 Securonix

A malicious PyPI package named termcolour reappeared in March as a three-stage downloader, illustrating how repurposing an abandoned package name can seed a supply-chain attack. The incident shows how PyPI’s name-reuse policy and lack of visibility into who re…

Read More
Threat Research

Tomiris called, they want their Turla malware back

April 20, 2023October 14, 2025 Securonix

Tomiris is a Russian-speaking threat actor whose operations target CIS government and diplomatic entities, deploying a wide range of burners, backdoors, and file stealers across multiple campaigns and languages. The analysis links Tomiris to Turla toolsets lik…

Read More
Threat Research

Open-Source Gh0st RAT Still Haunting Inboxes 15 Years After Release

April 20, 2023October 16, 2025 Securonix

Gh0st RAT is a decades-old open-source remote administration tool that still shows up in phishing campaigns, including against a European medical technology organization, highlighting its enduring availability and adaptability. While once tied to nation-state …

Read More
Threat Research

AllaKore(d) the SideCopy Train

April 19, 2023October 13, 2025 CTI

Identifying Connected Infrastructure and Management Activities Introduction This blog post seeks to build on recent public reporting on…

Read More
Threat Research

X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe

April 19, 2023October 13, 2025 Securonix

Symantec’s Threat Hunter Team links a broader X_Trader software supply chain attack to multiple victims, including two critical infrastructure organizations in the energy sector in the U.S. and Europe, plus two other financial trading firms. The operation uses…

Read More
Threat Research

Cyble – Qakbot Malware Continues To Morph

April 19, 2023October 13, 2025 Securonix

Cyble researchers report Qakbot’s evolving delivery using OneNote attachments that drop CHM files, which load a PowerShell script to download and execute a DLL via rundll32. This method—along with embedded ISO content and hardcoded URLs—helps Qakbot evade dete…

Read More
Threat Research

Securonix Threat Labs Security Advisory: New OCX#HARVESTER Attack Campaign Leverages Modernized More_eggs Suite to Target Victims

April 19, 2023October 16, 2025 Securonix

OCX#HARVESTER is a threat campaign by Securonix Threat Labs leveraging the More_eggs malware suite to target financial-sector victims, with activity observed from late 2022 through early 2023 and new C2 infrastructure shifts. The campaign uses image-based LNK …

Read More
Threat Research

Critical Vulnerabilities in PaperCut Print Management Software

April 18, 2023October 16, 2025 Securonix

Researchers observed in-the-wild exploitation of zero-day vulnerabilities in PaperCut MF/NG that allow unauthenticated remote code execution via an authentication bypass. The campaign uses post-exploitation payloads (including Atera and Syncro RMM installers) …

Read More
Threat Research

ViperSoftX Updates Encryption, Steals Data

April 18, 2023October 16, 2025 Securonix

Trend Micro details a new ViperSoftX campaign that hides its loader in illicit software packages and uses DLL sideloading, advanced encryption, and anti-analysis techniques to steal cryptocurrency wallets and passwords. The operation targets both consumers and…

Read More
Threat Research

ChatGPT-Themed Scam Attacks Are on the Rise

April 18, 2023October 18, 2025 Securonix

Unit 42 researchers document a surge in ChatGPT-related scams, including domain squatting and copycat services that abuse OpenAI branding to lure users into malware or data theft. The article presents phishing, malware delivery, crypto and financial scams, and…

Read More
Threat Research

EvilExtractor – All-in-One Stealer | FortiGuard Labs

April 18, 2023October 13, 2025 Securonix

EvilExtractor is a Windows-focused info stealer with modular components that exfiltrate browser data, credentials, and system information to an attacker’s FTP server, and it includes a Kodex ransomware capability. FortiGuard Labs links its phishing delivery, P…

Read More

Posts pagination

Previous 1 … 413 414 415 … 490 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.