Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Redistribution of Magniber Ransomware in Korea (January 28th) – ASEC BLOG

February 2, 2023October 14, 2025 Securonix

ASEC reports Magniber distribution in Korea disguised as MSI Windows installers, using MOTW bypass and base64-encoded links to evade blocking. The campaign leverages MSI Custom Actions to execute a Magniber DLL, deletes volume shadow copies to hinder recovery,…

Read More
Threat Research

ASEC Weekly Malware Statistics (January 30th, 2023 – February 5th, 2023) – ASEC BLOG

February 2, 2023October 15, 2025 Securonix

ASEC’s RAPIT analysis summarizes malware weekly stats from January 30 to February 5, 2023, highlighting downloader as the top category, followed by Infostealer and backdoor. The leading families were SmokeLoader, BeamWinHTTP, Formbook, Quasar RAT, and RedLine,…

Read More
Threat Research

Cyble – Massive Ransomware Attack Targets VMware ESXi Servers

February 2, 2023October 16, 2025 Securonix

The ESXiArgs ransomware campaign targets VMware ESXi servers by exploiting a two-year-old OpenSLP heap overflow vulnerability (CVE-2021-21974) to deploy encryption across near 1,000 servers worldwide, with France, the US, and Germany heavily affected. The atta…

Read More
Threat Research

Sliver Malware With BYOVD Distributed Through Sunlogin Vulnerability Exploitations – ASEC BLOG

February 2, 2023October 15, 2025 Securonix

Sliver backdoor was installed via Sunlogin vulnerability exploitation, with threat actors using BYOVD to disable security products and deploy a reverse shell alongside Gh0st RAT and XMRig CoinMiner. The report details Sliver’s capabilities, the Sunlogin RCE at…

Read More
Threat Research

Ransomware Roundup – Trigona | FortiGuard Labs

February 1, 2023October 18, 2025 Securonix

Fortinet’s FortiGuard Labs highlights the Trigona ransomware in its bi-weekly Ransomware Roundup, detailing its double-extortion approach of encrypting endpoints and threatening to leak exfiltrated data. The report covers suspected infection vectors (emails, R…

Read More
Threat Research

New Medusa Botnet Emerging Via Mirai Botnet Targeting Linux Users – Cyble

February 1, 2023October 15, 2025 Securonix

A Mirai-driven botnet variant is dropping Medusa, a Python-based botnet, onto Linux targets to perform DDoS, ransomware, brute-force attacks, and data exfiltration. The article details the Medusa botnet’s client, C2 communications, attack methods, and the IOCs…

Read More
Threat Research

No Macro? No Worries. VSTO Being Weaponized by Threat Actors | Deep Instinct

February 1, 2023October 25, 2025 Securonix

VSTO Add-Ins can be weaponized to deliver and execute code via Office documents, offering persistence across Office sessions. The article details local and remote VSTO attack flows, including user prompts to enable Add-Ins, encoded PowerShell payloads, and a r…

Read More
Threat Research

Supply Chain Attack by New Malicious Python Package, “web3-essential” | FortiGuard Labs

February 1, 2023October 13, 2025 Securonix

FortiGuard Labs detected a zero-day in a PyPI package named “web3-essential,” published by a newly joined user known as ‘Trexon’ on January 26, 2023. The package downloads and executes a Go-based binary to steal sensitive data and exfiltrate it via a Discord w…

Read More
Threat Research

Operation Ice Breaker Targets The Gam(bl)ing Industry Right Before It’s Biggest Gathering

February 1, 2023October 15, 2025 Securonix

IceBreaker APT is a newly tracked threat targeting the gambling/gaming sector in the run-up to ICE London, employing social-engineering to lure a customer-service agent and delivering a two-stage payload chain. Researchers describe a modular Node.js-based back…

Read More
Threat Research

ASEC Weekly Malware Statistics (January 23rd, 2023 – January 29th, 2023) – ASEC BLOG

February 1, 2023October 13, 2025 Securonix

ASEC’s weekly malware statistics for January 23–29, 2023 categorize threats by family, with downloader as the largest share, followed by Infostealer and backdoor. The report highlights BeamWinHTTP as the top downloader, with SmokeLoader, Formbook, AgentTesla, …

Read More
Threat Research

Cyble – New BATLoader Disseminates RATs And Stealers

February 1, 2023October 17, 2025 Securonix

Cyble Research & Intelligence Labs details a new BAT loader used to disseminate RATs and stealers via OneNote attachments delivered through spam emails. The article walks through the infection chain, the obfuscated BAT loader, in-memory .NET payload loading (Q…

Read More
Threat Research

UAC Bypass Using CMSTP

February 1, 2023October 16, 2025 Securonix

Two sentences summarizing the article: Quick Heal researchers examine how malware bypasses User Account Control (UAC) to gain admin privileges, enabling ransomware to encrypt system files. The piece details three CMSTP-based UAC bypass methods (malicious INF f…

Read More
Threat Research

Collect, Exfiltrate, Sleep, Repeat

February 1, 2023October 19, 2025 TheDFIR

Two sentences summarizing the intrusion: An August 2022 incident began with a malicious Word document carrying a VBA macro that installed a PowerShell-based implant, established persistence via scheduled tasks, and used a renamed AutoHotkey-based keylogger to …

Read More
Threat Research

Dynamic Approaches seen in AveMaria’s Distribution Strategy

February 1, 2023October 14, 2025 Securonix

AveMaria distribution campaigns evolved through seven case studies in 2022, showcasing multiple delivery formats and evolving execution steps to evade detection. ThreatLabz notes ongoing updates to AveMaria’s chain, including new techniques like custom downloa…

Read More
Threat Research

Evolution of a Software Supply Chain Attacker

January 31, 2023October 14, 2025 CTI

Checkmarx researchers tracked a persistent threat actor they named PYTA27 who distributed multiple malicious Python packages to PyPI and GitHub, evolving from plain-text payloads to obfuscated and multi-stage stealers that target Discord and crypto-wallets. Th…

Read More

Posts pagination

Previous 1 … 430 431 432 … 490 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.