Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Hunting Follina

August 10, 2022October 14, 2025 Securonix

Follina (CVE-2022-30190) is a remote-code-execution vulnerability in Microsoft’s MSDT exploited via Word documents that load a remote template containing a payload. Researchers show how attackers used remote templates and base64-encoded PowerShell to run code,…

Read More
Threat Research

THREAT ANALYSIS REPORT: Bumblebee Loader – The High Road to Enterprise Domain Control

August 10, 2022October 15, 2025 Securonix

Cybereason GSOC analyzes a Bumblebee Loader infection, detailing the attack chain from initial lure to full network compromise and Active Directory takeover, with notes on post-exploitation actions, credential theft, and data exfiltration. The report also high…

Read More
Threat Research

DarkTortilla Malware Analysis

August 10, 2022October 16, 2025 Securonix

DarkTortilla is a highly configurable .NET-based crypter that delivers commodity information stealers and RATs, with targeted payloads such as Cobalt Strike and Metasploit. It uses a two-component architecture (initial loader and core processor) with strong an…

Read More
Threat Research

Two more malicious Python packages in the PyPI

August 10, 2022October 13, 2025 Securonix

Two newly discovered malicious PyPI packages masquerade as a popular library to steal data and credentials, delivering a multi-stage payload that culminates in the W4SP Stealer which exfiltrates browser data and Discord tokens via a Discord webhook. The campai…

Read More
Threat Research

Raccoon Infostealer Malware Returns with New TTPS – Detection & Response – Security Investigation

August 9, 2022October 17, 2025 Securonix

Raccoon is an info-stealer malware offered as malware-as-a-service since 2019, capable of stealing passwords, cookies, autofill data, and cryptocurrency wallet data from browsers. The campaign uses phishing campaigns and trusted Windows components to drop, exe…

Read More
Threat Research

Typosquatting Campaign Targeting Python’s Top Packages, Dropping GitHub Hosted Malware with DGA…

August 9, 2022October 13, 2025 Securonix

A Checkmarx analysis details a large typosquatting campaign targeting Python’s top packages that drops Windows malware hosted on GitHub and uses a domain-generation algorithm for C2. The operation also includes DDOS capabilities, anti-sandbox tricks, and persi…

Read More
Threat Research

UNC3890: Suspected Iranian Threat Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors

August 8, 2022October 19, 2025 Securonix

UNC3890 is an Iran-linked threat cluster tracked by Mandiant that targets Israeli shipping, government, energy and healthcare organizations using social-engineering lures and watering holes. The operation leverages a backdoor (SUGARUSH), a credential stealer (…

Read More
Threat Research

Threat in your browser: what dangers innocent-looking extensions hold for users

August 8, 2022October 14, 2025 Securonix

Browser extensions can be convenient, but many disguise real threats, collecting data, showing affiliate ads, or even stealing credentials. The report documents several malicious and unwanted extension families (WebSearch, DealPly, AddScript, FB Stealer) and e…

Read More
Threat Research

Shuckworm: Russia-Linked Group Maintains Ukraine Focus

August 5, 2022October 16, 2025 Securonix

Shuckworm (also known as Gamaredon or Armageddon) is a Russia-linked group that has focused on Ukraine since 2014, conducting espionage and information-stealing campaigns. Symantec’s observations detail the infection chain, malware families, and IOCs tied to a…

Read More
Threat Research

PyPI package ‘secretslib’ drops fileless Linux malware to mine monero

August 5, 2022October 16, 2025 Securonix

Sonatype uncovered secretslib, a PyPI package that masquerades as a secrets-management library but secretly runs an in-memory Linux cryptominer, a technique used by fileless malware. The incident also involved identity impersonation of a real Argonne National …

Read More
Threat Research

Cyble – Phishing Site Used To Spread Typhon Stealer

August 4, 2022October 13, 2025 Securonix

Cyble researchers uncovered a phishing site impersonating Lindesbergs Kommun that delivers Typhon Stealer via a crafted .lnk file and PowerShell to download the payload. The stealer harvests data from browsers, wallets, gaming apps, and messaging tools, with e…

Read More
Threat Research

CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies

August 4, 2022October 19, 2025 Securonix

Trend Micro tracks CopperStealer’s new campaign, which distributes a malicious Chromium-based browser extension to steal cryptocurrencies and wallet keys. The operation uses a multi-stage dropper, heavy JavaScript obfuscation, and browser-configuration manipul…

Read More
Threat Research

Operation(верность) mercenary:陷阵于东欧平原的钢铁洪流

August 4, 2022October 13, 2025 Securonix

Conti Group, a globally renowned ransomware operation, has recently targeted high-value sectors by exploiting Exchange vulnerabilities to launch targeted campaigns against affluent firms. The report also covers BruteSql Group and links to Conti activity, inclu…

Read More
Threat Research

Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users

August 4, 2022October 14, 2025 Securonix

Iron Tiger’s operation against Mimi chat installers shows a supply chain compromise delivering HyperBro on Windows and rshell on macOS/Linux across multiple targets. The campaign spans three major platforms, uses code obfuscation, and establishes C2 communicat…

Read More
Threat Research

Cyble – MikuBot Spotted In The Wild

August 4, 2022October 16, 2025 Securonix

Cyble Research Labs uncovered MikuBot, a new Windows botnet that steals data and runs hidden HVNC sessions for remote access, with USB propagation and the ability to download and execute additional malware. The actor markets MikuBot with a panel, uses encrypti…

Read More

Posts pagination

Previous 1 … 462 463 464 … 489 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.