Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

Citrix Bleed Vulnerability: A Gateway to LockBit Ransomware

December 6, 2023October 14, 2025 Securonix

eSentire’s TRU unit tracked a October 2023 LockBit ransomware intrusion linked to a Citrix Bleed CVE-2023-4966 exploit, including initial access via session token bypass and C2 activity tied to Brute Ratel and FileTransfer assets. The investigation details the…

Read More
Threat Research

Unmasking the Enigma: A Historical Dive into the World of PlugX Malware | Splunk

December 5, 2023October 13, 2025 Securonix

PlugX is a covert malware linked to cyber espionage and targeted attacks, with a history of evasion and modular capabilities. Splunk Threat Research Team provides a deep dive into a PlugX variant, covering its side-loading, multi-layer payload decryption, and …

Read More
Cyber Security News

Kaspersky malware report for Q3 2023

December 1, 2023January 25, 2025 SecureList

Attacks on a critical infrastructure target in South Africa, supply-chain attack on Linux machines, Telegram doppelganger used to target people in China.

Read More
Threat Research

Securonix Threat Labs Security Advisory: Threat Actors Target MSSQL Servers in DB#JAMMER to Deliver FreeWorld Ransomware

December 1, 2023October 20, 2025 Securonix

Threat actors in the DB#JAMMER campaigns compromised exposed MSSQL databases via brute-force login attempts and deployed a full toolkit leading to ransomware and Cobalt Strike payloads. The operation progressed from initial access through enumeration, defense …

Read More
Threat Research

The FlowerPower APT campaign uses a malicious OLE insertion attack inside HWP documents and utilizes Github C2.

November 30, 2023October 13, 2025 Genians-Korea

Genians Security Center observed a Korean-targeted APT campaign that delivers malicious OLE objects embedded in HWP documents to execute encrypted PowerShell payloads from the FlowerPower tool family. Attackers leverage GitHub as a covert command-and-control/h…

Read More
Threat Research

Can’t Touch This: Data Exfiltration via Finger

November 27, 2023October 13, 2025 Securonix

Threat actors repurpose native Windows tools (LOLBins) such as finger.exe to enable data ingress and exfiltration while blending in with legitimate activity. The Huntress report shows finger.exe used to download files to the endpoint, enumerate information, an…

Read More
Interesting Stuff

Ghidra Basics – Pivoting from String Cross References

November 24, 2023May 24, 2024 CTI

Leveraging Ghidra to establish context and intent behind suspicious strings.

Read More
Threat Research

Israel-Hamas War Spotlight: Shaking the Rust Off SysJoker – Check Point Research

November 23, 2023October 20, 2025 Checkpoint

Check Point Research describes new SysJoker variants used in targeted attacks against Israeli organizations, highlighting a full rewrite in Rust and a shift from Google Drive to OneDrive for hosting encrypted C2 configuration. The report details persistence vi…

Read More
Threat Research

Unveiling the Deceptive Dance: Phobos Ransomware Masquerading As VX-Underground | Qualys Security Blog

November 23, 2023October 20, 2025 Securonix

Qualys Threat Research uncovers Phobos ransomware masquerading as VX-Underground (VXUG), often distributed via stolen RDP and operating as a RaaS linked to Dharma/CrySIS. The article details anti-analysis checks, a wide process-kill routine, backup and firewal…

Read More
Threat Research

Diamond Sleet supply chain compromise distributes a modified CyberLink installer | Microsoft Security Blog

November 21, 2023October 16, 2025 Securonix

Microsoft Threat Intelligence uncovered a Diamond Sleet supply chain attack that tampered with a CyberLink installer to deliver a second-stage payload. The malicious file is signed with a valid CyberLink certificate, hosted on CyberLink infrastructure, and inc…

Read More
Threat Research

Is this the real life? Is this just fantasy? Caught in a landslide, NoEscape from NCC Group

November 21, 2023October 16, 2025 Securonix

A NCC Group incident response study analyzes NoEscape ransomware techniques observed in a recent engagement, highlighting opportunistic access and noisy tool use. The findings cover ProxyShell exploit access to Exchange, RDP lateral movement with SSH tunneling…

Read More
Threat Research

The Continued Evolution of the DarkGate Malware-as-a-Service

November 20, 2023October 14, 2025 Securonix

DarkGate is a sophisticated Remote Access Trojan sold as Malware-as-a-Service by the actor RastaFarEye, evolving through multiple versions with advanced evasion and multi-stage loading chains. Trellix researchers document its deployment methods, feature set, a…

Read More
Threat Research

Stately Taurus Targets the Philippines As Tensions Flare in the South Pacific

November 18, 2023October 15, 2025 Securonix

Unit 42 documents three Stately Taurus campaigns in August targeting South Pacific entities, including the Philippines government, using renamed Solid PDF Creator and a side-loaded DLL to maintain persistence and C2 activity. The actors also disguised C2 traff…

Read More
Threat Research

New SEO#LURKER Attack Campaign: Threat Actors Use SEO Poisoning and Fake Google Ads to Lure Victims Into Installing Malware

November 17, 2023October 15, 2025 Securonix

Securonix researchers describe an SEO poisoning/malvertising campaign dubbed SEO#LURKER that uses fake Google ads and lookalike sites to deliver a malicious WinSCP lure which sideloads DLLs and executes obfuscated Python payloads, resulting in C2 beaconing and…

Read More
Threat Research

Cryptojacking Attack Campaign Against Apache Web Servers Using Cobalt Strike – ASEC BLOG

November 17, 2023October 18, 2025 Securonix

ASEC reports attacks against vulnerable Apache web servers where threat actors deploy Cobalt Strike beacons and XMRig coin miners on Windows servers, often via PHP web shells and unpatched vulnerabilities. The operation uses obfuscated malware, staged beacons,…

Read More

Posts pagination

Previous 1 … 132 133 134 … 152 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.