Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: EDR

Threat Research

#StopRansomware: Zeppelin Ransomware | CISA

August 2, 2022October 16, 2025 Securonix

The article compiles a large set of file hash indicators tied to Zeppelin ransomware activity as described in the CISA alert AA22-223a, associated with the StopRansomware campaign. It presents these indicators in a purely IOC-focused format without narrative d…

Read More
Threat Research

Novel News on Cuba Ransomware: Greetings From Tropical Scorpius

August 1, 2022October 15, 2025 Securonix

Unit 42 analyzes Tropical Scorpius (UNC2596) activity, detailing Cuba Ransomware’s evolution with new tools like ROMCOM RAT, KerberCache, and a kernel driver to defeat defenses, plus its connection to the Industrial Spy marketplace. The report covers ransomwar…

Read More
Threat Research

Adversary Quest 2022: 4 CATAPULT SPIDER eCrime Challenges | CrowdStrike

July 28, 2022October 16, 2025 Securonix

Researchers analyze CrowdStrike’s Adversary Quest 2022 CATAPULT SPIDER track, which centers on a Dogecoin-driven ransomware campaign leveraging CHM phishing, encoded PowerShell, and a Dogecoin-based C2. The storyline uncovers multi-stage payloads, a vulnerable…

Read More
Threat Research

Living Off Windows Defender | LockBit Ransomware Sideloads Cobalt Strike Through Microsoft Security Tool

July 26, 2022October 20, 2025 Securonix

LockBit operators have been observed abusing legitimate security tools to load Cobalt Strike beacons, deploying a living-off-the-land approach to evade defenses. The campaign pivots on using MpCmdRun.exe to decrypt and load a weaponized DLL, following prior si…

Read More
Threat Research

Here’s a Simple Script to Detect the Stealthy Nation-State BPFDoor | Qualys Security Blog

July 25, 2022October 13, 2025 Securonix

BPFDoor is a Linux/Unix backdoor that uses Berkeley Packet Filters (BPF) to filter data through sockets and support multiple C2 protocols (TCP, UDP, ICMP), enabling stealthy remote access. The BPFDoor campaign is attributed to the Chinese threat actor Red Mens…

Read More
Threat Research

Threat analysis: Follina exploit fuels ‘live-off-the-land’ attacks

July 21, 2022October 20, 2025 Securonix

Two-sentence summary: An in-depth analysis shows how the Follina exploit (CVE-2022-30190) is weaponized to achieve remote code execution via MSDT and to enable persistent, live-off-the-land attacker activity using native Windows tools. The report details three…

Read More
Threat Research

Cyble – Targeted Attacks Being Carried Out Via DLL SideLoading

July 21, 2022October 15, 2025 Securonix

Threat actors are leveraging DLL sideloading in legitimate Microsoft applications to deliver a Cobalt-Strike beacon. The dropped DLL is loaded from application folders and communicates with a C2 URL hosted on CloudFront to enable beacon operations. #QakBot #Co…

Read More
Threat Research

Threat Actors Leveraging Microsoft Applications via DLL SideLoading – Detection & Response – Security Investigation

July 20, 2022October 16, 2025 Securonix

Threat actors abuse DLL sideloading to run malicious code through legitimate Microsoft applications (Teams and OneDrive), dropping and loading a malicious DLL that communicates with a remote C2 and leverages Cobalt Strike Beacon for post‑exploitation. The camp…

Read More
Threat Research

eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID

July 20, 2022October 16, 2025 Securonix

Gootloader is a Malware-as-a-Service (MaaS) offering that is spread through SEO poisoning to distribute malicious payloads, such as IcedID. Threat actors have begun using IcedID, a former banking trojan, since it’s a stealthier option compared to Cobalt Strike…

Read More
Threat Research

Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities | Proofpoint US

July 6, 2022October 14, 2025 Securonix

TA4563 is a threat actor using the EvilNum backdoor to target European DeFi, cryptocurrency, and forex entities, with campaigns evolving in how they deliver the malware and evade defenses. EvilNum functions as a backdoor for data theft and loading additional p…

Read More
Threat Research

New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails

July 5, 2022October 17, 2025 Securonix

Fortinet’s FortiGuard Labs documented a phishing campaign delivering a new QakBot variant via an attached HTML file that auto-executes to drop a ZIP, load a loader, and ultimately run QakBot within a Windows process. The analysis details the infection chain fr…

Read More
Threat Research

Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive

June 28, 2022October 14, 2025 Securonix

Researchers document Cloaked Ursa (APT29) campaigns that weaponize trusted cloud storage services to hide malware delivery, notably Dropbox and Google Drive. The campaigns deploy EnvyScout HTML droppers to fetch Agenda.iso payloads and use Google Drive-based e…

Read More
Threat Research

When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors

June 23, 2022October 14, 2025 Securonix

Unit 42 analyzes Brute Ratel C4 (BRc4) activity tied to a Roshan_CV ISO, showing how a red-teaming tool can evade modern defenses and operate with nation-state-like tradecraft. The post covers the tool’s packaging, delivery via a LNK lure, in-memory execution,…

Read More
Threat Research

Securonix Threat Labs Initial Coverage Advisory: Analysis and Detection of BumbleBee Loader Using Securonix

June 22, 2022October 13, 2025 Securonix

BumbleBee is a new loader actively used to deliver payloads via phishing campaigns and to establish an initial foothold in target networks. The analysis highlights its living-off-the-land techniques, notably using a Microsoft-signed odbcconf.exe to indirectly …

Read More
Threat Research

Socgholish to Cobalt Strike in 10 Minutes

June 15, 2022October 15, 2025 Securonix

eSentire’s TRU team uncovered Socgholish, a drive-by social engineering threat that delivers a fake software update, leading to quick Cobalt Strike deployment and persistence. The case highlights how drive-by infections can escalate to hands-on-keyboard intrus…

Read More

Posts pagination

Previous 1 … 149 150 151 152 Next

What are you looking for ?

  • šŸ–„ļø [ D A S H B O A R D ]
  • šŸ•µļøā€ā™‚ļø Threat Research
  • šŸ“° Security News
  • 🚨 Attack & Data Breach
  • šŸ›‘ Ransomware Monitor
  • šŸ’€ Hacked! Web Defacement
  • ✨ Interesting Stuff
  • šŸ“ŗ Youtube Overview
  • šŸ” Google Cybersecurity
  • šŸ“¢ Telegram Notification
  • šŸ“° News Daily Recap
  • šŸ“° Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.