Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

Technical Advisory: Various Threat Actors Targeting ManageEngine Exploit CVE-2022-47966

February 20, 2023October 17, 2025 Securonix

Bitdefender Labs observed a global wave of opportunistic attacks exploiting CVE-2022-47966 in ManageEngine products, with 2,000–4,000 internet-facing servers potentially vulnerable. The advisory documents four attack clusters (Initial Access Brokers, Buhti Ran…

Read More
Threat Research

HardBit 2.0 Ransomware

February 17, 2023October 16, 2025 Securonix

HardBit 2.0 is a ransomware variant observed from late 2022 that encrypts data after stealing sensitive information, negotiating ransom rather than paying a fixed bitcoin amount. It combines data theft, encryption, and multiple defense-evading and persistence …

Read More
Threat Research

Cyble – The Many Faces Of Qakbot Malware: A Look At Its Diverse Distribution Methods

February 17, 2023October 16, 2025 Securonix

Qakbot (QBot) is spread through multiple OneNote- and script-based channels, including OneNote attachments, WSF/JS/JSE/HTA paths, and HTML applications, each delivering a DLL payload that is executed via Rundll32 and often injected into processes. The campaign…

Read More
Threat Research

HWP Malware Using the Steganography Technique: RedEyes (ScarCruft) – ASEC BLOG

February 17, 2023October 13, 2025 Securonix

ASEC reports that the RedEyes group (ScarCruft/APT37) targeted individuals in Korea by exploiting the CVE-2017-8291 HWP EPS vulnerability and delivering malware via steganography. They reveal a new backdoor, M2RAT (Map2RAT), that uses a shared memory channel a…

Read More
Threat Research

Cyble – Decoding The Inner Workings Of DarkCloud Stealer

February 16, 2023October 13, 2025 Securonix

DarkCloud Stealer is a multi-stage information-stealer that can exfiltrate data via SMTP, Telegram, Web Panel, and FTP, and is distributed through spam campaigns with a customizable builder for grabber and clipper features. Researchers observed a rise in DarkC…

Read More
Threat Research

Your Office Document is at Risk – XLL, A New Attack Vector

February 16, 2023October 16, 2025 Securonix

Two office-document threat vectors are described: attackers are moving from VBA macros to malicious Microsoft Office Add-ins, specifically XLLs, to deliver payloads. The article details a Raccoon Stealer V2 campaign that uses obfuscated .NET installers loaded …

Read More
Threat Research

Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia

February 16, 2023October 16, 2025 Securonix

Hydrochasma targets medical laboratories and shipping organizations in Asia in an intelligence-gathering campaign that relies on publicly available tools and living-off-the-land techniques. The operation, active since October 2022, appears focused on informati…

Read More
Threat Research

BlackCat Ransomware Group Claims Attack on Healthcare Service Provider

February 15, 2023October 13, 2025 Securonix

Security researchers report that the BlackCat ransomware group briefly claimed an attack on a major U.S. electronic health record (EHR) vendor, but the entry disappeared within days. STRIKE analysis links possible BlackCat activity to its ExMatter/Fendr exfilt…

Read More
Threat Research

Three Cases of Cyber Attacks on the Security Service of Ukraine and NATO Allies, Likely by Russian State-Sponsored Gamaredon

February 15, 2023October 14, 2025 Securonix

EclecticIQ analyzes three cases of cyberattacks likely linked to the Gamaredon APT group, targeting the Security Service of Ukraine, Culver Aviation, and Latvian/NATO allies with phishing, HTML smuggling, and CVE-2017-0199 Word exploits. The report notes overl…

Read More
Threat Research

Invitation to a Secret Event: Uncovering Earth Yako’s Campaigns

February 13, 2023October 16, 2025 Securonix

Earth Yako is an intrusion set linked to Operation RestyLink/EneLink, with newly observed TTPs and infrastructure for cyberespionage against Japanese researchers and think tanks (also some Taiwan targets). The campaign features multiple malware families (Mirro…

Read More
Threat Research

스테가노그래피 기법 사용한 한글(HWP) 악성코드 : RedEyes(ScarCruft) – ASEC BLOG

February 12, 2023October 15, 2025 Securonix

ASEC analyzed RedEyes (ScarCruft/APT37) activity in Korea, revealing the group’s use of the Hangul EPS vulnerability CVE-2017-8291 to spread malware via steganography and a new M2RAT backdoor that employs shared memory for C2. The operation combines persistenc…

Read More
Threat Research

Global ESXiArgs ransomware attack on the back of a two-year-old vulnerability

February 10, 2023October 14, 2025 Securonix

The ESXiArgs ransomware campaign exploited CVE-2021-21974 via the OpenSLP service to remotely execute code on exposed ESXi servers. VMware patched the vulnerability in early 2021, while Trellix details how attackers probe the internet for unpatched systems, en…

Read More
Threat Research

ProxyShellMiner Campaign Creating Dangerous Backdoors

February 10, 2023October 20, 2025 Securonix

Morphisec identifies a highly evasive ProxyShellMiner campaign that leverages ProxyShell flaws to gain access to Windows Exchange servers and deploys a multi-stage coin-mining operation across an organization. The campaign uses domain-wide persistence, obfusca…

Read More
Threat Research

Technical Advisory: Immediately Patch Your VMware ESXi Servers Targeted by Opportunistic Threat Actors

February 8, 2023October 13, 2025 Securonix

Bitdefender researchers describe opportunistic threat actors abusing CVE-2021-21974 to target VMware ESXi, leveraging OpenSLP (port 427) for pre-auth remote code execution and deploying ESXiArgs ransomware against VM files. The advisory covers attack patterns,…

Read More
Threat Research

Investigating Intrusions From Intriguing Exploits

February 7, 2023October 16, 2025 Securonix

Huntress linked a February 2023 GoAnywhere MFT-related intrusion to a zero-day vulnerability and a Truebot-like post-exploitation activity, leading to a mitigation before a ransomware event could unfold. The effort highlighted how certutil and rundll32 were us…

Read More

Posts pagination

Previous 1 … 207 208 209 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.