Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

BumbleBee Zeros in on Meterpreter

November 8, 2022October 14, 2025 TheDFIR

A May 2022 intrusion used BumbleBee as the initial access vector via a Contact Forms campaign, delivering an ISO containing an LNK and a DLL to load Meterpreter and Cobalt Strike Beacons. The attackers conducted multi-stage post-exploitation including UAC bypa…

Read More
Threat Research

Cyble – Phishing Campaign Targeting Indonesian BRI Bank Using SMS Stealer

November 4, 2022October 15, 2025 Securonix

Cyble researchers uncovered a phishing campaign targeting Bank Rakyat Indonesia (BRI) that escalates by distributing Android SMS stealers to harvest OTPs and bypass 2FA. The operation begins with credential- and OTP-phishing sites, then installs a custom SMS s…

Read More
Threat Research

Raccoon | Malware Trends Tracker

November 1, 2022October 15, 2025 Securonix

Raccoon is an information stealer malware distributed as a service with a user-friendly dashboard and frequent updates, enabling attackers to steal data from infected machines. It collects browser passwords, Outlook data, system information, and more, archives…

Read More
Threat Research

SocGholish Diversifies and Expands Its Malware Staging Infrastructure to Counter Defenders

October 31, 2022October 16, 2025 Securonix

SocGholish operators have significantly expanded and diversified their malware staging infrastructure since mid-2022, adding about 18 new second-stage servers per month to counter defenders and scale operations. The majority of these new servers are in Europe …

Read More
Threat Research

Robin Banks still might be robbing your bank (part 2)

October 31, 2022October 16, 2025 Securonix

IronNet analyzes how the Robin Banks phishing-as-a-service platform has evolved to evade takedowns, relocate infrastructure to a Russian provider, and add features like cookie-stealing to bypass MFA. The study highlights how open-source code and off-the-shelf …

Read More
Threat Research

Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor

October 27, 2022October 17, 2025 Securonix

SentinelLabs provides a comprehensive analysis of Black Basta’s operational TTPs, revealing custom tools, EDR-evasion capabilities, and a likely link to FIN7. The findings suggest FIN7 developers may have contributed to Black Basta’s toolset, with privilege es…

Read More
Threat Research

Securonix Threat Labs Security Advisory: Apache Commons Text4Shell (CVE-2022-42889) Exploitation – Analysis and Detection

October 26, 2022October 14, 2025 Securonix

Text4Shell (CVE-2022-42889) is a critical remote code execution vulnerability in Apache Commons Text (versions 1.5–1.9) that can be triggered by crafted input strings to run code on vulnerable hosts. The advisory covers exploitation methods, potential post-exp…

Read More
Threat Research

Follina Exploit Leads to Domain Compromise

October 24, 2022October 17, 2025 TheDFIR

An intrusion in early June 2022 leveraged the Follina CVE-2022-30190 vulnerability embedded in a malicious Word document to install Qbot (Qakbot/Pinksliplot) and pivot through the network toward a domain compromise. Attackers used Cobalt Strike, NetSupport Man…

Read More
Threat Research

Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity | Microsoft Security Blog

October 19, 2022October 18, 2025 Securonix

Microsoft’s analysis shows Raspberry Robin as part of a broader, interconnected malware ecosystem that enables pre-ransomware activity across thousands of devices, linking USB-driven infections to follow-on hands-on-keyboard attacks and ransomware deployments.…

Read More
Threat Research

Ransomware Spotlight: BlackCat – Security News

October 18, 2022October 16, 2025 Securonix

BlackCat (ALPHV) ransomware has risen to prominence with a Rust-based framework, triple extortion tactics, and a growing affiliate network that leverages diverse attack vectors. Trend Micro highlights evolving TTPs—from Emotet-assisted initial access to privat…

Read More
Threat Research

LV Ransomware Exploits ProxyShell in Attack on a Jordan-based Company

October 17, 2022October 17, 2025 Securonix

Trend Micro analyzed an LV ransomware intrusion tied to ProxyShell and ProxyLogon exploits affecting a Jordan-based company, highlighting double-extortion and expanding affiliate activity. The report details the infection chain—from Exchange vulnerabilities an…

Read More
Threat Research

Analysis on Attack Techniques and Cases Using RDP – ASEC BLOG

October 14, 2022October 17, 2025 Securonix

RDP is commonly used for initial compromise and lateral movement, including via wrappers when native remote desktop support is unavailable. The article also covers how attackers add user accounts, drop RDP-related malware, and employ credential theft and sessi…

Read More
Threat Research

WarHawk: the New Backdoor in the Arsenal of the SideWinder APT Group

October 14, 2022October 13, 2025 Securonix

Two Zscaler ThreatLabz reports reveal WarHawk, a new backdoor used by the SideWinder APT to target Pakistan, delivering Cobalt Strike via a multi-module loader that includes KernelCallBackTable injection and a Pakistan Standard Time check. The campaign leverag…

Read More
Threat Research

#StopRansomware: Daixin Team | CISA

October 14, 2022October 17, 2025 Securonix

Daixin Team is a ransomware and data extortion group focused on Healthcare and Public Health sector targets in the U.S., using VPN compromises and credential theft to deploy ransomware on ESXi servers and exfiltrate data. The FBI/CISA/HHS advisory details TTPs…

Read More
Threat Research

Mirai, RAR1Ransom, and GuardMiner – Multiple Malware Campaigns Target VMware Vulnerability

October 14, 2022October 18, 2025 Securonix

In April, VMware patched CVE-2022-22954, but attacks exploiting remote code execution via server-side template injection persisted, delivering Mirai variants, RAR1Ransom, and GuardMiner payloads to exposed VMware Workspace ONE Access and Identity Manager insta…

Read More

Posts pagination

Previous 1 … 213 214 215 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.