Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

BumbleBee: Round Two

September 19, 2022October 15, 2025 TheDFIR

May 2022 intrusion used BumbleBee as the initial access vector to deploy Cobalt Strike and Meterpreter across the network. The actors delivered a hidden DLL via an ISO/LNK chain, then moved laterally with RDP/SMB and remote access tools before being evicted; t…

Read More
Threat Research

Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets | Recorded Future

September 19, 2022October 19, 2025 Securonix

Recorded Future analyzes TA413, a Chinese state-sponsored group, detailing campaigns against the Tibetan community and the adoption of new capabilities, including the LOWZERO backdoor and exploitation of zero-days such as CVE-2022-1040 and Follina. The report …

Read More
Threat Research

Iranian State Actors Conduct Cyber Operations Against the Government of Albania | CISA

September 15, 2022October 15, 2025 Securonix

The FBI and CISA release a Cybersecurity Advisory detailing Iranian state actors, operating as HomeLand Justice, conducting destructive cyber operations against the Government of Albania in July and September 2022, including a year-long intrusion, ransomware-s…

Read More
Threat Research

DPRK Job Opportunity Phishing via WhatsApp | PuTTY Utility

September 14, 2022October 16, 2025 GoogleCloudIntel

In July 2022, during proactive threat hunting activities at a company in the media industry, Mandiant Managed Defense identified a novel spear phish methodology employed by the threat cluster tracked as UNC4034. Mandiant has identified several overlaps between this group and those we suspect have a North Korea nexus.

UNC4034 established communication…

Read More
Threat Research

Cyble – New Malware Campaign Targets Zoom Users

September 14, 2022October 17, 2025 Securonix

Cyble researchers uncovered a campaign that uses fake Zoom sites to spread Vidar Stealer to Zoom users. The malware drops binaries, injects into MSBuild, and communicates with C2 infrastructure via GitHub-hosted payloads and hardcoded addresses. #VidarStealer …

Read More
Threat Research

Some Kind of Monster: RaaS Hides Itself Using Traits From Other Malware

September 14, 2022October 14, 2025 Securonix

Monster is a Delphi-based ransomware-as-a-service (RaaS) that hides its capabilities and uses configurable features to customize encryption and evasion, raising the risk of attribution confusion. The BlackBerry analysis details its encryption methods, use of I…

Read More
Threat Research

Ransomware Roundup: Ragnar Locker Ransomware | FortiGuard Labs

September 14, 2022October 14, 2025 Securonix

Fortinet’s Ragnar Locker Ransomware Roundup explains that Ragnar Locker encrypts files, exfiltrates data, and uses double extortion to pressure victims, including negotiations via a Tor-based site and leaking stolen information on a “Wall of Shame.” It also no…

Read More
Threat Research

Gamaredon APT targets Ukrainian government agencies in new campaign

September 8, 2022October 15, 2025 Securonix

Cisco Talos reports a new Gamaredon APT campaign targeting Ukrainian government entities, leveraging spear-phishing with Russian invasion-themed Office documents and malicious VBScript macros to seed infection. The operation uses a multi-stage chain (LNK in RA…

Read More
Threat Research

Iranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Disk Encryption for Ransom Operations | CISA

September 8, 2022October 15, 2025 Securonix

IRGC-affiliated cyber actors exploited known Fortinet FortiOS and Microsoft Exchange vulnerabilities, plus VMware Horizon Log4j flaws, to gain initial access and conduct ransomware-like operations involving data encryption and data extortion. The advisory outl…

Read More
Threat Research

Lorenz Ransomware Group Cracks MiVoice | Arctic Wolf

September 5, 2022October 17, 2025 Securonix

Arctic Wolf Labs analyzed a Lorenz ransomware intrusion that exploited CVE-2022-29499 on a Mitel MiVoice Connect appliance to gain initial access and deploy encryption with BitLocker. The attackers used LOLBins, Chisel tunneling, and FileZilla for data exfiltr…

Read More
Threat Research

New Wave of Espionage Activity Targets Asian Governments

September 5, 2022October 13, 2025 Securonix

Symantec details a new espionage campaign targeting Asian governments that uses DLL side-loading of legitimate software to load payloads, followed by credential theft and network-wide movement with a wide toolkit. The activity, spanning April–July 2022, hit a …

Read More
Threat Research

Dead or Alive? An Emotet Story

September 2, 2022October 15, 2025 TheDFIR

May 2022 saw an Emotet-driven intrusion that began with a phishing Excel document and culminated in a domain-wide compromise, Cobalt Strike beaconing, lateral movement, and data exfiltration via Rclone. Emotet has since resurfaced (with TrickBot support) and r…

Read More
Threat Research

Lazarus and the tale of three RATs

September 2, 2022October 15, 2025 Securonix

Cisco Talos reports Lazarus Group’s global campaign exploiting VMware Horizon vulnerabilities to gain long-term access to energy-sector targets, deploying VSingle, YamaBot, and the newly described MagicRAT implants. The activity shows post-exploitation, latera…

Read More
Threat Research

MagicRAT: Lazarus’ latest gateway into victim networks

September 1, 2022October 13, 2025 Securonix

Cisco Talos identifies a new Lazarus Group remote access trojan named MagicRAT, deployed after exploiting publicly exposed VMware Horizon platforms. The malware, linked to TigerRAT and Lazarus infrastructure, includes persistence, reconnaissance, and the hosti…

Read More
Threat Research

Mirai Variant MooBot Targeting D-Link Devices

August 31, 2022October 14, 2025 Securonix

Unit 42 researchers describe MooBot, a Mirai variant, that leverages four D-Link vulnerabilities to seize control of exposed devices and deploy a botnet for DDoS attacks. The campaign downloads MooBot from a remote host, communicates with a C2 server, and incl…

Read More

Posts pagination

Previous 1 … 215 216 217 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.