Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

Cyble – Qakbot Resurfaces With New Playbook

July 15, 2022October 16, 2025 Securonix

Cyble Research Labs uncovered a new Qakbot playbook that uses DLL sideloading and a multi-stage delivery chain, including HTML-embedded ZIPs and an ISO with a disguised LNK file to trigger execution. The campaign evolves with legitimate apps loading malicious …

Read More
Threat Research

Securonix Threat Labs Initial Coverage Advisory: STIFF#BIZON Detection Using Securonix – New Attack Campaign Observed Possibly Linked to Konni/APT37 (North Korea)

July 7, 2022October 16, 2025 Securonix

Threat researchers observed a new attack campaign named STIFF#BIZON targeting high-value targets in the Czech Republic, Poland, and other countries, with artifacts possibly linked to North Korea’s APT37 (Konni). The campaign uses a multi-stage infection chain …

Read More
Threat Research

NukeSped RAT Report – CYFIRMA

July 4, 2022October 16, 2025 Securonix

NukeSped RAT is a Windows-based remote access trojan attributed to the Lazarus Group that uses phishing Word documents with malicious macros to drop staged payloads. It exfiltrates data, captures keystrokes and screenshots, and downloads additional payloads, e…

Read More
Threat Research

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems | CISA

June 30, 2022October 15, 2025 Securonix

Cyber threat actors, including state-sponsored APT groups, continue to exploit CVE-2021-44228 (Log4Shell) in unpatched VMware Horizon and Unified Access Gateway (UAG) servers to gain initial access and move laterally within organizations. They deploy loader ma…

Read More
Threat Research

Digium Phones Under Attack: Insight Into the Web Shell Implant

June 28, 2022October 16, 2025 Securonix

Unit 42 describes a campaign targeting Elastix/Digium phones where a PHP web shell is implanted to exfiltrate data and fetch additional payloads. The activity links to a Rest Phone Apps RCE (CVE-2021-45461) and is mitigated by Palo Alto Networks WildFire and T…

Read More
Threat Research

Confucius:隐藏在CloudFlare下的垂钓者

June 24, 2022October 14, 2025 Securonix

Confucius, an Indian APT group, has targeted Pakistan’s government and military since 2021 using spearphishing attachments and counterfeit government portals to deliver multi-stage loaders. The operation leverages QuasarRAT and bespoke C++/C# backdoors, delive…

Read More
Threat Research

Climbing Mount Everest: Black-Byte Bytes Back?

June 24, 2022October 13, 2025 Securonix

NCC Group analyzes Everest ransomware operations and argues a link to Black-Byte, detailing how Everest-related activity deployed during an incident response used TTPs such as RDP-based lateral movement, credential dumping, and C2 via remote tools. The report …

Read More
Threat Research

North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector | CISA

June 22, 2022October 16, 2025 Securonix

This joint Cybersecurity Advisory explains that Maui ransomware has been used by North Korean state-sponsored actors since May 2021 to target Healthcare and Public Health sector organizations, detailing TTPs and IOCs. It urges mitigations and reporting, and wa…

Read More
Threat Research

Bitter APT continues to target Bangladesh | SECUINFRA Falcon Team

June 22, 2022October 16, 2025 Securonix

Bitter (T-APT-17) continues to target Bangladesh, employing a multi-stage infection chain beginning with an Excel Maldoc that exploits CVE-2018-0798 to drop additional payloads. The operation culminates in Almond RAT, a .NET-based backdoor that uses AES-CBC en…

Read More
Threat Research

Cyble – Xloader Returns With New Infection Technique

June 21, 2022October 14, 2025 Securonix

Cyble Research Labs analyzed Xloader’s updated infection technique, detailing a multi-stage chain that starts with a phishing email delivering a PDF attachment, then traverses through embedded XLSX and an RTF-triggered dropper to load a final Xloader payload. …

Read More
Threat Research

The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefact

June 20, 2022October 13, 2025 Securonix

SessionManager is an IIS backdoor tied to the GELSEMIUM activity cluster that persists on compromised servers by loading a malicious IIS module after ProxyLogon-type exploits. It enables reading/writing files, remote command execution, and HTTP-based command-a…

Read More
Threat Research

Cyble – Quantum Software:  LNK File-based Builders Growing In Popularity

June 10, 2022October 18, 2025 Securonix

Cyble Research Labs highlights a rise in using Windows .lnk shortcut files to deliver payloads via LOLBins like PowerShell and mshta, including a new “Quantum Builder” tool that can create .lnk, .hta, and .iso-based payloads. The report also notes potential La…

Read More
Threat Research

Avos ransomware group expands with new attack arsenal

June 9, 2022October 15, 2025 Securonix

Talos observed a month-long AvosLocker campaign leveraging Sliver, Cobalt Strike, and network scanners to move laterally after exploiting Log4Shell on exposed VMware Horizon UAG appliances. The incident underscores the importance of properly configured securit…

Read More
Threat Research

QBot returns with new TTPS – Detection & Response – Security Investigation

June 7, 2022October 13, 2025 Securonix

QBot (QakBot) is a long-standing banking trojan that steals credentials and is spread via spam emails with macro-enabled Office documents. The article highlights two recent distribution methods (XLSB with hidden payload sheets and XLTM macro templates), detail…

Read More
Threat Research

DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach

June 6, 2022October 16, 2025 Securonix

Volexity details a targeted Sophos Firewall breach that leveraged a zero-day remote code execution vulnerability (CVE-2022-1040) to install a webshell, establish persistence, and conduct MITM activity that extended to external systems such as CMS websites. Sop…

Read More

Posts pagination

Previous 1 … 218 219 220 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.