Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

Cyble – Hydra Android Malware Distributed Via Play Store

June 6, 2022October 13, 2025 Securonix

Cyble Research Labs identified an Android malware variant distributed via the Play Store that acts as a Hostile Downloader to fetch the Hydra Banking Trojan. The app masquerades as Document Manager, uses fake update prompts, and communicates with a TOR-enabled…

Read More
Threat Research

Telerik UI exploitation leads to cryptominer, Cobalt Strike infections

June 5, 2022October 19, 2025 Securonix

An unknown threat actor exploits CVE-2019-18935 in Telerik UI for ASP.NET AJAX to seize control of Windows servers, drop a Cobalt Strike beacon, and stage further malware via PowerShell commands. Sophos MTR links these campaigns to earlier Blue Mockingbird act…

Read More
Threat Research

Detect the Follina MSDT Vulnerability (CVE-2022-30190) with Qualys Multi-Vector EDR & Context XDR | Qualys Security Blog

June 3, 2022October 14, 2025 Securonix

Follina (CVE-2022-30190) is a remote code execution vulnerability in Microsoft Office that can be exploited without macros by loading an external reference which ultimately invokes the MSDT tool to run PowerShell. The article outlines the attack flow, the tech…

Read More
Threat Research

Internet Storm Center Diary 2024-05-22

May 27, 2022October 15, 2025 Securonix

An ISC guest diary analyzes the modern coin miner malware variant “redtail” and its capabilities across four CPU architectures, showing how attackers gain initial SSH access, upload payloads, and establish persistence on compromised hosts. The report traces tw…

Read More
Threat Research

Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years

May 26, 2022October 17, 2025 Securonix

Aoqin Dragon is a long-running Chinese-speaking APT tracked by SentinelLabs, active since 2013 and targeting government, education, and telecom organizations in Southeast Asia and Australia. The group uses document exploits, fake removable devices, DLL hijacki…

Read More
Threat Research

Cyble – Bumblebee Loader On The Rise

May 26, 2022October 14, 2025 Securonix

Bumblebee is a sophisticated loader that replaces BazarLoader and delivers frameworks like Cobalt Strike, Shellcode, Sliver, and Meterpreter, while also dropping other malware such as ransomware. It is distributed via spear-phishing ISO downloads, employs exte…

Read More
Threat Research

Shining the Light on Black Basta

May 25, 2022October 14, 2025 Securonix

Researchers document Black Basta’s observed TTPs during a recent incident response, detailing lateral movement, defense evasion, discovery, and encryption activities against Hyper-V environments and Veeam backups. The post also provides a technical breakdown o…

Read More
Threat Research

Tales From the Honeypot: WatchDog Evolves With a New Multi-Stage Cryptojacking Attack

May 25, 2022October 15, 2025 Securonix

WatchDog has evolved a multi-stage cryptojacking campaign that targets exposed Docker Engine API endpoints and Redis servers, repurposing TeamTNT payloads while attempting to foil attribution. The attack uses timestomping, process hiding, and worm-like propaga…

Read More
Threat Research

Will the Real Msiexec Please Stand Up? Exploit Leads to Data Exfiltration

May 24, 2022October 15, 2025 Securonix

Threat actors exploited CVE-2021-44077 to gain initial access to an internet-facing ManageEngine SupportCenter Plus instance, planted a web shell, and began days-long data exfiltration via web shell and RDP. The operation involved Plink-based SSH tunneling, LS…

Read More
Threat Research

To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions

May 20, 2022October 18, 2025 Securonix

UNC2165 is analyzed as overlapping with Evil Corp activities and shifting toward ransomware deployments such as HADES and LOCKBIT, leveraging FAKEUPDATES, BEACON, and post-exploitation techniques to breach networks while evading sanctions. The report traces th…

Read More
Threat Research

SocGholish Campaigns and Initial Access Kit

May 13, 2022October 16, 2025 Securonix

The article analyzes SocGholish (aka FAKEUPDATES) campaigns and how they function as a major initial-access vector through fake updates, compromised sites, and phishing-style techniques, detailing loader chains and observed IOCs. It covers campaigns delivering…

Read More
Threat Research

Space Pirates: исследуем инструменты и связи новой хакерской группировки

April 18, 2022October 16, 2025 Securonix

Space Pirates is an Asia-rooted advanced threat group whose activities span several backdoors and loaders, targeting government and aerospace/energy sectors in Russia, Georgia, and Mongolia. The report ties Space Pirates to multiple other APTs and tooling exch…

Read More
Threat Research

Onyx Ransomware Report – CYFIRMA

April 12, 2022October 16, 2025 Securonix

Onyx is a ransomware observed in April 2022 that encrypts files, appends the .ampkcz extension, and leaves a readme.txt ransom note. It uses several evasion, persistence, and exfiltration techniques, including process checks, startup-folder modifications, and …

Read More
Threat Research

Cybereason vs. Quantum Locker Ransomware

April 11, 2022October 15, 2025 Securonix

Quantum Locker is a fast, human-operated ransomware strain linked to MountLocker that encrypts data within hours of infection, often leaving defenders little time to respond. Cybereason Nocturnus classifies the threat as HIGH, notes a RansomOps playbook, and h…

Read More
Threat Research

COBALT MIRAGE conducts ransomware operations in U.S.

April 11, 2022October 15, 2025 Securonix

Secureworks CTU researchers analyzed COBALT MIRAGE’s ransomware operations in the United States, spotting two intrusion clusters: Cluster A uses BitLocker/DiskCryptor for opportunistic ransomware, while Cluster B pursues targeted intrusions with some ransomwar…

Read More

Posts pagination

Previous 1 … 219 220 221 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.