### #WinZipVulnerability #MarkOfTheWeb #TrendMicroZeroDayInitiative Summary: A critical vulnerability in WinZip allows attackers to bypass security measures by stripping the “Mark-of-the-Web” flag from downloaded files, potentially leading to malicious code execution on users’ systems. Users are urg…
Tag: SPYWARE
0:00 Facebook might owe you money
2:10 NSO Continued to Hack WhatsApp
4:25 iPhones Mysteriously Rebooting
6:38 Alleged Snowflake Hacker Arrested
===============================================
My Website: https://www.seytonic.com/
Follow me on TWTR: https://twitter.com/seytonic
Follow me on INSTA: https://www.instagram.com/jhonti/
===============================================
### #AppleSecurity #ThreatAnalysis #ZeroDayVulnerabilities Summary: Apple has released critical security updates addressing two actively exploited vulnerabilities in its operating systems, discovered by Google’s Threat Analysis Group. The vulnerabilities, CVE-2024-44308 and CVE-2024-44309, primarily…
📡 1st Security News RSS feed Our goal is to help make your world a safer place showcasing the latest in security news, products and services. An online global portal we offer a simple translation feature in 45 languages, informing thousands of security professionals and keeping them up to speed on t…
BlackBerry found that the LightSpy campaign (attributed to APT41) evolved into a new modular Windows surveillance framework called DeepData, which uses 12 specialized plugins to harvest messages, credentials, system data, audio and more. The report also detail…
A newly disclosed keylogger attributed to the North Korean actor Andariel targets U.S. organizations by capturing keystrokes, mouse activity, and clipboard data, then storing logs in a password-protected ZIP file. The malware uses junk-code obfuscation, in-mem…
RunningRAT, a long‑standing remote access trojan first seen in 2018, has been observed deployed from public open directories and used to deliver cryptocurrency mining tools (notably XMRig). Analysis shows me.exe drops DLLs, establishes C2 connections (24.199.1…
Summary: Researchers have uncovered an advanced version of the LightSpy spyware targeting Apple iOS, which not only enhances its data-capturing capabilities but also introduces destructive features that can render devices inoperable. This modular implant exploits known vulnerabilities in iOS and mac…
This Edureka playlist on “Cyber Security Training for Beginners” will help you learn Cyber Security from scratch. You will get to know what is the role of Cyber Security in today’s IT world and how different kind of attacks are taken care by Cyber Security. https://www.youtube.com/playlist?list=PL9o…
In a world ran by advertising, businesses and organizations are not the only ones using this powerful tool. Cybercriminals have a knack for exploiting the engine that powers online platforms by corrupting the vast reach of advertising to distribute malware en masse.
While legitimate businesses rely on ads to reach new audiences,…
Summary: The Socket Research Team has identified security risks associated with the npm package React ReExt, which collects sensitive developer information without consent. The package, claiming to be maintained by a former Sencha engineer, has been found to e…
Summary: A Vietnamese team, Viettel Cyber Security, won the inaugural Pwn2Own Ireland event, earning over $205,000 for discovering multiple zero-day vulnerabilities across various devices. The competition highlighted the importance of responsible disclosure to enhance product security for end users….
Google Threat Intelligence Group uncovered UNC5812, a suspected Russian hybrid espionage and influence operation that uses a Telegram persona “Civil Defense” to distribute Windows and Android malware and target Ukrainian military recruitment. The campaign blen…
Summary: Google’s Threat Analysis Group (TAG) has identified a critical zero-day vulnerability in Samsung mobile processors, tracked as CVE-2024-44068, which can be exploited to escalate privileges on vulnerable Android devices. This vulnerability has been linked to commercial spyware targeting Sams…
TA866 (aka Asylum Ambuscade) has operated since at least 2020 and has evolved into multi-stage intrusion campaigns that use malspam, malvertising and traffic distribution systems to deliver JavaScript/MSI downloaders and payloads such as WasabiSeed, Screenshot…