Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SSO

Threat Research

A LNK Between Browsers: Hunting Methodologies and Extension Abusing Actors | Mandiant

April 27, 2023October 16, 2025 Securonix

Mandiant outlines a chain where a tampered LNK shortcut launches a legitimate Chromium-based browser, loading a malicious extension to achieve persistence. The research tracks multiple malware families—RILIDE, BRAINFOG, BRAINSTORM, and BRAINLINK—and details th…

Read More
Threat Research

Cyble – BlackBit Ransomware: A Threat From The Shadows Of LokiLocker

April 27, 2023October 16, 2025 Securonix

BlackBit is a LokiLocker ransomware variant that operates under a RaaS model and shows signs of being in early development with targeted persistence and evasion capabilities. The strain deploys multiple defense-evasion techniques, persistence mechanisms, and u…

Read More
Threat Research

CoinMiner (KONO DIO DA) Distributed to Linux SSH Servers – ASEC BLOG

April 25, 2023October 14, 2025 Securonix

ASEC reports ongoing campaigns where XMRig CoinMiner is installed on poorly managed Linux SSH servers, using SHC-built malware and creating backdoor SSH accounts for persistence. The attacks, attributed to the KONO DIO DA threat actor, involve dictionary/dicti…

Read More
Threat Research

Cyble – Citrix Users At Risk: AresLoader Spreading Through Disguised GitLab Repo

April 25, 2023October 16, 2025 Securonix

CRIL researchers describe AresLoader, a multiclass loader used to spread LummaStealer and IcedID via a disguised GitLab repo, targeting Citrix users. The malware uses multi-stage delivery, dynamic API resolution, and various anti-analysis techniques to evade d…

Read More
Threat Research

Elastic Security Labs discovers the LOBSHOT malware — Elastic Security Labs

April 24, 2023October 19, 2025 Securonix

Elastic Security Labs uncovers LOBSHOT, a stealthy hVNC-capable malware tied to TA505, spread via malvertising campaigns that impersonate legitimate software. The analysis provides a YARA signature and a configuration extractor, detailing infection, persistenc…

Read More
Threat Research

Magecart threat actor rolls out convincing modal forms

April 22, 2023October 14, 2025 Securonix

Researchers detail a Magecart campaign in which a threat actor uses a custom fraudulent modal to hijack checkout and steal credit card data from compromised Prestashop stores. The skimmer relies on a well-crafted modal, dynamic HTML, obfuscated code, and a red…

Read More
Threat Research

Dog Hunt: Finding Decoy Dog Toolkit via Anomalous DNS Traffic

April 21, 2023October 17, 2025 Securonix

Infoblox identifies a rare DNS-based toolkit named Decoy Dog, built around the Pupy RAT, observed in enterprise networks through DNS beacons and encrypted DNS traffic. The report links possible Earth Berberoka activity and outlines three infrastructure models …

Read More
Threat Research

Package names repurposed to push malware on PyPI

April 20, 2023October 15, 2025 Securonix

A malicious PyPI package named termcolour reappeared in March as a three-stage downloader, illustrating how repurposing an abandoned package name can seed a supply-chain attack. The incident shows how PyPI’s name-reuse policy and lack of visibility into who re…

Read More
Threat Research

Activity Targeting Crypto Asset Exchangers for Parallax RAT Infection – JPCERT/CC Eyes

April 20, 2023October 17, 2025 admin

JPCERT/CC documented an attack around February 2023 that targeted a crypto asset exchanger with Parallax RAT delivered via spam emails directing victims to a Google Drive link. The operation used OneNote files with embedded VBS, a PowerShell payload, Windows s…

Read More
Threat Research

AllaKore(d) the SideCopy Train

April 19, 2023October 13, 2025 CTI

Identifying Connected Infrastructure and Management Activities Introduction This blog post seeks to build on recent public reporting on…

Read More
Threat Research

Securonix Threat Labs Security Advisory: New OCX#HARVESTER Attack Campaign Leverages Modernized More_eggs Suite to Target Victims

April 19, 2023October 16, 2025 Securonix

OCX#HARVESTER is a threat campaign by Securonix Threat Labs leveraging the More_eggs malware suite to target financial-sector victims, with activity observed from late 2022 through early 2023 and new C2 infrastructure shifts. The campaign uses image-based LNK …

Read More
Threat Research

Daggerfly: APT Actor Targets Telecoms Company in Africa

April 17, 2023October 13, 2025 Securonix

Symantec Threat Hunter details Daggerfly/MgBot activity targeting telecoms in Africa and Asia, highlighting a modular malware framework used for extensive information gathering. The campaign shows ongoing tool development, credential dumping, AD enumeration, a…

Read More
Threat Research

Bumblebee Malware Distributed Via Trojanized Installer Downloads

April 14, 2023October 15, 2025 Securonix

Two sentences summarizing the article. Bumblebee malware was distributed via trojanized installers for Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace, using a malicious Google Ad chain and a compromised WordPress site to drive victims to fake download p…

Read More
Threat Research

Trigona Ransomware Attacking MS-SQL Servers – ASEC BLOG

April 13, 2023October 17, 2025 Securonix

Trigona ransomware campaigns target poorly managed MS-SQL servers, leveraging a CLR SqlShell dropper and service-based execution to escalate privileges and encrypt data. The operation includes credential abuse, registry and Run key persistence, and a ransom no…

Read More
Threat Research

Technical Analysis of Trigona Ransomware

April 12, 2023October 13, 2025 Securonix

Trigona is a Delphi-based ransomware that encrypts files using RSA and AES with a novel residual block termination, adds a multi-step decryption workflow, and recently gained a data wiper capability. ThreatLabz notes overlap in tactics with BlackCat/ALPHV, but…

Read More

Posts pagination

Previous 1 … 503 504 505 … 523 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.