Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SSO

Threat Research

From RM3 to LDR4: URSNIF Leaves Banking Fraud Behind

October 13, 2022October 16, 2025 Securonix

URSNIF’s LDR4 variant marks a shift from banking fraud to remote access capabilities, dropping banking modules in favor of enabling VNC and remote shell access on compromised machines. It introduces API call obfuscation, a redesigned configuration/storage stru…

Read More
Threat Research

Spyder Loader: Malware Seen in Recent Campaign Targeting Organizations in Hong Kong

October 13, 2022October 13, 2025 Securonix

Security researchers tie the Spyder Loader (Trojan.Spyload) to a long-running intelligence-gathering operation called Operation CuckooBees, active since at least 2019 and targeting intellectual property. The loader is a 64-bit PE DLL derived from sqlite3.dll, …

Read More
Threat Research

The Anatomy of Wiper Malware, Part 4: Helper Techniques

October 10, 2022October 14, 2025 Securonix

This fourth post in a four-part series examines the rarely used “helper” techniques wipers employ to augment data destruction, such as manipulating VSS, filling disk space, and altering boot configurations. It covers methods like shadow-copy deletion, space-fi…

Read More
Threat Research

Agent Tesla Malware Analysis: WSHRAT Acting as a Dropper

October 10, 2022October 13, 2025 Securonix

Uptycs reports a new campaign where WSHRAT acts as a dropper for Agent Tesla through a multi-stage infection chain emphasizing evasion techniques like steganography and in-memory DLL loading. The campaign begins with phishing emails containing GZ and R00 archi…

Read More
Threat Research

The Fresh Phish Market: Behind the Scenes of the Caffeine Phishing-as-a-Service Platform

October 5, 2022October 14, 2025 Securonix

Security researchers outline detection strategies for the Caffeine phishing service platform, including endpoint and network indicators. They provide YARA rules, domain infrastructure details, and defensive best practices to mitigate PhaaS-based phishing campa…

Read More
Threat Research

MAR-10365227-2.v1 – Impacket 2 | CISA

October 4, 2022October 20, 2025 Securonix

Cybersecurity analysts from CISA analyzed HyperBro malware samples linked to a Defense Industrial Base incident, detailing a backdoor capable of file transfer, keystroke logging, and remote command execution. The report covers four analyzed files, a C2 endpoin…

Read More
Threat Research

Hiding in the XML – InQuest

October 4, 2022October 16, 2025 Securonix

The article examines how Office CustomXMLParts can secretly store and execute a payload, using a hex-encoded DLL embedded in XML and retrieved via VBA in documents. It shows how a YARA rule and code structure detect and decode the payload, and notes that such …

Read More
Threat Research

Excel Document Delivers Multiple Malware by Exploiting CVE-2017-11882 – Part II | FortiGuard Labs

October 3, 2022October 16, 2025 Securonix

FortiGuard Labs analyzed an Excel document delivering Redline malware via CVE-2017-11882. The loader uses in-memory techniques and persistence via Task Scheduler to exfiltrate sensitive data to a C2 server over HTTP using a WCF SOAP channel. Hashtags: #Redline…

Read More
Threat Research

Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims

October 3, 2022October 13, 2025 Securonix

BlackBerry Research & Intelligence uncovers a Mustang Panda operation targeting Myanmar that uses PlugX malware delivered via legitimate HP utilities embedded in RAR archives. The campaign employs DLL side-loading and domain-based C2 infrastructure masqueradin…

Read More
Threat Research

SolarMarker Malware Activity

September 30, 2022October 14, 2025 Securonix

eSentire has observed a significant rise in SolarMarker infections delivered via drive-by download attacks that rely on social engineering to persuade users to execute malware disguised as document templates. SolarMarker is a modular information-stealing malwa…

Read More
Threat Research

CrowdStrike Falcon® Platform Identifies Supply Chain Attack via a Trojanized Comm100 Chat Installer – crowdstrike.com

September 28, 2022October 17, 2025 Securonix

CrowdStrike Falcon platform identified a supply chain attack tied to a trojanized Comm100 Live Chat installer, delivering a backdoor via a signed installer. The activity, with a suspected China nexus, involved a second-stage script, loader DLL, and multiple C2…

Read More
Threat Research

Leveraging Microsoft Office Documents to Deliver Agent Tesla and njRat | FortiGuard Labs 

September 27, 2022October 15, 2025 Securonix

Fortinet FortiGuard Labs analyzed malicious Microsoft Office documents that abused legitimate sites MediaFire and Blogger to deliver two malware variants: Agent Tesla and njRat (Bladabindi). The operation uses a multi-stage chain—VBA macros, mshta, and PowerSh…

Read More
Threat Research

Lazarus ‘Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto

September 26, 2022October 15, 2025 Securonix

Operation In(ter)ception continues Lazarus’ macOS malware activity, using decoy job postings for Coinbase and Crypto.com to lure victims and install a multi-stage payload. The campaign features persistence via a LaunchAgent, staged download components, and har…

Read More
Threat Research

Hunting for Unsigned DLLs to Find APTs

September 21, 2022October 16, 2025 Securonix

Threat actors increasingly rely on unsigned DLL loading to execute payloads, enabling stealthy operations by abusing signed processes. The investigation highlights Stately Taurus (PKPLUG/Mustang Panda) and Selective Pisces (Lazarus Group) and shows how unsigne…

Read More
Threat Research

More Than Meets the Eye: Exposing a Polyglot File That Delivers IcedID

September 21, 2022October 14, 2025 Securonix

Unit 42 reveals a polyglot CHM file used to deliver the IcedID information stealer, weaving deception to evade detection by showing a benign decoy window first and launching malicious activity on a second run. The threat chain includes phishing with a ZIP, an …

Read More

Posts pagination

Previous 1 … 512 513 514 … 523 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.