Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SSO

Threat Research

Lampion Trojan Delivered with Cloud-Based Sharing | Cofense

September 2, 2022October 14, 2025 Securonix

Lampion, a banking Trojan, was analyzed as delivered through a phishing email that directs victims to a cloud-based link to obtain a ZIP file. The campaign uses a VBScript loader and WScript to fetch DLL payloads, which are injected into memory to steal bankin…

Read More
Threat Research

Credential Gathering From Third-Party Software

September 2, 2022October 15, 2025 Securonix

The article examines how third-party software can store credentials insecurely and how attackers can retrieve them to broaden access, with concrete examples across WinSCP, Git, RDCMan, OpenVPN, and various browsers. It also discusses protections in Cortex XDR …

Read More
Threat Research

TA453 Uses Impersonation to Capitalize on FOMO | Proofpoint US

September 2, 2022October 15, 2025 Securonix

TA453, an Iran-aligned actor, expanded its social engineering with Multi-Persona Impersonation (MPI), using multiple actor-controlled personas within a single email thread to boost campaign credibility. The technique targets researchers and nuclear security do…

Read More
Threat Research

BRONZE PRESIDENT Targets Government Officials

September 1, 2022October 14, 2025 Securonix

Bronze President targeted government officials using PlugX payloads across multiple documents and delivery methods. The campaign involved malicious archives, shortcuts, DLLs, and encrypted payloads linked to PlugX, with identified C2 servers associated to the …

Read More
Threat Research

#StopRansomware: Vice Society | CISA

August 30, 2022October 15, 2025 Securonix

Joint FBI/CISA/MS-ISAC advisory details Vice Society’s ransomware operations, highlighting their methods, IOCs, and recommended mitigations for education-sector defenders. It notes that Vice Society uses variants such as Hello Kitty/Five Hands and Zeppelin and…

Read More
Threat Research

Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks – Avast Threat Labs

August 29, 2022October 17, 2025 Securonix

Avast Threat Labs details Bobik, a .NET Remote Access Trojan that now functions as a DDoS module within a botnet used by the pro-Russian group NoName057(16) to target Ukraine and nearby countries. The report maps the botnet’s C2 infrastructure, the multi-stage…

Read More
Threat Research

BumbleBee a New Modular Backdoor Evolved From BookWorm

August 26, 2022October 16, 2025 Securonix

BumbleBee is described as a refactored, modular backdoor evolved from BookWorm, featuring a two-app architecture (server/controller and client/slave) with layered deployment and a loader chain that uses a legitimate executable to run shellcode. The campaign ap…

Read More
Threat Research

HWP File Disguised as Personal Profile Form (OLE Object) – ASEC BLOG

August 26, 2022October 13, 2025 Securonix

ASEC researchers identified a malicious HWP document that exploits OLE objects and a Flash vulnerability (CVE-2018-15982), using embedded links to trigger execution. The attack drops files in %TEMP%, hides OLE objects, and can download and run additional paylo…

Read More
Threat Research

Malicious Word Files Targeting Specific Individuals Related to North Korea – ASEC BLOG

August 23, 2022October 17, 2025 Securonix

The ASEC analysis team reports the ongoing distribution of malicious Word documents targeting individuals tied to national defense and North Korea, with filenames referencing real people. The embedded macros download PowerShell scripts, collect host informatio…

Read More
Threat Research

Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems

August 23, 2022October 16, 2025 Securonix

Securonix Threat Labs uncovered a Golang-based GO#WEBBFUSCATOR campaign that leverages a James Webb image and obfuscated Go payloads to infect targets. The attack chain starts with a phishing Office attachment, downloads a malicious template, and uses DNS-base…

Read More
Threat Research

Cyble – Mini Stealer: Possible Predecessor Of Parrot Stealer

August 22, 2022October 17, 2025 Securonix

Cyble researchers report a threat actor began releasing MiniStealer’s builder and panel for free, with Parrot Stealer allegedly based on MiniStealer. The campaign targets Windows systems and steals data from Chromium-based browsers and FTP applications, signal…

Read More
Threat Research

Advanced BEC Scam Campaign Targeting Executives on O365

August 22, 2022October 17, 2025 Securonix

Mitiga uncovered an advanced business email compromise (BEC) campaign that targets executives via Office 365, combining high-end spear-phishing with adversary-in-the-middle (AiTM) techniques to bypass MFA and achieve persistence. Attackers monitor significant …

Read More
Threat Research

Demystifying Qbot Malware

August 19, 2022October 16, 2025 Securonix

Qbot (QakBot) infections surged in 2022, with Trellix SecOps documenting its evolving delivery vectors and detection strategies to outpace defenses. The post details Qbot’s infection chain, MITRE technique mappings, IOCs, and Trellix detection/hunting guidance…

Read More
Threat Research

Roasting 0ktapus: The phishing campaign going after Okta identity credentials

August 19, 2022October 19, 2025 Securonix

Security researchers describe a phishing campaign attributed to 0ktapus that targets Okta identity credentials, using a large set of look-alike domains to harvest user data. The article catalogs hundreds of IPs and domains used in the campaign’s infrastructure…

Read More
Threat Research

Kimsuky’s GoldDragon cluster and its C2 operations

August 18, 2022October 18, 2025 Securonix

Kimsuky’s GoldDragon cluster is a multi-stage operation targeting Korea-related entities, evolving rapidly with new infection chains and a layered C2 network. The campaign starts with spear-phishing and uses HTML Application (HTA), VBScript, and mshta to fetch…

Read More

Posts pagination

Previous 1 … 514 515 516 … 523 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.