Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SSO

Threat Research

The Anatomy of Wiper Malware, Part 2: Third-Party Drivers | CrowdStrike

August 17, 2022October 15, 2025 Securonix

Part 2 of the wiper series explains how threat actors exploit legitimate third-party kernel drivers to bypass detection and perform disk wiping in kernel space, focusing on ElRawDisk and EPMNTDRV. It also covers how these drivers are loaded (via Service Contro…

Read More
Threat Research

Brazil malspam pushes Astaroth (Guildma) malware

August 15, 2022October 23, 2025 Securonix

Today’s diary describes a Brazilian malspam campaign delivering Astaroth (Guildma) malware via a Boleto-themed email pretending to be from Grupo Solução & CIA. The malicious ZIP contains a Windows shortcut and a batch file used to infect a Windows host and exf…

Read More
Threat Research

A Tale of PivNoxy and Chinoxy Puppeteer | FortiGuard Labs 

August 12, 2022October 17, 2025 Securonix

Fortinet FortiGuard Labs analyzes a spearphishing campaign against a South Asian telecommunications agency, weaponizing an RTF document with Royal Road to exploit CVE-2018-0798 and drop a DLL chain leading to PoisonIvy (PivNoxy/Chinoxy) backdoors. The report o…

Read More
Threat Research

Cyble – EvilCoder Project Selling Multiple Dangerous Tools Online

August 11, 2022October 13, 2025 Securonix

Cyble researchers exposed a dark web post by a malware developer selling a powerful Windows RAT suite, including XWorm with ransomware and HVNC capabilities. The article details the toolset, persistence and anti-analysis techniques, data exfiltration, and the …

Read More
Threat Research

THREAT ANALYSIS REPORT: Bumblebee Loader – The High Road to Enterprise Domain Control

August 10, 2022October 15, 2025 Securonix

Cybereason GSOC analyzes a Bumblebee Loader infection, detailing the attack chain from initial lure to full network compromise and Active Directory takeover, with notes on post-exploitation actions, credential theft, and data exfiltration. The report also high…

Read More
Threat Research

DarkTortilla Malware Analysis

August 10, 2022October 16, 2025 Securonix

DarkTortilla is a highly configurable .NET-based crypter that delivers commodity information stealers and RATs, with targeted payloads such as Cobalt Strike and Metasploit. It uses a two-component architecture (initial loader and core processor) with strong an…

Read More
Threat Research

Raccoon Infostealer Malware Returns with New TTPS – Detection & Response – Security Investigation

August 9, 2022October 17, 2025 Securonix

Raccoon is an info-stealer malware offered as malware-as-a-service since 2019, capable of stealing passwords, cookies, autofill data, and cryptocurrency wallet data from browsers. The campaign uses phishing campaigns and trusted Windows components to drop, exe…

Read More
Threat Research

Shuckworm: Russia-Linked Group Maintains Ukraine Focus

August 5, 2022October 16, 2025 Securonix

Shuckworm (also known as Gamaredon or Armageddon) is a Russia-linked group that has focused on Ukraine since 2014, conducting espionage and information-stealing campaigns. Symantec’s observations detail the infection chain, malware families, and IOCs tied to a…

Read More
Threat Research

PyPI package ‘secretslib’ drops fileless Linux malware to mine monero

August 5, 2022October 16, 2025 Securonix

Sonatype uncovered secretslib, a PyPI package that masquerades as a secrets-management library but secretly runs an in-memory Linux cryptominer, a technique used by fileless malware. The incident also involved identity impersonation of a real Argonne National …

Read More
Threat Research

Cyble – MikuBot Spotted In The Wild

August 4, 2022October 16, 2025 Securonix

Cyble Research Labs uncovered MikuBot, a new Windows botnet that steals data and runs hidden HVNC sessions for remote access, with USB propagation and the ability to download and execute additional malware. The actor markets MikuBot with a panel, uses encrypti…

Read More
Threat Research

#StopRansomware: Zeppelin Ransomware | CISA

August 2, 2022October 16, 2025 Securonix

The article compiles a large set of file hash indicators tied to Zeppelin ransomware activity as described in the CISA alert AA22-223a, associated with the StopRansomware campaign. It presents these indicators in a purely IOC-focused format without narrative d…

Read More
Threat Research

BlueSky Ransomware: Fast Encryption via Multithreading

August 2, 2022October 16, 2025 Securonix

BlueSky ransomware is an emerging Windows-focused family employing multithreading to speed up file encryption and evade defenses. The analysis ties BlueSky to Conti v3 in structure and network behavior, while its cryptography resembles Babuk (ChaCha20 with Cur…

Read More
Threat Research

Cisco Talos shares insights related to recent cyber attack on Cisco

August 1, 2022October 16, 2025 Securonix

Cisco Talos and CSIRT describe a May 2022 compromise in which a Cisco employee’s Google account credentials (synced from a personal browser) enabled initial VPN access after MFA bypass via vishing and MFA fatigue. The investigation links the actors to an initi…

Read More
Threat Research

Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities

August 1, 2022October 16, 2025 Securonix

SmokeLoader (Dofoil) continues to leverage aging vulnerabilities to deliver its payload via a crafted phishing email chain, decrypt an embedded OLE stream, and drop a final DLL payload that is associated with zgRAT. The campaign demonstrates how attackers rely…

Read More
Threat Research

Pivoting on a SharpExt to profile Kimsuky panels for great good

July 29, 2022October 16, 2025 Securonix

SharpExt is a browser-extension malware used by Kimsuky to steal emails and attachments, as detailed by Volexity and related researchers. The campaign maps to older activity, leverages a large network of domains for delivery and C2, and targets US, Europe, and…

Read More

Posts pagination

Previous 1 … 515 516 517 … 523 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.