Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: SSO

Threat Research

Conti Affiliate Exposed: New Domain Names, IP Addresses and Email…

March 15, 2022October 15, 2025 Securonix

TRU and BreakPoint Labs uncovered a Conti affiliate operating an automated Cobalt Strike infrastructure, exposing new domain names, IP addresses, and emails used for command-and-control. The findings link Conti operations to Trickbot, BazarLoader, IcedID, Five…

Read More
Threat Research

A Whirlwind Tour Of Crypto Phishing

March 15, 2022October 16, 2025 Securonix

The article surveys how crypto phishing relies on malvertising, social media campaigns, and fake wallet prompts to steal seed phrases, wallets, and NFTs—from Ledger impersonations to Vitalik Buterin fakery and ApeCoin scams. It also highlights techniques like …

Read More
Threat Research

Mēris and TrickBot standing on the shoulders of giants – Avast Threat Labs

March 14, 2022October 18, 2025 Securonix

Avast Threat Labs connects Meris, TrickBot, and Glupteba campaigns to a single C2 that covertly controls roughly 230,000 MikroTik routers in a botnet-as-a-service. The research traces exploitation of CVE-2018-14847, wides…

Read More
Threat Research

APT Attack Being Distributed as Windows Help File (*.chm) – ASEC BLOG

March 11, 2022October 19, 2025 Securonix

ASEC uncovered malware distributed as Windows Help Files (.chm) aimed at Korean users, delivered via compressed email attachments. When opened, the CHM dropper spawns VBScript and PowerShell payloads, persists through a Run key, and downloads a second-stage do…

Read More
Threat Research

Suspected DarkHotel APT Activity Update

March 11, 2022October 16, 2025 Securonix

Threat researchers describe a first-stage spearphishing campaign targeting luxury hotels in Macao that used a password-protected Excel file with macros to drop and execute further payloads via scheduled tasks and PowerShell. The operation, attributed to DarkHo…

Read More
Threat Research

奇安信威胁情报中心

March 9, 2022October 22, 2025 Securonix

A Ukrainian-focused campaign linked to UNC1151 is analyzed, describing CHM-based loaders, obfuscated VBScript, and memory-resident backdoors that connect to C2 servers, echoing Ghostwriter/UNC1151 activity. The finding in…

Read More
Threat Research

DirtyMoe: Worming Modules – Avast Threat Labs

March 9, 2022October 15, 2025 Securonix

DirtyMoe’s worming module autonomously spreads by exploiting several known vulnerabilities and by generating target IPs based on geolocation, enabling mass-scale infection and lateral movement. This Avast Threat Lab analysis details the worm’s kill chain, the …

Read More
Threat Research

Qakbot infection with Cobalt Strike and VNC activity

March 9, 2022October 16, 2025 Securonix

A Windows host was infected with Qakbot (Qbot) on 2022-03-14, with Cobalt Strike and VNC remote-access activity appearing about 17 hours later. The incident highlights the obama166 distribution tag, the DLLs downloaded during infection, and notable changes in …

Read More
Threat Research

Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and “PrintNightmare” Vulnerability | CISA

March 8, 2022October 14, 2025 Securonix

FBI and CISA warn that Russian state-sponsored cyber actors gained network access by exploiting default MFA configurations and the PrintNightmare vulnerability, enabling document exfiltration from an NGO via compromised credentials and MFA bypass. The advisory…

Read More
Threat Research

Decoding a DanaBot Downloader

March 7, 2022October 16, 2025 Securonix

DanaBot is delivered via a VBS-based downloader that uses a distinctive obfuscation scheme and is associated with a social-engineering lure built around unclaimed property. The article also covers three methods to decode the VBS, noting DanaBot’s ties to the S…

Read More
Threat Research

Fake Purchase Order Used to Deliver Agent Tesla | FortiGuard Labs 

February 28, 2022October 18, 2025 Securonix

FortiGuard Labs uncovered a phishing operation masquerading as a purchase order to a Ukrainian manufacturer, delivering Agent Tesla via a PPAM PowerPoint add-in. The campaign uses a multi-stage dropper with Bit.ly and MediaFire stages, ends with PowerShell-bas…

Read More
Threat Research

Phishers Spoof Power BI to Harvests Microsoft Credentials

February 18, 2022October 19, 2025 admin

Microsoft Power BI is being impersonated in a credential-harvesting campaign that uses realistic-looking notification emails and fake sign-in pages to collect Microsoft account credentials. The campaign leverages stolen credentials to create believable notific…

Read More
Threat Research

Technical Analysis of the DDoS Attacks against Ukrainian Websites

February 9, 2022October 14, 2025 Securonix

Ukrainian banks and government websites were targeted by a moderate DDoS campaign attributed to the Katana botnet, a Mirai variant used to flood services. Preparation for the attack appears to have begun as early as February 13, with delivery through exploited…

Read More
Threat Research

What’s with the shared VBA code between Transparent Tribe and other threat actors?

February 1, 2022October 13, 2025 Securonix

Researchers link VBA-based samples to threat actors in South Asia, showing code reuse across groups such as Transparent Tribe, SideCopy, Donot, and Hangover through final payloads like CrimsonRAT and ObliqueRAT. The findings emphasize shared VBA patterns, cros…

Read More
Threat Research

Zoom For You — SEO Poisoning to Distribute BATLOADER and Atera Agent

January 28, 2022October 17, 2025 Securonix

Mandiant ties a campaign that uses SEO poisoning to distribute BATLOADER and ATERA Agent to techniques disclosed after a CONTI ransomware affiliate leak in August 2021. The report also provides extensive indicators, a YARA rule, and a MITRE ATT&CK mapping span…

Read More

Posts pagination

Previous 1 … 520 521 522 523 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.