Fortinet disclosed a critical unauthenticated stack-based buffer overflow vulnerability (CVE-2025-32756) affecting multiple products, allowing remote code execution by attackers. This vulnerability has been exploited in the wild targeting FortiVoice appliances, impacting several Fortinet products. #Fortinet #FortiVoice
Tag: THREAT HUNTING
Proactive threat hunting focuses on detecting and neutralizing cyber threats before attacks occur by analyzing early indicators such as newly registered domains and malicious hosting activity. Silent Push supports this approach with advanced intelligence and tools that provide deep visibility into adversarial infrastructure, enhancing organizational cyber defenses. #SilentPush #Cybersecurity…
Effective Incident Response (IR) hinges on measuring performance through Key Performance Indicators (KPIs) to quantify success and reveal gaps in processes, tools, and team efficiency. The article dissects 20 essential IR KPIs across time-based, volume, accura…
Annual cybersecurity vendor reports typically follow a structured format that includes key sections on threat overview, emerging attack techniques, and trend analysis, often supported by statistics on threat prevalence and impact. These reports highlight ongoing and evolving cyber threats like sophisticated nation-state cyber espionage, cybercriminal operations targeting critical infrastructure, and increasing influence operations—underscoring the importance of adaptive defense strategies. #CyberSpyware #RansomCybercrime
Jared Atkinson introduced the concept of Execution Modality to better understand and detect malware techniques by focusing on how malicious behaviors are executed rather than just what they do. This approach emphasizes detection as close to the operating system’s source of truth as possible, improving visibility and robustness in threat detection. #ExecutionModality #ElasticSecurity
This web content introduces various free and affordable online platforms for learning penetration testing and cybersecurity skills in 2025. It highlights resources like Hack The Box Academy, PortSwigger Web Security Academy, and TryHackMe to help aspiring pentesters accelerate their journey. Affected: cybersecurity training platforms, learners, and aspiring penetration testers
Malicious threat actors have been abusing Linux .desktop files by embedding obfuscated junk code to execute commands that download malware, often disguising malicious PDF files hosted on Google Drive as distractions. This blog provides detailed hunting techniques and proactive detection queries for identifying such threats, focusing on behaviors in Linux desktop environments and related process executions. #GoogleThreatIntelligence #Linux #MalwareHunting
The Genians Security Center (GSC) has uncovered the recent “Operation: ToyBox Story” campaign by North Korean-linked APT37, involving sophisticated spear-phishing attacks using trusted cloud services. The campaign primarily delivered the RoKRAT remote access trojan through fileless malware techniques, targeting South Korean and other regional organizations. Affected: South Korean think tanks, government…
Cybercriminals are increasingly targeting overlooked infrastructure such as outdated software, IoT devices, and open-source packages to launch attacks at scale. Threat actors are shifting their focus from high-value targets to vulnerable “infrastructure” components, reshaping intrusion, persistence, and evasion strategies. Affected: Organizations relying on outdated systems, IoT device users, open-source software ecosystems….
APT37 conducted spear phishing attacks targeting North Korea-related activists by distributing malicious LNK files via Dropbox disguised as academic conference invitations. The group leveraged legitimate cloud services like Dropbox, pCloud, and Yandex for comm…
Google Threat Intelligence Group uncovered LOSTKEYS, a new malware by Russian-linked COLDRIVER targeting high-profile individuals to steal files and system data via a multi-stage PowerShell infection chain. Protection includes Google safety features and user a…
Pure Crypter is a malware-as-a-service loader widely used by threat actors, employing advanced evasion techniques to bypass Windows 11 security. Distributed via Telegram, it uses deceptive marketing with FUD claims, but multiple AVs detect it. eSentire develop…
Check Point Research revealed a sophisticated phishing campaign using Discord to target crypto users via fake Collab.Land bots and phishing sites linked to Inferno Drainer. Despite shutdown claims, Inferno Drainer evolved with stealthy smart contracts, leading…
This content discusses the threats posed by malicious files, particularly those found in compressed formats, and emphasizes the importance of proper monitoring and threat detection mechanisms. It explains how to correlate file events to effectively track the o…
Security Operations Center (SOC) teams are increasingly challenged by advanced adversaries who can evade traditional security tools, necessitating a multi-layered detection approach like Network Detection and Response (NDR). This shift is driven by the evoluti…