RansomHub Ransomware Group Targets 210 Victims Across Critical Sectors https://firewall.firm.in/wp-content/uploads/2024/09/ransomware.jpg Threat actors linked to the RansomHub ransomware group encrypted and exfiltrated data from at least 210 victims since its inception in February 2024, the U.S. government said. The victims span various sectors, including water and wastewater, information technology, government services and facilities, healthcare and public health, emergency services, food and ...
Read More »Vulnerabilities & Exploits
Iranian Hackers Set Up New Network to Target U.S. Political Campaigns
Iranian Hackers Set Up New Network to Target U.S. Political Campaigns https://firewall.firm.in/wp-content/uploads/2024/09/Iranianhackers.jpg Aug 30, 2024Ravie LakshmananCyber Threat / Cyber Espionage Cybersecurity researchers have unearthed new network infrastructure set up by Iranian threat actors to support activities linked to the recent targeting of U.S. political campaigns. Recorded Future’s Insikt Group has linked the infrastructure to a hacking group it tracks as ...
Read More »North Korean Hackers Deploy FudModule Rootkit via Chrome Zero-Day Exploit
North Korean Hackers Deploy FudModule Rootkit via Chrome Zero-Day Exploit https://firewall.firm.in/wp-content/uploads/2024/08/chrome.jpg Aug 31, 2024Ravie LakshmananRootkit / Threat Intelligence A recently patched security flaw in Google Chrome and other Chromium web browsers was exploited as a zero-day by North Korean actors in a campaign designed to deliver the FudModule rootkit. The development is indicative of the persistent efforts made by the ...
Read More »Google says Russian hackers using iOS, Chrome flaws to steal users data – ET CISO
Google says Russian hackers using iOS, Chrome flaws to steal users data – ET CISO https://etimg.etb2bimg.com/thumb/msid-112934730,imgsize-25018,width-1200,height=765,overlay-etciso/data-breaches/google-says-russian-hackers-using-ios-chrome-flaws-to-steal-users-data.jpg The Russian state-sponsored APT29 hacking group has been observed using the same iOS and Chrome on Android exploits created by commercial spyware vendors like NSO Group and Intellexa in a series of cyberattacks between November 2023 and July 2024. “The campaigns first delivered an ...
Read More »Cyberattackers Exploit Google Sheets for Malware Control in Likely Espionage Campaign
Cyberattackers Exploit Google Sheets for Malware Control in Likely Espionage Campaign https://firewall.firm.in/wp-content/uploads/2024/08/hackers.jpg Cybersecurity researchers have uncovered a novel malware campaign that leverages Google Sheets as a command-and-control (C2) mechanism. The activity, detected by Proofpoint starting August 5, 2024, impersonates tax authorities from governments in Europe, Asia, and the U.S., with the goal of targeting over 70 organizations worldwide by means ...
Read More »Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32
Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32 https://firewall.firm.in/wp-content/uploads/2024/08/code.png Aug 29, 2024Ravie LakshmananCyber Espionage / Malware A non-profit supporting Vietnamese human rights has been the target of a multi-year campaign designed to deliver a variety of malware on compromised hosts. Cybersecurity company Huntress attributed the activity to a threat cluster known as APT32, a Vietnamese-aligned hacking crew that’s ...
Read More »U.S. Agencies Warn of Iranian Hacking Group’s Ongoing Ransomware Attacks
U.S. Agencies Warn of Iranian Hacking Group’s Ongoing Ransomware Attacks https://firewall.firm.in/wp-content/uploads/2024/08/iran-hackers.png U.S. cybersecurity and intelligence agencies have called out an Iranian hacking group for breaching multiple organizations across the country and coordinating with affiliates to deliver ransomware. The activity has been linked to a threat actor dubbed Pioneer Kitten, which is also known as Fox Kitten, Lemon Sandstorm (formerly Rubidium), ...
Read More »Fortra Issues Patch for High-Risk FileCatalyst Workflow Security Vulnerability
Fortra Issues Patch for High-Risk FileCatalyst Workflow Security Vulnerability https://firewall.firm.in/wp-content/uploads/2024/08/password.png Aug 28, 2024Ravie LakshmananVulnerability / Data Security Fortra has addressed a critical security flaw impacting FileCatalyst Workflow that could be abused by a remote attacker to gain administrative access. The vulnerability, tracked as CVE-2024-6633, carries a CVSS score of 9.8, and stems from the use of a static password to ...
Read More »macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users
macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users https://firewall.firm.in/wp-content/uploads/2024/08/chinese-hacker.png Aug 27, 2024Ravie LakshmananCyber Espionage / Malware Users of Chinese instant messaging apps like DingTalk and WeChat are the target of an Apple macOS version of a backdoor named HZ RAT. The artifacts “almost exactly replicate the functionality of the Windows version of the backdoor and differ only ...
Read More »Microsoft Fixes ASCII Smuggling Flaw That Enabled Data Theft from Microsoft 365 Copilot
Microsoft Fixes ASCII Smuggling Flaw That Enabled Data Theft from Microsoft 365 Copilot https://firewall.firm.in/wp-content/uploads/2024/08/ms.png Aug 27, 2024Ravie LakshmananAI Security / Vulnerability Details have emerged about a now-patched vulnerability in Microsoft 365 Copilot that could enable the theft of sensitive user information using a technique called ASCII smuggling. “ASCII Smuggling is a novel technique that uses special Unicode characters that mirror ...
Read More »