Iran-Linked IOCONTROL Malware Targets SCADA and Linux-Based IoT Platforms https://firewall.firm.in/wp-content/uploads/2024/12/exploit.png Dec 13, 2024The Hacker NewsIoT Security / Operational Technology Iran-affiliated threat actors have been linked to a new custom malware that’s geared toward IoT and operational technology (OT) environments in Israel and the United States. The malware has been codenamed IOCONTROL by OT cybersecurity company Claroty, highlighting its ability to ...
Read More »Vulnerabilities & Exploits
Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection
Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection https://firewall.firm.in/wp-content/uploads/2024/12/openwrt.png Dec 13, 2024The Hacker NewsLinux / Vulnerability A security flaw has been disclosed in OpenWrt’s Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicious firmware packages. The vulnerability, tracked as CVE-2024-54143, carries a CVSS score of 9.3 out of a maximum of 10, indicating ...
Read More »390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits https://firewall.firm.in/wp-content/uploads/2024/12/github.png Dec 13, 2024Ravie LakshmananCyber Attack / Malware A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000 credentials. The malicious activity is part of a broader attack campaign undertaken ...
Read More »DoJ Indicts 14 North Koreans for $88M IT Worker Fraud Scheme Over Six Years
DoJ Indicts 14 North Koreans for $88M IT Worker Fraud Scheme Over Six Years https://firewall.firm.in/wp-content/uploads/2024/12/fbi.jpg The U.S. Department of Justice (DoJ) has indicted 14 nationals belonging to the Democratic People’s Republic of Korea (DPRK or North Korea) for their alleged involvement in a long-running conspiracy to violate sanctions and commit wire fraud, money laundering, and identity theft by illegally seeking ...
Read More »Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online
Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online https://firewall.firm.in/wp-content/uploads/2024/12/serves-hacking.png Dec 12, 2024Ravie LakshmananVulnerability / Cloud Security Cybersecurity researchers are warning that thousands of servers hosting the Prometheus monitoring and alerting toolkit are at risk of information leakage and exposure to denial-of-service (DoS) as well as remote code execution (RCE) attacks. “Prometheus servers or exporters, often lacking proper ...
Read More »Secret Blizzard Deploys Kazuar Backdoor in Ukraine Using Amadey Malware-as-a-Service
Secret Blizzard Deploys Kazuar Backdoor in Ukraine Using Amadey Malware-as-a-Service https://firewall.firm.in/wp-content/uploads/2024/12/hacking.png Dec 11, 2024Ravie LakshmananMalware / Cyber Espionage The Russian nation-state actor tracked as Secret Blizzard has been observed leveraging malware associated with other threat actors to deploy a known backdoor called Kazuar on target devices located in Ukraine. The new findings come from the Microsoft threat intelligence team, which ...
Read More »Fake Recruiters Distribute Banking Trojan via Malicious Apps in Phishing Scam
Fake Recruiters Distribute Banking Trojan via Malicious Apps in Phishing Scam https://firewall.firm.in/wp-content/uploads/2024/12/phishing.png Dec 10, 2024Ravie LakshmananMobile Security / Cryptocurrency Cybersecurity researchers have shed light on a sophisticated mobile phishing (aka mishing) campaign that’s designed to distribute an updated version of the Antidot banking trojan. “The attackers presented themselves as recruiters, luring unsuspecting victims with job offers,” Zimperium zLabs Vishnu Pratapagiri ...
Read More »Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged
Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged https://firewall.firm.in/wp-content/uploads/2024/12/exploit.png Dec 10, 2024Ravie LakshmananVulnerability / Threat Analysis Users of Cleo-managed file transfer software are being urged to ensure that their instances are not exposed to the internet following reports of mass exploitation of a vulnerability affecting fully patched systems. Cybersecurity company Huntress said it discovered evidence of threat ...
Read More »Financial institutions double down on more checks for tech partners – ET CISO
Financial institutions double down on more checks for tech partners – ET CISO https://etimg.etb2bimg.com/thumb/msid-116125812,imgsize-2565646,width-1200,height=765,overlay-etciso/data-breaches/financial-institutions-double-down-on-more-checks-for-tech-partners.jpg Regulated entities such as banks and financial services companies are evaluating options like having backup service providers and tightening their data-sharing norms with technology service companies in the wake of a massive data leak that impacted Signzy. Bengaluru-based Signzy is a regulatory technology firm which offers ...
Read More »Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social Engineering
Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social Engineering https://firewall.firm.in/wp-content/uploads/2024/12/rnsomware.png Dec 09, 2024Ravie LakshmananThreat Intelligence / Malware The threat actors linked to the Black Basta ransomware have been observed switching up their social engineering tactics, distributing a different set of payloads such as Zbot and DarkGate since early October 2024. “Users within the target environment will be ...
Read More »
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India











