Aggregator
SecWiki News 2025-01-07 Review
PhishWP Plug-in Hijacks WordPress E-Commerce Checkouts
【资料】分析认知框架:全源情报分析指南
miyako is Allegedly Selling Access to an Unidentified City Government in Germany
Security Risk Advisors joins the Microsoft Intelligent Security Association
Philadelphia, Pennsylvania, 7th January 2025, CyberNewsWire
The post Security Risk Advisors joins the Microsoft Intelligent Security Association appeared first on Security Boulevard.
Threat actors breached the Argentina’s airport security police (PSA) payroll
Microsoft заставляет мир перейти на Windows 11
Trend Micro and Intel Innovate to Weed Out Covert Threats
[Control Systems] Moxa security advisory (AV25-004)
Name That Edge Toon: Greetings and Salutations
Safepay
Telegram hands over data on thousands of users to US law enforcement
New FireScam Android Malware Abusing Firebase Services To Evade Detection
FireScam is multi-stage malware disguised as a fake “Telegram Premium” app that steals data and maintains persistence on compromised devices and leverages phishing websites to distribute its payload and infiltrate Android devices. It is Android malware disguised as a fake Telegram Premium app distributed via a phishing website mimicking RuStore, which steals user data like […]
The post New FireScam Android Malware Abusing Firebase Services To Evade Detection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CSE’s evolved Security Review Program
40 лет до Альфа Центавра: физики раскрыли способ достижения других звездных систем
Hackers Weaponize Security Testing By Weaponizing npm, PyPI, & Ruby Exploit Packages
Over the past year, malicious actors have been abusing OAST services for data exfiltration, C2 channel establishment, and multi-stage attacks by leveraging compromised JavaScript, Python, and Ruby packages. OAST tools, initially designed for ethical researchers to perform network interactions, can also be exploited by threat actors for malicious purposes such as data exfiltration and pivot […]
The post Hackers Weaponize Security Testing By Weaponizing npm, PyPI, & Ruby Exploit Packages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Malicious Browser Extensions are the Next Frontier for Identity Attacks
Cybercriminals Don't Care About National Cyber Policy
Hackers Mimic Social Security Administration To Deliver ConnectWise RAT
A phishing campaign spoofing the United States Social Security Administration emerged in September 2024, delivering emails with embedded links to a ConnectWise Remote Access Trojan (RAT) installer. These emails, disguised as updated benefits statements, employed various techniques, including mismatched links and “View Statement” buttons, to deceive recipients. It initially leveraged ConnectWise infrastructure for its command […]
The post Hackers Mimic Social Security Administration To Deliver ConnectWise RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.