North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware

November 2, 2023 State-sponsored threat actors from the Democratic People’s Republic of Korea (DPRK) have been found targeting blockchain engineers of an unnamed crypto exchange platform via Discord with a novel macOS malware dubbed KANDYKORN. Elastic Security Labs said the activity, traced back to April 2023, exhibits overlaps with the infamous adversarial collective Lazarus Group, citing an …

North Korean Hackers Targeting Crypto Experts with KANDYKORN macOS Malware Read More »

Turla Updates Kazuar Backdoor with Advanced Anti-Analysis to Evade Detection

November 2, 2023 The Russia-linked hacking crew known as Turla has been observed using an updated version of a known second-stage backdoor referred to as Kazuar. The new findings come from Palo Alto Networks Unit 42, which is tracking the adversary under its constellation-themed moniker Pensive Ursa. “As the code of the upgraded revision of Kazuar …

Turla Updates Kazuar Backdoor with Advanced Anti-Analysis to Evade Detection Read More »

Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability

November 2, 2023 F5 is warning of active abuse of a critical security flaw in BIG-IP less than a week after its public disclosure, resulting in the execution of arbitrary system commands as part of an exploit chain. Tracked as CVE-2023-46747 (CVSS score: 9.8), the vulnerability allows an unauthenticated attacker with network access to the BIG-IP system through the …

Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability Read More »

Arid Viper Targeting Arabic Android Users with Spyware Disguised as Dating App

November 1, 2023 The threat actor known as Arid Viper (aka APT-C-23, Desert Falcon, or TAG-63) has been attributed as behind an Android spyware campaign targeting Arabic-speaking users with a counterfeit dating app designed to harvest data from infected handsets. “Arid Viper’s Android malware has a number of features that enable the operators to surreptitiously collect sensitive …

Arid Viper Targeting Arabic Android Users with Spyware Disguised as Dating App Read More »

Malicious NuGet Packages Caught Distributing SeroXen RAT Malware

November 1, 2023 Cybersecurity researchers have uncovered a new set of malicious packages published to the NuGet package manager using a lesser-known method for malware deployment. Software supply chain security firm ReversingLabs described the campaign as coordinated and ongoing since August 1, 2023, while linking it to a host of rogue NuGet packages that were observed delivering …

Malicious NuGet Packages Caught Distributing SeroXen RAT Malware Read More »

PentestPad: Platform for Pentest Teams

November 1, 2023 In the ever-evolving cybersecurity landscape, the game-changers are those who adapt and innovate swiftly. Pen test solutions not only supercharge productivity but also provide a crucial layer of objectivity, ensuring efficiency and exceptional accuracy. The synergy between a skilled penetration tester and the precision of pen testing solutions are crucial for staying …

PentestPad: Platform for Pentest Teams Read More »

Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss

November 1, 2023 Atlassian has warned of a critical security flaw in Confluence Data Center and Server that could result in “significant data loss if exploited by an unauthenticated attacker.” Tracked as CVE-2023-22518, the vulnerability is rated 9.1 out of a maximum of 10 on the CVSS scoring system. It has been described as an instance …

Atlassian Warns of New Critical Confluence Vulnerability Threatening Data Loss Read More »

Trojanized PyCharm Software Version Delivered via Google Search Ads

November 1, 2023 A new malvertising campaign has been observed capitalizing on a compromised website to promote spurious versions of PyCharm on Google search results by leveraging Dynamic Search Ads. “Unbeknownst to the site owner, one of their ads was automatically created to promote a popular program for Python developers, and visible to people doing a Google …

Trojanized PyCharm Software Version Delivered via Google Search Ads Read More »

Canada Bans WeChat and Kaspersky Apps On Government Devices

November 1, 2023 Canada on Monday announced a ban on the use of apps from Tencent and Kaspersky on government mobile devices, citing an “unacceptable level of risk to privacy and security.” “The Government of Canada is committed to keeping government information and networks secure,” the Canadian government said. “We regularly monitor potential threats and take …

Canada Bans WeChat and Kaspersky Apps On Government Devices Read More »

Meta Launches Paid Ad-Free Subscription in Europe to Satisfy Privacy Laws

November 1, 2023 Meta on Monday announced plans to offer an ad-free option to access Facebook and Instagram for users in the European Union (EU), European Economic Area (EEA), and Switzerland to comply with “evolving” data protection regulations in the region. The ad-free subscription, which costs €9.99/month on the web or €12.99/month on iOS and …

Meta Launches Paid Ad-Free Subscription in Europe to Satisfy Privacy Laws Read More »

Open Whatsapp chat
Whatsapp Us
Chat with us for faster replies.