www.secnews.physaphae.fr This is the RSS 2.0 feed from www.secnews.physaphae.fr. IT's a simple agragated flow of multiple articles soruces. Liste of sources, can be found on www.secnews.physaphae.fr. 2024-05-20T18:18:57+00:00 www.secnews.physaphae.fr Security Affairs - Blog Secu Conti leaked chats confirm that the gang\'s ability to conduct firmware-based attacks 2022-06-02T17:09:12+00:00 https://securityaffairs.co/wordpress/131885/hacking/conti-leaked-chat-firmware-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4934690 False Ransomware,Threat None None Security Affairs - Blog Secu SideWinder carried out over 1,000 attacks since April 2020 SideWinder, an aggressive APT group, is believed to have carried out over 1,000 attacks since April 2020, Kaspersky reported. Researchers from Kaspersky have analyzed the activity of an aggressive threat actor tracked as SideWinder (aka RattleSnake and T-APT-04). The group stands out for the high frequency and persistence of its attacks, researchers believe that the […] ]]> 2022-05-31T14:28:17+00:00 https://securityaffairs.co/wordpress/131831/apt/sidewinder-aggressive-apt.html www.secnews.physaphae.fr/article.php?IdArticle=4905216 False Threat APT-C-17 None Security Affairs - Blog Secu A new WhatsApp OTP scam could allow the hijacking of users\' accounts 2022-05-30T14:49:23+00:00 https://securityaffairs.co/wordpress/131807/hacking/whatsapp-otp-scam.html www.secnews.physaphae.fr/article.php?IdArticle=4895641 False Threat None None Security Affairs - Blog Secu GoodWill Ransomware victims have to perform socially driven activities to decryption their data Researchers discovered a new ransomware family called GoodWill that asks victims to donate the ransom for social causes. CloudSEK's Threat Intelligence Research team has disclosed a new ransomware strain called GoodWill, that demands victims the payment of a ransom through donations for social causes and financially helping people in need. “The ransomware group propagates very unusual demands in […] ]]> 2022-05-30T11:20:08+00:00 https://securityaffairs.co/wordpress/131792/hacking/goodwill-ransomware.html www.secnews.physaphae.fr/article.php?IdArticle=4894581 False Ransomware,Threat None 3.0000000000000000 Security Affairs - Blog Secu Experts believe that Russian Gamaredon APT could fuel a new round of DDoS attacks 360 Qihoo reported DDoS attacks launched by APT-C-53 (aka Gamaredon) conducted through the open-source DDoS Trojan program LOIC. Researchers at 360 Qihoo observed a wave of DDoS attacks launched by Russia-linked APT-C-53 (aka Gamaredon) and reported that the threat actors also released as open-source the code of a DDoS Trojan called LOIC. The instances of the malware spotted by the experts […] ]]> 2022-05-28T15:55:27+00:00 https://securityaffairs.co/wordpress/131762/apt/gamaredon-apt-ddos-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4860568 False Malware,Threat None None Security Affairs - Blog Secu Reuters: Russia-linked APT behind Brexit leak website Russia-linked threat actors are behind a new website that published leaked emails from leading proponents of Britain’s exit from the EU, the Reuters reported. According to a Google cybersecurity official and the former head of UK foreign intelligence, the “Very English Coop d’Etat” website was set up to publish private emails from Brexit supporters, including […] ]]> 2022-05-28T13:30:21+00:00 https://securityaffairs.co/wordpress/131740/data-breach/brexit-data-leak-site.html www.secnews.physaphae.fr/article.php?IdArticle=4858916 False Threat,Guideline None None Security Affairs - Blog Secu GitHub: Nearly 100,000 NPM Users\' credentials stolen in the April OAuth token attack 2022-05-28T11:01:18+00:00 https://securityaffairs.co/wordpress/131733/hacking/100k-npm-credential-github-oauth-breach.html www.secnews.physaphae.fr/article.php?IdArticle=4856431 False Threat None None Security Affairs - Blog Secu FBI: Compromised US academic credentials available on various cybercrime forums The FBI warns organizations in the higher education sector of credentials sold on cybercrime forums that can allow threat actors to access their networks. The FBI issued an alert to inform the higher education sector about the availability of login credentials on dark web forums that can be used by threat actors to launch attacks […] ]]> 2022-05-27T13:22:16+00:00 https://securityaffairs.co/wordpress/131711/cyber-crime/fbi-us-academic-credentials-dark-web.html www.secnews.physaphae.fr/article.php?IdArticle=4839050 False Threat None None Security Affairs - Blog Secu Experts released PoC exploit code for critical VMware CVE-2022-22972 flaw Security researchers released PoC exploit code for the critical authentication bypass vulnerability CVE-2022-22972 affecting multiple VMware products. Horizon3 security researchers have released a proof-of-concept (PoC) exploit and technical analysis for the critical authentication bypass vulnerability CVE-2022-22972 affecting multiple VMware products. The virtualization giant recently warned that a threat actor can exploit the CVE-2022-22972 flaw (CVSSv3 base score of 9.8) […] ]]> 2022-05-27T05:58:22+00:00 https://securityaffairs.co/wordpress/131698/hacking/poc-exploit-code-vmware-cve-2022-22972.html www.secnews.physaphae.fr/article.php?IdArticle=4832547 False Vulnerability,Threat None None Security Affairs - Blog Secu Exposed: the threat actors who are poisoning Facebook An investigation of the infamous “Is That You?” video scam led Cybernews researchers into exposing threat actors who are poisoning Facebook Original post @ https://cybernews.com/security/exposed-the-threat-actors-who-are-poisoning-facebook/ An investigation of the infamous “Is That You?” video scam has led Cybernews researchers to a cybercriminal stronghold, from which threat actors have been infecting the social media giant with […] ]]> 2022-05-26T20:40:28+00:00 https://securityaffairs.co/wordpress/131694/cyber-crime/threat-actors-poisoning-facebook.html www.secnews.physaphae.fr/article.php?IdArticle=4825308 False Threat None None Security Affairs - Blog Secu Italy announced its National Cybersecurity Strategy 2022/26 Italy announced its National Cybersecurity Strategy for 2022/26, a crucial document to address cyber threats and increase the resilience of the country. Italy presented its National Cybersecurity Strategy for 2022/26 and reinforce the government’s commitment to addressing cyber threats and increasing the resilience of the country to cyber attacks. The strategy is aligned with the […] ]]> 2022-05-26T09:13:55+00:00 https://securityaffairs.co/wordpress/131674/security/italy-national-cybersecurity-strategy.html www.secnews.physaphae.fr/article.php?IdArticle=4817843 False Threat None None Security Affairs - Blog Secu Unknown APT group is targeting Russian government entities An unknown APT group is targeting Russian government entities since the beginning of the Russian invasion of Ukraine. Researchers from Malwarebytes observed an unknown Advanced Persistent Threat (APT) group targeting Russian government entities with at least four separate spear-phishing campaigns since the beginning of the Russian invasion of Ukraine. The threat actors behind the attacks […] ]]> 2022-05-25T22:36:59+00:00 https://securityaffairs.co/wordpress/131658/apt/unknown-apt-group-target-russia.html www.secnews.physaphae.fr/article.php?IdArticle=4809758 False Threat None None Security Affairs - Blog Secu Trend Micro addressed a flaw exploited by China-linked Moshen Dragon APT Trend Micro addressed a DLL hijacking issue in Trend Micro Security actively exploited by a China-linked threat group to deploy malware. Trend Micro addressed a DLL hijacking flaw in Trend Micro Security that a China-linked threat actor actively exploited to deploy malware. In early May, SentinelOne researchers observed a China-linked APT group, tracked as Moshen […] ]]> 2022-05-24T18:18:56+00:00 https://securityaffairs.co/wordpress/131635/hacking/trend-micro-flaw-moshen-dragon.html www.secnews.physaphae.fr/article.php?IdArticle=4788923 False Threat None None Security Affairs - Blog Secu Microsoft warns of new highly evasive web skimming campaigns Threat actors behind web skimming campaigns are using malicious JavaScript to mimic Google Analytics and Meta Pixel scripts to avoid detection. Microsoft security researchers recently observed web skimming campaigns that used multiple obfuscation techniques to avoid detection. The threat actors obfuscated the skimming script by encoding it in PHP, which, in turn, was embedded in […] ]]> 2022-05-24T13:16:01+00:00 https://securityaffairs.co/wordpress/131625/hacking/web-skimming-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4785397 False Threat None None Security Affairs - Blog Secu Russia-linked Turla APT targets Austria, Estonia, and NATO platform Russia-linked APT group Turla was observed targeting the Austrian Economic Chamber, a NATO eLearning platform, and the Baltic Defense College. Researchers from SEKOIA.IO Threat & Detection Research (TDR) team have uncovered a reconnaissance and espionage campaign conducted by Russia-linked Turla APT aimed at the Baltic Defense College, the Austrian Economic Chamber (involved in government decision-making such as economic sanctions) and NATO's […] ]]> 2022-05-23T22:03:19+00:00 https://securityaffairs.co/wordpress/131586/apt/turla-apt-austria-estonia-nato.html www.secnews.physaphae.fr/article.php?IdArticle=4780683 False Threat None None Security Affairs - Blog Secu Russia-linked Fronton botnet could run disinformation campaigns Researchers warn that the Fronton botnet was used by Russia-linked threat actors for coordinated disinformation campaigns. Fronton is a distributed denial-of-service (DDoS) botnet that was used by Russia-linked threat actors for coordinated disinformation campaigns. In March 2020, the collective of hacktivists called “Digital Revolution” claimed to have hacked a subcontractor to the Russian FSB. The […] ]]> 2022-05-23T17:17:24+00:00 https://securityaffairs.co/wordpress/131574/cyber-warfare-2/fronton-botnet-disinformation.html www.secnews.physaphae.fr/article.php?IdArticle=4777123 False Threat None None Security Affairs - Blog Secu Cytrox\'s Predator spyware used zero-day exploits in 3 campaigns 2022-05-23T09:04:29+00:00 https://securityaffairs.co/wordpress/131561/hacking/predator-spyware-zero-day-exploits.html www.secnews.physaphae.fr/article.php?IdArticle=4772298 False Threat None None Security Affairs - Blog Secu Threat actors target the infoSec community with fake PoC exploits Researchers uncovered a malware campaign targeting the infoSec community with fake Proof Of Concept to deliver a Cobalt Strike beacon. Researchers from threat intelligence firm Cyble uncovered a malware campaign targeting the infoSec community. The expert discovered a post where a researcher were sharing a fake Proof of Concept (POC) exploit code for an RPC Runtime Library […] ]]> 2022-05-23T06:56:23+00:00 https://securityaffairs.co/wordpress/131553/intelligence/fake-poc-exploits-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4770925 False Malware,Threat None None Security Affairs - Blog Secu North Korea-linked Lazarus APT uses Log4J to target VMware servers North Korea-linked Lazarus APT is exploiting the Log4J remote code execution (RCE) in attacks aimed at VMware Horizon servers. North Korea-linked group Lazarus is exploiting the Log4J RCE vulnerability (CVE-2021-44228) to compromise VMware Horizon servers. Multiple threat actors are exploiting this flaw since January, in January VMware urged customers to patch critical Log4j security vulnerabilities impacting Internet-exposed […] ]]> 2022-05-22T15:48:25+00:00 https://securityaffairs.co/wordpress/131483/apt/lazarus-apt-log4j-vmware-servers.html www.secnews.physaphae.fr/article.php?IdArticle=4758896 False Vulnerability,Threat APT 38 None Security Affairs - Blog Secu Cisco fixes an IOS XR flaw actively exploited in the wild Cisco addressed a medium-severity vulnerability affecting IOS XR Software, the company warns that the flaw is actively exploited in the wild. Cisco released security updates to address a medium-severity vulnerability affecting IOS XR Software, tracked as CVE-2022-20821 (CVSS score: 6.5), that threat actors are actively exploiting in attacks in the wild. The flaw resides in […] ]]> 2022-05-21T11:14:50+00:00 https://securityaffairs.co/wordpress/131516/security/cisco-ios-xr-flaw.html www.secnews.physaphae.fr/article.php?IdArticle=4733799 False Vulnerability,Threat None None Security Affairs - Blog Secu The activity of the Linux XorDdos bot increased by 254% over the last six months Microsoft researchers have observed a spike in the activity of the Linux bot XorDdos over the last six months. XORDDoS, also known as XOR.DDoS, first appeared in the threat landscape in 2014 it is a Linux Botnet that was employed in attacks against gaming and education websites with massive DDoS attacks that reached 150 gigabytes per second […] ]]> 2022-05-20T14:36:00+00:00 https://securityaffairs.co/wordpress/131478/hacking/linux-bornet-xorddos-254-surge.html www.secnews.physaphae.fr/article.php?IdArticle=4714823 False Threat None None Security Affairs - Blog Secu VMware fixed a critical auth bypass issue in some of its products VMware addressed a critical authentication bypass vulnerability “affecting local domain users” in multiple products. The virtualization giant warns that a threat actor can exploit the flaw, tracked as CVE-2022-22972 (CVSSv3 base score of 9.8), to obtain admin privileges and urges customers to install patches immediately. “This critical vulnerability should be patched or mitigated immediately per the […] ]]> 2022-05-18T21:29:54+00:00 https://securityaffairs.co/wordpress/131429/security/vmware-critical-auth-bypass-issue.html www.secnews.physaphae.fr/article.php?IdArticle=4694633 False Vulnerability,Threat None None Security Affairs - Blog Secu Microsoft warns of attacks targeting MSSQL servers using the tool sqlps Microsoft warns of brute-forcing attacks targeting Microsoft SQL Server (MSSQL) database servers exposed online. Microsoft warns of a new hacking campaign aimed at MSSQL servers, threat actors are launching brute-forcing attacks against poorly protected instances. The attacks are using the legitimate tool sqlps.exe, a sort of SQL Server PowerShell file, as a LOLBin (short for living-off-the-land binary). Microsoft warned of […] ]]> 2022-05-18T20:04:37+00:00 https://securityaffairs.co/wordpress/131418/hacking/mssql-servers-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4692993 False Tool,Threat None None Security Affairs - Blog Secu Microsoft warns of the rise of cryware targeting hot wallets Microsoft researchers warn of the rising threat of cryware targeting non-custodial cryptocurrency wallets, also known as hot wallets. Microsoft warns of the rise of cryware, malicious software used to steal info an dfunds from non-custodial cryptocurrency wallets, also known as hot wallets. Data stolen from this kind of malware includes private keys, seed phrases, and […] ]]> 2022-05-18T14:37:54+00:00 https://securityaffairs.co/wordpress/131406/malware/microsoft-warns-cryware.html www.secnews.physaphae.fr/article.php?IdArticle=4689032 False Malware,Threat None None Security Affairs - Blog Secu Experts spotted a new variant of UpdateAgent macOS malware dropper written in Swift Researchers spotted a new variant of the UpdateAgent macOS malware dropper that was employed in attacks in the wild. Researchers from the Jamf Threat Labs team have uncovered a new variant of the UpdateAgent macOS malware dropper. The new version is written in Swift and relies on the AWS infrastructure to host its malicious payloads.  […] ]]> 2022-05-18T07:41:40+00:00 https://securityaffairs.co/wordpress/131391/malware/updateagent-macos-malware-swift.html www.secnews.physaphae.fr/article.php?IdArticle=4682929 False Malware,Threat None None Security Affairs - Blog Secu Venezuelan cardiologist accused of operating and selling Thanos ransomware The U.S. Justice Department accused a 55-year-old Venezuelan cardiologist of operating and selling the Thanos ransomware. The U.S. Justice Department accused Moises Luis Zagala Gonzalez, a 55-year-old cardiologist from Venezuela, of operating and selling the Thanos ransomware. Thanos ransomware (a.k.a. Hakbit ransomware) has been developed by Nosophoros (aka Aesculapius, and Nebuchadnezzar), a threat actor offering for sale the malware […] ]]> 2022-05-17T19:10:57+00:00 https://securityaffairs.co/wordpress/131382/cyber-crime/venezuelan-man-accused-thanos-ransomware.html www.secnews.physaphae.fr/article.php?IdArticle=4672141 False Ransomware,Malware,Threat None None Security Affairs - Blog Secu A custom PowerShell RAT uses to target German users using Ukraine crisis as bait Researchers spotted a threat actor using a custom PowerShell RAT targeting German users to gain intelligence on the Ukraine crisis. Malwarebytes experts uncovered a campaign that targets German users with custom PowerShell RAT targeting. The threat actors attempt to trick victims into opening weaponized documents by using the current situation in Ukraine as bait. The […] ]]> 2022-05-17T05:19:04+00:00 https://securityaffairs.co/wordpress/131353/intelligence/powershell-rat-targets-germany-ukraine-bait.html www.secnews.physaphae.fr/article.php?IdArticle=4663123 False Threat None None Security Affairs - Blog Secu Eternity Project: You can pay $260 for a stealer and $490 for a ransomware Researchers from threat intelligence firm Cyble analyzed the Eternity Project Tor website which offers any kind of malicious code. Researchers at cybersecurity firm Cyble analyzed a Tor website named named 'Eternity Project’ that offers for sale a broad range of malware, including stealers, miners, ransomware, and DDoS Bots. The experts discovered the marketplace during a […] ]]> 2022-05-16T05:28:25+00:00 https://securityaffairs.co/wordpress/131317/malware/eternity-project-malware-listings.html www.secnews.physaphae.fr/article.php?IdArticle=4653098 False Ransomware,Threat None None Security Affairs - Blog Secu Sysrv-K, a new variant of the Sysrv botnet includes new exploits Microsoft reported that the Sysrv botnet is targeting Windows and Linux servers exploiting flaws in the Spring Framework and WordPress. Microsoft Security Intelligence team Microsoft reported that a new variant of the Sysrv botnet, tracked as Sysrv-K, now includes exploits for vulnerabilities in the Spring Framework and WordPress. Threat actors use the botnet in a cryptomining campaign targeting Windows […] ]]> 2022-05-15T11:25:31+00:00 https://securityaffairs.co/wordpress/131290/cyber-crime/microsoft-sysrv-botnet-new-exploits.html www.secnews.physaphae.fr/article.php?IdArticle=4634838 False Threat None None Security Affairs - Blog Secu Iran-linked COBALT MIRAGE group uses ransomware in its operations 2022-05-13T06:52:53+00:00 https://securityaffairs.co/wordpress/131218/apt/iran-cobalt-mirage-ransomware-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4589476 False Ransomware,Threat APT 15,APT 15 4.0000000000000000 Security Affairs - Blog Secu Threat actors are actively exploiting CVE-2022-1388 RCE in F5 BIG-IP 2022-05-10T06:41:59+00:00 https://securityaffairs.co/wordpress/131132/hacking/big-ip-cve-2022-1388-exploitation.html www.secnews.physaphae.fr/article.php?IdArticle=4571359 False Threat None 4.0000000000000000 Security Affairs - Blog Secu Vulnerable Docker Installations Are A Playhouse for Malware Attacks 2022-05-06T10:02:23+00:00 https://securityaffairs.co/wordpress/130973/cyber-crime/uptycs-docker-malware-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4554063 False Malware,Threat None None Security Affairs - Blog Secu China-linked APT Curious Gorge targeted Russian govt agencies 2022-05-03T23:21:00+00:00 https://securityaffairs.co/wordpress/130873/apt/china-curious-gorge-targeted-russian-govt.html www.secnews.physaphae.fr/article.php?IdArticle=4540712 False Threat None None Security Affairs - Blog Secu Hackers stole +80M from DeFi platforms Rari Capital and Fei Protocol 2022-05-01T13:13:29+00:00 https://securityaffairs.co/wordpress/130768/hacking/80m-hack-defi-rari-capital-fei-protocol.html www.secnews.physaphae.fr/article.php?IdArticle=4529270 False Threat None None Security Affairs - Blog Secu Emotet tests new attack chain in low volume campaigns 2022-04-30T17:27:35+00:00 https://securityaffairs.co/wordpress/130739/cyber-crime/emotet-operators-test-new-techniques.html www.secnews.physaphae.fr/article.php?IdArticle=4526624 False Threat None None Security Affairs - Blog Secu Bumblebee, a new malware loader used by multiple crimeware threat actors 2022-04-28T14:49:32+00:00 https://securityaffairs.co/wordpress/130699/cyber-crime/new-bumblebee-loader.html www.secnews.physaphae.fr/article.php?IdArticle=4517267 False Malware,Threat None None Security Affairs - Blog Secu Russia-linked threat actors launched hundreds of cyberattacks on Ukraine 2022-04-28T04:36:37+00:00 https://securityaffairs.co/wordpress/130677/apt/russia-hit-ukraine-hundreds-cyberattacks.html www.secnews.physaphae.fr/article.php?IdArticle=4515530 False Threat None None Security Affairs - Blog Secu Conti ransomware operations surge despite the recent leak 2022-04-27T07:15:07+00:00 https://securityaffairs.co/wordpress/130640/cyber-crime/conti-ransomware-operations-continues.html www.secnews.physaphae.fr/article.php?IdArticle=4512034 False Ransomware,Threat None None Security Affairs - Blog Secu Experts warn of a surge in zero-day flaws observed and exploited in 2021 2022-04-25T08:09:22+00:00 https://securityaffairs.co/wordpress/130569/apt/zero-day-discovered-exploited-2021.html www.secnews.physaphae.fr/article.php?IdArticle=4503461 False Threat None None Security Affairs - Blog Secu Atlassian addresses a critical Jira authentication bypass flaw 2022-04-24T13:57:11+00:00 https://securityaffairs.co/wordpress/130564/hacking/atlassian-jira-authentication-bypass-issue.html www.secnews.physaphae.fr/article.php?IdArticle=4500777 False Vulnerability,Threat None None Security Affairs - Blog Secu US, Australia, Canada, New Zealand, and the UK warn of Russia-linked threat actors\' attacks 2022-04-21T07:15:37+00:00 https://securityaffairs.co/wordpress/130430/cyber-warfare-2/russia-threat-actors-cyber-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4486650 False Threat None None Security Affairs - Blog Secu Russian Gamaredon APT continues to target Ukraine 2022-04-20T19:30:08+00:00 https://securityaffairs.co/wordpress/130419/apt/gamaredon-targets-ukraine.html www.secnews.physaphae.fr/article.php?IdArticle=4483342 False Threat None None Security Affairs - Blog Secu NSO Group Pegasus spyware leverages new zero-click iPhone exploit in recent attacks 2022-04-19T10:03:43+00:00 https://securityaffairs.co/wordpress/130360/malware/nso-group-pegasus-click-iphone-exploit.html www.secnews.physaphae.fr/article.php?IdArticle=4476685 False Threat None None Security Affairs - Blog Secu Experts spotted Industrial Spy, a new stolen data marketplace 2022-04-18T17:46:46+00:00 https://securityaffairs.co/wordpress/130323/cyber-crime/industrial-spy-marketplace.html www.secnews.physaphae.fr/article.php?IdArticle=4472164 False Malware,Threat None None Security Affairs - Blog Secu Enemybot, a new DDoS botnet appears in the threat landscape 2022-04-17T17:53:00+00:00 https://securityaffairs.co/wordpress/130291/cyber-crime/enemybot-botnet-ddos.html www.secnews.physaphae.fr/article.php?IdArticle=4468197 False Threat None None Security Affairs - Blog Secu Stolen OAuth tokens used to download data from dozens of organizations, GitHub warns 2022-04-17T14:58:53+00:00 https://securityaffairs.co/wordpress/130279/hacking/github-warns-stolen-oauth-tokens-access-data.html www.secnews.physaphae.fr/article.php?IdArticle=4467924 False Threat None None Security Affairs - Blog Secu Threat actors target the Ukrainian gov with IcedID malware 2022-04-16T11:49:34+00:00 https://securityaffairs.co/wordpress/130250/cyber-warfare-2/icedid-against-ukraine-gov-agencies.html www.secnews.physaphae.fr/article.php?IdArticle=4463749 False Malware,Threat None None Security Affairs - Blog Secu Threat actors use Zimbra exploits to target organizations in Ukraine 2022-04-15T22:13:40+00:00 https://securityaffairs.co/wordpress/130244/cyber-warfare-2/attacks-ukraine-govt-zimbra-exploits.html www.secnews.physaphae.fr/article.php?IdArticle=4460127 False Vulnerability,Threat None None Security Affairs - Blog Secu ZingoStealer crimeware released for free in the cybercrime ecosystem 2022-04-15T14:37:07+00:00 https://securityaffairs.co/wordpress/130229/breaking-news/zingostealer-crimeware.html www.secnews.physaphae.fr/article.php?IdArticle=4456420 False Threat None None Security Affairs - Blog Secu Google fixed third zero-day in Chrome since the start of 2022 2022-04-15T10:25:30+00:00 https://securityaffairs.co/wordpress/130213/security/google-chrome-zeroday-cve-2022-1364.html www.secnews.physaphae.fr/article.php?IdArticle=4454633 False Vulnerability,Threat None None Security Affairs - Blog Secu US gov agencies e private firms warn nation-state actors are targeting ICS & SCADA devices 2022-04-14T15:10:01+00:00 https://securityaffairs.co/wordpress/130195/apt/us-gov-warns-apt-targets-ics-scada.html www.secnews.physaphae.fr/article.php?IdArticle=4448710 False Threat None None Security Affairs - Blog Secu Critical VMware Workspace ONE Access CVE-2022-22954 flaw actively exploited 2022-04-14T10:42:53+00:00 https://securityaffairs.co/wordpress/130188/hacking/vmware-workspace-one-access-flaw-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4446405 False Vulnerability,Threat None None Security Affairs - Blog Secu China-linked Hafnium APT leverages Tarrask malware to gain persistence 2022-04-13T14:52:23+00:00 https://securityaffairs.co/wordpress/130167/apt/tarrask-malware-persistence-technique.html www.secnews.physaphae.fr/article.php?IdArticle=4441316 False Malware,Threat None None Security Affairs - Blog Secu Russia-linked Sandworm APT targets energy facilities in Ukraine with wipers 2022-04-12T14:05:20+00:00 https://securityaffairs.co/wordpress/130123/apt/russia-sandworm-targets-energy-facilities-ukraine.html www.secnews.physaphae.fr/article.php?IdArticle=4434834 False Malware,Threat None None Security Affairs - Blog Secu Securing Easy Appointments and earning CVE-2022-0482 2022-04-11T07:19:41+00:00 https://securityaffairs.co/wordpress/130077/security/securing-easy-appointments-cve-2022-0482.html www.secnews.physaphae.fr/article.php?IdArticle=4427953 False Vulnerability,Threat None None Security Affairs - Blog Secu Facebook blocked Russia and Belarus threat actors\' activity against Ukraine 2022-04-10T07:53:57+00:00 https://securityaffairs.co/wordpress/130037/cyber-warfare-2/facebook-block-russia-belarus-against-ukraine.html www.secnews.physaphae.fr/article.php?IdArticle=4424676 False Threat None None Security Affairs - Blog Secu China-linked threat actors target Indian Power Grid organizations 2022-04-09T12:06:00+00:00 https://securityaffairs.co/wordpress/130010/apt/china-linked-threat-actors-target-indian-power-grid-organizations.html www.secnews.physaphae.fr/article.php?IdArticle=4422268 False Threat APT 1 None Security Affairs - Blog Secu A Mirai-based botnet is exploiting the Spring4Shell vulnerability 2022-04-09T07:45:29+00:00 https://securityaffairs.co/wordpress/129998/hacking/mirai-based-botnet-spring4shell.html www.secnews.physaphae.fr/article.php?IdArticle=4421818 False Vulnerability,Threat None None Security Affairs - Blog Secu Hamas-linked threat actors target high-profile Israeli individuals 2022-04-08T07:16:58+00:00 https://securityaffairs.co/wordpress/129973/apt/hamas-linked-apt-targets-israeli-individuals.html www.secnews.physaphae.fr/article.php?IdArticle=4415879 False Threat APT-C-23 None Security Affairs - Blog Secu Colibri Loader employs clever persistence mechanism 2022-04-07T14:56:47+00:00 https://securityaffairs.co/wordpress/129956/cyber-crime/colibri-loader-persistent-mechanism.html www.secnews.physaphae.fr/article.php?IdArticle=4411867 False Malware,Threat None None Security Affairs - Blog Secu Ukraine warns of attacks aimed at taking over Telegram accounts 2022-04-06T14:57:35+00:00 https://securityaffairs.co/wordpress/129900/hacking/cert-ua-attacks-telegram-accounts.html www.secnews.physaphae.fr/article.php?IdArticle=4405789 False Threat None None Security Affairs - Blog Secu Borat RAT, a new RAT that performs ransomware and DDoS attacks 2022-04-04T05:38:05+00:00 https://securityaffairs.co/wordpress/129805/malware/borat-rat-a-new-rat-that-performs-ransomware-and-ddos-attacks.html www.secnews.physaphae.fr/article.php?IdArticle=4391934 False Ransomware,Threat None None Security Affairs - Blog Secu Critical CVE-2022-1162 flaw in GitLab allowed threat actors to take over accounts 2022-04-02T10:00:39+00:00 https://securityaffairs.co/wordpress/129730/hacking/cve-2022-1162-flaw-gitlab.html www.secnews.physaphae.fr/article.php?IdArticle=4384181 False Vulnerability,Threat None None Security Affairs - Blog Secu Flaws in Wyze cam devices allow their complete takeover 2022-04-01T06:56:46+00:00 https://securityaffairs.co/wordpress/129677/hacking/wyze-cam-flaws-allow-takeover.html?utm_source=rss&utm_medium=rss&utm_campaign=wyze-cam-flaws-allow-takeover www.secnews.physaphae.fr/article.php?IdArticle=4377264 False Threat None None Security Affairs - Blog Secu CISA and DoE warns of attacks targeting UPS devices 2022-03-30T15:02:13+00:00 https://securityaffairs.co/wordpress/129620/security/cisa-doe-warn-attacks-ups.html?utm_source=rss&utm_medium=rss&utm_campaign=cisa-doe-warn-attacks-ups www.secnews.physaphae.fr/article.php?IdArticle=4366753 True Threat None None Security Affairs - Blog Secu $625M stolen from Axie Infinity \'s Ronin bridge, the largest ever crypto hack 2022-03-29T22:03:16+00:00 https://securityaffairs.co/wordpress/129609/cyber-crime/625m-axie-infinity-ronin-hack.html?utm_source=rss&utm_medium=rss&utm_campaign=625m-axie-infinity-ronin-hack www.secnews.physaphae.fr/article.php?IdArticle=4362602 False Hack,Threat None None Security Affairs - Blog Secu What is credential stuffing? And how to prevent it? 2022-03-29T07:04:04+00:00 https://securityaffairs.co/wordpress/129590/hacking/credential-stuffing.html?utm_source=rss&utm_medium=rss&utm_campaign=credential-stuffing www.secnews.physaphae.fr/article.php?IdArticle=4357829 False Threat None None Security Affairs - Blog Secu Chinese threat actor Scarab targets Ukraine, CERT-UA warns 2022-03-25T15:29:35+00:00 https://securityaffairs.co/wordpress/129477/apt/chinese-threat-actor-scarab-targets-ukraine-cert-ua-warns.html?utm_source=rss&utm_medium=rss&utm_campaign=chinese-threat-actor-scarab-targets-ukraine-cert-ua-warns www.secnews.physaphae.fr/article.php?IdArticle=4340699 False Threat None None Security Affairs - Blog Secu Ukrainian enterprises hit with the DoubleZero wiper 2022-03-23T21:43:36+00:00 https://securityaffairs.co/wordpress/129417/malware/doublezero-wiper-hit-ukraine.html?utm_source=rss&utm_medium=rss&utm_campaign=doublezero-wiper-hit-ukraine www.secnews.physaphae.fr/article.php?IdArticle=4331493 False Malware,Threat None None Security Affairs - Blog Secu FBI warns of growing risks of Russia-linked attacks on US energy firms 2022-03-23T15:19:59+00:00 https://securityaffairs.co/wordpress/129409/security/fbi-warns-russia-us-energy-firms.html?utm_source=rss&utm_medium=rss&utm_campaign=fbi-warns-russia-us-energy-firms www.secnews.physaphae.fr/article.php?IdArticle=4329804 False Threat None None Security Affairs - Blog Secu Lapsus$ extortion gang claims to have stolen sensitive data from Okta 2022-03-22T14:31:17+00:00 https://securityaffairs.co/wordpress/129343/data-breach/lapsus-gang-claims-okta-hack.html?utm_source=rss&utm_medium=rss&utm_campaign=lapsus-gang-claims-okta-hack www.secnews.physaphae.fr/article.php?IdArticle=4323918 False Hack,Threat None None Security Affairs - Blog Secu Mar 13- Mar 19 Ukraine – Russia the silent cyber conflict 2022-03-20T14:26:44+00:00 https://securityaffairs.co/wordpress/129263/cyber-warfare-2/mar-13-19-ukraine-russia-cyber-conflict.html?utm_source=rss&utm_medium=rss&utm_campaign=mar-13-19-ukraine-russia-cyber-conflict www.secnews.physaphae.fr/article.php?IdArticle=4312260 False Threat None None Security Affairs - Blog Secu Crooks claims to have stolen 4TB of data from TransUnion South Africa 2022-03-19T16:10:54+00:00 https://securityaffairs.co/wordpress/129224/data-breach/transunion-south-africa-data-breach.html?utm_source=rss&utm_medium=rss&utm_campaign=transunion-south-africa-data-breach www.secnews.physaphae.fr/article.php?IdArticle=4309324 False Threat None None Security Affairs - Blog Secu Exotic Lily initial access broker works with Conti gang 2022-03-19T13:15:26+00:00 https://securityaffairs.co/wordpress/129216/cyber-crime/exotic-lily-access-broker.html?utm_source=rss&utm_medium=rss&utm_campaign=exotic-lily-access-broker www.secnews.physaphae.fr/article.php?IdArticle=4308980 False Ransomware,Threat None None Security Affairs - Blog Secu China-linked threat actors are targeting the government of Ukraine 2022-03-18T21:12:47+00:00 https://securityaffairs.co/wordpress/129206/apt/china-linked-apts-target-ukraine.html?utm_source=rss&utm_medium=rss&utm_campaign=china-linked-apts-target-ukraine www.secnews.physaphae.fr/article.php?IdArticle=4305044 False Threat None None Security Affairs - Blog Secu Russia\'s disinformation uses deepfake video of Zelenskyy telling people to lay down arms 2022-03-16T22:44:40+00:00 https://securityaffairs.co/wordpress/129124/intelligence/russia-deepfake-video-zelenskyy.html?utm_source=rss&utm_medium=rss&utm_campaign=russia-deepfake-video-zelenskyy www.secnews.physaphae.fr/article.php?IdArticle=4294864 False Threat None None Security Affairs - Blog Secu Russia-linked threats actors exploited default MFA protocol and PrintNightmare bug to compromise NGO cloud 2022-03-16T13:28:18+00:00 https://securityaffairs.co/wordpress/129113/apt/russia-linked-threats-actors-alert.html?utm_source=rss&utm_medium=rss&utm_campaign=russia-linked-threats-actors-alert www.secnews.physaphae.fr/article.php?IdArticle=4291950 False Threat None None Security Affairs - Blog Secu A massive DDoS attack hit Israel, government sites went offline 2022-03-14T21:51:17+00:00 https://securityaffairs.co/wordpress/129063/cyber-warfare-2/massive-ddos-attack-hit-israel.html?utm_source=rss&utm_medium=rss&utm_campaign=massive-ddos-attack-hit-israel www.secnews.physaphae.fr/article.php?IdArticle=4280486 False Threat None None Security Affairs - Blog Secu Russia-Ukraine cyber conflict poses critical infrastructure at risk 2022-03-14T08:09:12+00:00 https://securityaffairs.co/wordpress/129009/cyber-warfare-2/russia-ukraine-critical-infrastructure-attacks.html?utm_source=rss&utm_medium=rss&utm_campaign=russia-ukraine-critical-infrastructure-attacks www.secnews.physaphae.fr/article.php?IdArticle=4275587 False Threat None None Security Affairs - Blog Secu Attackers use website contact forms to spread BazarLoader malware 2022-03-12T16:40:23+00:00 https://securityaffairs.co/wordpress/128942/cyber-crime/phishing-bazarloader-campaign.html?utm_source=rss&utm_medium=rss&utm_campaign=phishing-bazarloader-campaign www.secnews.physaphae.fr/article.php?IdArticle=4268700 False Malware,Threat None None Security Affairs - Blog Secu Crooks target Ukraine\'s IT Army with a tainted DDoS tool 2022-03-10T21:51:37+00:00 https://securityaffairs.co/wordpress/128894/cyber-crime/fake-ddos-tool-ukraines-it-army.html?utm_source=rss&utm_medium=rss&utm_campaign=fake-ddos-tool-ukraines-it-army www.secnews.physaphae.fr/article.php?IdArticle=4256081 False Malware,Tool,Threat None None Security Affairs - Blog Secu Multiple Russian government websites hacked in a supply chain attack 2022-03-09T15:57:44+00:00 https://securityaffairs.co/wordpress/128853/breaking-news/russian-government-sites-supply-chain-attack.html?utm_source=rss&utm_medium=rss&utm_campaign=russian-government-sites-supply-chain-attack www.secnews.physaphae.fr/article.php?IdArticle=4250250 False Threat None None Security Affairs - Blog Secu Samsung data breach: Lapsus$ gang stole Galaxy devices\' source code 2022-03-09T07:50:04+00:00 https://securityaffairs.co/wordpress/128828/data-breach/samsung-data-breach.html?utm_source=rss&utm_medium=rss&utm_campaign=samsung-data-breach www.secnews.physaphae.fr/article.php?IdArticle=4248895 False Threat None None Security Affairs - Blog Secu Google TAG: Russia, Belarus-linked APTs targeted Ukraine 2022-03-08T21:44:44+00:00 https://securityaffairs.co/wordpress/128821/apt/russia-belarus-apts-targeted-ukraine.html?utm_source=rss&utm_medium=rss&utm_campaign=russia-belarus-apts-targeted-ukraine www.secnews.physaphae.fr/article.php?IdArticle=4247388 False Threat None None Security Affairs - Blog Secu Russia-Ukraine, who are the soldiers that crowd cyberspace? 2022-03-04T10:09:07+00:00 https://securityaffairs.co/wordpress/128659/cyber-warfare-2/russia-ukraine-battlefield.html?utm_source=rss&utm_medium=rss&utm_campaign=russia-ukraine-battlefield www.secnews.physaphae.fr/article.php?IdArticle=4225625 False Threat None None Security Affairs - Blog Secu China-linked APT used Daxin, one of the most sophisticated backdoor even seen 2022-03-01T15:24:35+00:00 https://securityaffairs.co/wordpress/128545/uncategorized/daxin-backdoor.html?utm_source=rss&utm_medium=rss&utm_campaign=daxin-backdoor www.secnews.physaphae.fr/article.php?IdArticle=4208132 False Threat None None Security Affairs - Blog Secu FoxBlade malware targeted Ukrainian networks hours before Russia\'s invasion 2022-03-01T00:12:28+00:00 https://securityaffairs.co/wordpress/128538/cyber-warfare-2/foxblade-malware-used-hours-before-invasion.html?utm_source=rss&utm_medium=rss&utm_campaign=foxblade-malware-used-hours-before-invasion www.secnews.physaphae.fr/article.php?IdArticle=4204132 False Malware,Threat None None Security Affairs - Blog Secu Iran-linked UNC3313 APT employed two custom backdoors against a Middle East gov entity 2022-02-28T10:29:00+00:00 https://securityaffairs.co/wordpress/128493/malware/unc3313-apt-two-backdoors.html?utm_source=rss&utm_medium=rss&utm_campaign=unc3313-apt-two-backdoors www.secnews.physaphae.fr/article.php?IdArticle=4199208 False Threat None None Security Affairs - Blog Secu CISA adds two Zabbix flaws to its Known Exploited Vulnerabilities Catalog 2022-02-24T21:53:39+00:00 https://securityaffairs.co/wordpress/128374/hacking/cisa-zabbix-flaws.html?utm_source=rss&utm_medium=rss&utm_campaign=cisa-zabbix-flaws www.secnews.physaphae.fr/article.php?IdArticle=4179086 False Tool,Vulnerability,Threat None None Security Affairs - Blog Secu New Wiper Malware HermeticWiper targets Ukrainian systems 2022-02-24T11:54:24+00:00 https://securityaffairs.co/wordpress/128349/malware/wiper-malware-hermeticwipe-ukrain.html?utm_source=rss&utm_medium=rss&utm_campaign=wiper-malware-hermeticwipe-ukrain www.secnews.physaphae.fr/article.php?IdArticle=4176729 False Malware,Threat None 5.0000000000000000 Security Affairs - Blog Secu Threat actors target poorly protected Microsoft SQL Server installs 2022-02-22T20:46:50+00:00 https://securityaffairs.co/wordpress/128297/hacking/microsoft-sql-server-compromise.html?utm_source=rss&utm_medium=rss&utm_campaign=microsoft-sql-server-compromise www.secnews.physaphae.fr/article.php?IdArticle=4168128 False Threat None None Security Affairs - Blog Secu Threat Report Portugal: Q4 2021 2022-02-21T07:58:51+00:00 https://securityaffairs.co/wordpress/128222/security/threat-report-portugal-q4-2021.html?utm_source=rss&utm_medium=rss&utm_campaign=threat-report-portugal-q4-2021 www.secnews.physaphae.fr/article.php?IdArticle=4159225 True Threat None None Security Affairs - Blog Secu Threat actors leverage Microsoft Teams to spread malware 2022-02-17T23:06:16+00:00 https://securityaffairs.co/wordpress/128136/hacking/microsoft-teams-attack-vector.html?utm_source=rss&utm_medium=rss&utm_campaign=microsoft-teams-attack-vector www.secnews.physaphae.fr/article.php?IdArticle=4141283 False Malware,Threat None None Security Affairs - Blog Secu New Kraken botnet is allowing operators to earn USD 3,000 every month 2022-02-17T11:01:21+00:00 https://securityaffairs.co/wordpress/128116/malware/golang-kraken-botnet.html?utm_source=rss&utm_medium=rss&utm_campaign=golang-kraken-botnet www.secnews.physaphae.fr/article.php?IdArticle=4137553 False Threat None None Security Affairs - Blog Secu Russia-linked threat actors breached US cleared defense contractors (CDCs) 2022-02-16T21:36:03+00:00 https://securityaffairs.co/wordpress/128099/cyber-warfare-2/russian-hackers-breached-cleared-defense-contractors.html?utm_source=rss&utm_medium=rss&utm_campaign=russian-hackers-breached-cleared-defense-contractors www.secnews.physaphae.fr/article.php?IdArticle=4137555 False Threat None None Security Affairs - Blog Secu Remote sex toys might spice up your love life – but crooks could also get a kick out of them 2022-02-15T05:37:15+00:00 https://securityaffairs.co/wordpress/128028/hacking/lovense-remote-sex-toys-hacking.html?utm_source=rss&utm_medium=rss&utm_campaign=lovense-remote-sex-toys-hacking www.secnews.physaphae.fr/article.php?IdArticle=4131099 False Threat None None Security Affairs - Blog Secu SSU: Russia-linked actors are targeting Ukraine with \'massive wave of hybrid warfare\' 2022-02-14T23:42:02+00:00 https://securityaffairs.co/wordpress/128019/cyber-warfare-2/russia-targets-ukraine-hybrid-warfare.html?utm_source=rss&utm_medium=rss&utm_campaign=russia-targets-ukraine-hybrid-warfare www.secnews.physaphae.fr/article.php?IdArticle=4129238 False Threat None None Security Affairs - Blog Secu Organizations paid at least $602 million to ransomware gangs in 2021 2022-02-13T19:34:40+00:00 https://securityaffairs.co/wordpress/127974/cyber-crime/ransomware-payments-600m-2021.html?utm_source=rss&utm_medium=rss&utm_campaign=ransomware-payments-600m-2021 www.secnews.physaphae.fr/article.php?IdArticle=4122568 False Ransomware,Threat None None Security Affairs - Blog Secu CISA, FBI, NSA warn of the increased globalized threat of ransomware 2022-02-12T18:32:09+00:00 https://securityaffairs.co/wordpress/127923/security/cisa-fbi-nsa-ransomware-alert.html?utm_source=rss&utm_medium=rss&utm_campaign=cisa-fbi-nsa-ransomware-alert www.secnews.physaphae.fr/article.php?IdArticle=4119258 False Ransomware,Threat None None Security Affairs - Blog Secu Croatian phone carrier A1 Hrvatska discloses data breach 2022-02-12T11:46:51+00:00 https://securityaffairs.co/wordpress/127919/data-breach/a1-hrvatska-data-breach.html?utm_source=rss&utm_medium=rss&utm_campaign=a1-hrvatska-data-breach www.secnews.physaphae.fr/article.php?IdArticle=4118291 True Data Breach,Threat None None