Recent reports suggest threat actors have used phishing emails to distribute fileless malware. The attachment consists of a .hta (HTML Application) file, which can be used for deploying other malware …
Hackers Attacking MSSQL Servers To Deploy Ransomware
Recently, threat actors have been utilizing brute force attacks to compromise exposed MSSQL databases to distribute the FreeWorld ransomware. This attack campaign, dubbed DB#JAMMER, is notable, according to Securonix Threat Labs, …
Sophisticated Earth Estries Group Hack Government Agencies and Tech Companies
A new sophisticated cyber espionage group named Earth Estries, which overlaps notorious threat group FamousSparrow, was unveiled. The group has been active since 2020 and targets multiple government and technology …
Apple Opens Application for Security Research Device Program
Apple launched the Security Research Device (SRD) program, enabling security researchers to examine the security features of a specially-built hardware variant of the iPhone 14 Pro. Apple Security Bounty is …
Vulnerability in IBM Security Verify Let Attacker Extract Sensitive Information
Multiple Information Disclosure vulnerabilities were discovered in the IBM Security Verify Information Queue, which can reveal several internal product details. This information can then be used to conduct further attacks. …
Top 10 Best DDoS Protection Tools & Services – 2023
A Distributed Denial-of-Service (DDoS) attack is a malicious attempt to interrupt the regular traffic of a targeted server, service, or network by flooding the target or the area around it …
Threat and Vulnerability Roundup for the week of August 27th to September 2nd
We are glad to present the most recent news on cybersecurity in this week’s Threat and Vulnerability Roundup from Cyber Writes. The latest attack techniques, significant weaknesses, and exploits have …
SapphireStealer: A .NET Malware Capable of Stealing Sensitive Data from Computers
SapphireStealer is an open-source information stealer that may be utilized for obtaining sensitive information, such as corporate credentials, which are frequently sold to other threat actors who utilize the access for …
North Korea’s Hacker Group Deploys Malicious Version of Python Package in PyPI Repository
ReversingLabs spotted “VMConnect” in early August, a malicious supply chain campaign with two dozen rogue Python packages on PyPI. It’s been observed that these packages mimicked the following known open-source …
Junos OS Flaw Allows a Network-based Attacker to Launch DoS Attack
Junos OS and Junos OS Evolved have been found to be vulnerable to a DoS (Denial of Service) condition, which an unauthenticated, network-based attacker can exploit. Juniper Networks has addressed …

