The Play ransomware group, also going by the name Playcrypt, has been affecting several kinds of North American, South American, and European enterprises as well as vital infrastructure since June …
Hackers Abusing Search Engine Ads to Deliver DANABOT & DARKGATE Malwares
Threat actors are purchasing advertisements for malicious websites to lure victims into downloading malware, which can eventually lead to data theft and ransomware. This technique was used in several ad …
New Windows Zero-click RCE Flaw Let Attackers Exploit Outlook Clients
Microsoft recently reported that CVE-2023-23397, a critical Outlook vulnerability, is currently being exploited in the wild by a Russian-state-sponsored threat actor known as Forrest Blizzard. This vulnerability allowed threat actors …
Zoom Launches Open-source Vulnerability Impact Scoring System
Zoom, the popular video conferencing platform, has recently announced the launch of its Open-Source Vulnerability Impact Scoring System. This system is designed to provide a standardized method for evaluating the …
PikaBot Attacking Windows Machine via Malicious Search Ads
In the labyrinth of cyber threats that define the digital landscape, 2023 has witnessed the resurgence of a particularly pernicious foe — malicious advertisements, colloquially known as “malvertising.” This nefarious …
Ransomware Gangs Are Collaborating To Attack Financial Services Firms
The Cyber-Extortion Trinity—the BianLian, White Rabbit, and Mario ransomware gangs—was observed by researchers working together to launch a joint extortion campaign against publicly traded financial services companies. Although these joint …
Hackers Actively Exploiting QNAP VioStor NVR Vulnerability to Deploy Mirai Malware
Hackers exploit QNAP devices because they often have known vulnerabilities or misconfigurations that can be exploited for unauthorized access. Besides this, QNAP devices store valuable data, which makes them lucrative …
MongoDB Cyber Attack, Customer Data Exposed
MongoDB has experienced a security incident in which unauthorized access to its corporate systems was identified. However, the company confirmed that there was no evidence of access to any customer’s …
Security Engineer Pleads Guilty For Hacking into Cryptocurrency Exchange
In the intricate tapestry of the cyber landscape, Shakeeb Ahmed’s saga transcends the ordinary, featuring a downfall unparalleled in its significance—the inaugural conviction for hacking a smart contract. A tale …
Hackers are Actively Exploiting Apache Struts 2 Vulnerability
Hackers are taking advantage of a Critical Apache Struts Bug’s initial activity with limited IP addresses engaged in exploitation attempts. Apache is an open-source framework for creating Java EE web …
