Threat actors of Iranian origin, CharmingCypress (also known as Charming Kitten, APT42, TA453), have gathered political intelligence against international targets, with a special emphasis on journalists, think tanks, and NGOs. …
Multipurpose Glupteba Malware Controls OS Boot Process to Hide Itself
Glupteba, a decade-old malware in financial cybercrime, unveiled a new campaign in November 2023. Despite its long tenure, the undiscovered features include a UEFI bootkit that allows stealthy persistence, challenging …
Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited …
10 Best Secure Network As a Service for MSP Providers – 2024
Secure Network as a Service (SNaaS) for Managed Service Providers (MSPs) delivers networking and security services to clients via the cloud, integrating networking advantages with complete protection. This strategy allows …
ANY.RUN Threat Intelligence Lookup Tool – A Repository of Millions of Malware IOCs
Malware sandbox leader ANY.RUN introduced the Threat Intelligence Lookup platform that helps security researchers find the relevant threat data from the sandbox tasks of ANY.RUN. The platform aids in identifying …
Canada to Ban Flipper Zero Device Over Car Hacking Fears
The Canadian government has banned Flipper Zero, a compact and customizable hacking tool, citing concerns over its potential use in automotive theft. At a recent summit, François-Philippe Champagne, Canada’s Minister …
CISA Warns Of Active Attacks on Roundcube Webmail XSS Vulnerability
CISA, the Cybersecurity and Infrastructure Security Agency, has issued a warning regarding a Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail that is currently being targeted by attackers in the wild. …
10 Best Network Security Providers for Education Sectors – 2024
Network security providers for education safeguard schools, colleges, and educational institutions against cyberattacks. These providers protect student, research, and administrative data, comply with legal and regulatory requirements, and provide a …
Hackers Exploiting Ivanti SSRF Flaw to Inject DSLog Malware
Ivanti Connect Secure was previously discovered with another SSRF vulnerability that could allow unauthenticated threat actors to access unrestricted resources due to a flaw in the SAML module. The vulnerability …
Coyote Malware Leverage NodeJS to Attack Users of 60+ Bank Users
In banking attacks, threat actors actively exploit the NodeJS to steal the online banking credentials of the targeted users. Threat actors use JavaScript web injections to alter the login page …

