hacks

Malicious Exchange Server Module Hoovers Up Outlook Credentials

Researchers have uncovered a previously unknown malicious Internet Information Services (IIS) module, dubbed Owowa, that steals credentials when users log… Read More

2 years ago

Anubis Trojan Spoofs Legitimate App to Infect Customers of Hundreds of Banks

Customers of Chase, Wells Fargo, Bank of America, and Capital One, along with nearly 400 other financial firms, are being… Read More

2 years ago

When Scammers Get Scammed, They Take It to Cybercrime Court

To file a complaint with the cybercriminal court in one large underground forum, the user is required to open a… Read More

2 years ago

'Karakurt' Extortion Threat Emerges, But Says No to Ransomware

Researchers from Accenture Security have been tracking a group that calls itself “Karakurt,” which means “black wolf” in Turkish and… Read More

2 years ago

80K Retail WooCommerce Sites Exposed by Plugin XSS Bug

The plugin “Variation Swatches for WooCommerce,” installed across 80,000 WordPress-powered retail sites, contains a stored XSS security vulnerability that could… Read More

2 years ago

Threat Actor Behind Thieflock Deploys Yanluowang Ransomware in Attacks Against US Organizations

A threat actor previously tied to the Thieflock ransomware operation may now be using the emerging Yanluowang ransomware in a… Read More

2 years ago

Update: GoDaddy Breach Widens to Include Reseller Subsidiaries

The GoDaddy breach affecting 1.2 million customers has widened – it turns out that various subsidiaries that resell GoDaddy Managed… Read More

2 years ago

Netflix Bait: Phishers Target Streamers with Fake Service Signups

Kaspersky’s researchers observed various lures aimed at targets, depending on their current streaming subscription status. Fake sign-up pages were used… Read More

2 years ago

Ransomware Phishing Emails Sneak Through SEGs

Researchers are raising the alarm over a phishing email kicking off a Halloween-themed MICROP ransomware offensive, which they observed making… Read More

2 years ago

New Spear-Phishing Campaign Exploits Glitch Platform to Steal Employee Credentials

The campaign appears to be targeting only employees working in the Middle East as “a single campaign” in a series… Read More

2 years ago

Massive Zero-Day Hole Found in Palo Alto Security Appliances

Researchers have developed an exploit to gain remote code execution via a massive vulnerability in a security appliance from Palo… Read More

3 years ago

Multiple BusyBox Security Bugs Threaten Embedded Linux Devices

Researchers have discovered 14 critical vulnerabilities in a popular program used in embedded Linux apps, all of which allow for… Read More

3 years ago

US Casinos of Native Tribal Communities Suffer Millions in Ransomware Losses

The alert named notorious ransomware groups, including Bitpaymer, Conti, Cuba, REvil, Ryuk, and Snatch, which have launched successful attacks on… Read More

3 years ago

Proofpoint Phish Harvests Microsoft O365, Google Logins

According to researchers at Armorblox, they spotted one such campaign lobbed at an unnamed global communications company, with nearly a… Read More

3 years ago

Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar

A new Magecart threat actor is stealing people’s payment card info from their browsers using a digital skimmer that uses… Read More

3 years ago

Pegasus Spyware Maker Blacklisted by the US

NSO Group – the Israeli-based maker of the infamous, military-grade Pegasus spyware that’s been linked to cyberattacks against activists and… Read More

3 years ago