Mobile Security

'Karakurt' Extortion Threat Emerges, But Says No to Ransomware

Researchers from Accenture Security have been tracking a group that calls itself “Karakurt,” which means “black wolf” in Turkish and… Read More

2 years ago

80K Retail WooCommerce Sites Exposed by Plugin XSS Bug

The plugin “Variation Swatches for WooCommerce,” installed across 80,000 WordPress-powered retail sites, contains a stored XSS security vulnerability that could… Read More

2 years ago

Threat Actor Behind Thieflock Deploys Yanluowang Ransomware in Attacks Against US Organizations

A threat actor previously tied to the Thieflock ransomware operation may now be using the emerging Yanluowang ransomware in a… Read More

2 years ago

Update: GoDaddy Breach Widens to Include Reseller Subsidiaries

The GoDaddy breach affecting 1.2 million customers has widened – it turns out that various subsidiaries that resell GoDaddy Managed… Read More

2 years ago

Netflix Bait: Phishers Target Streamers with Fake Service Signups

Kaspersky’s researchers observed various lures aimed at targets, depending on their current streaming subscription status. Fake sign-up pages were used… Read More

2 years ago

Advanced threat predictions for 2022

Over the past 12 months, the style and severity of APT threats has continued to evolve. Despite their constantly changing… Read More

2 years ago

Ransomware Phishing Emails Sneak Through SEGs

Researchers are raising the alarm over a phishing email kicking off a Halloween-themed MICROP ransomware offensive, which they observed making… Read More

2 years ago

New Spear-Phishing Campaign Exploits Glitch Platform to Steal Employee Credentials

The campaign appears to be targeting only employees working in the Middle East as “a single campaign” in a series… Read More

2 years ago

Massive Zero-Day Hole Found in Palo Alto Security Appliances

Researchers have developed an exploit to gain remote code execution via a massive vulnerability in a security appliance from Palo… Read More

3 years ago

Multiple BusyBox Security Bugs Threaten Embedded Linux Devices

Researchers have discovered 14 critical vulnerabilities in a popular program used in embedded Linux apps, all of which allow for… Read More

3 years ago

US Casinos of Native Tribal Communities Suffer Millions in Ransomware Losses

The alert named notorious ransomware groups, including Bitpaymer, Conti, Cuba, REvil, Ryuk, and Snatch, which have launched successful attacks on… Read More

3 years ago

Proofpoint Phish Harvests Microsoft O365, Google Logins

According to researchers at Armorblox, they spotted one such campaign lobbed at an unnamed global communications company, with nearly a… Read More

3 years ago

Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar

A new Magecart threat actor is stealing people’s payment card info from their browsers using a digital skimmer that uses… Read More

3 years ago

Pegasus Spyware Maker Blacklisted by the US

NSO Group – the Israeli-based maker of the infamous, military-grade Pegasus spyware that’s been linked to cyberattacks against activists and… Read More

3 years ago

Office 365 Phishing Campaign Uses Kaspersky’s Amazon SES Token

In spite of coming from sender addresses such as noreply@sm.kaspersky.com, nobody at Kaspersky sent the phishing emails, the security company… Read More

3 years ago

Google Chrome is Abused to Deliver Malware as Legit Windows 10 App

Malware delivered via a compromised website on Chrome browsers can bypass User Account Controls to infect systems and steal sensitive… Read More

3 years ago