APT41 Likely Compromised Taiwanese Government-Affiliated Research Institute with ShadowPad and Cobalt Strike

A government-affiliated research organization in Taiwan was attacked by APT41 hackers, a notorious Chinese hacking group known for targeting sensitive technologies. The breach, starting in July 2023, was identified by Cisco Talos researchers.

Cyware News – Latest Cyber News – ​Read More

CISA Warns of Avtech Camera Vulnerability Exploited in Wild

An Avtech camera vulnerability that likely remains unfixed has been exploited in the wild, according to CISA.

The post CISA Warns of Avtech Camera Vulnerability Exploited in Wild appeared first on SecurityWeek.

SecurityWeek – ​Read More

Threat Intelligence: A Blessing and a Curse?

Access to timely and accurate threat intelligence is essential for organizations, but it can be overwhelming to navigate the vast amount of available data and feeds. Balancing comprehensive information with relevance is crucial.

Cyware News – Latest Cyber News – ​Read More

Google Chrome Adds App-Bound Encryption to Block Infostealer Malware

Google Chrome has implemented app-bound encryption to enhance cookie protection on Windows and defend against infostealer malware. This new feature encrypts data tied to app identity, similar to macOS’s Keychain, to prevent unauthorized access.

Cyware News – Latest Cyber News – ​Read More

U.S. Releases High-Profile Russian Hackers in Diplomatic Prisoner Exchange

In a historic prisoner exchange between Belarus, Germany, Norway, Russia, Slovenia, and the U.S., two Russian nationals serving time for cybercrime activities have been freed and repatriated to their country.
This includes Roman Valerevich Seleznev and Vladislav Klyushin, who are part of a group of eight people who have been swapped back to Russia in exchange for the release of 16 people who

The Hacker News – ​Read More

Over 35k Domains Hijacked in ‘Sitting Ducks’ Attacks

Threat actors have hijacked over 35,000 domains in five years because DNS providers fail to properly verify domain ownership.

The post Over 35k Domains Hijacked in ‘Sitting Ducks’ Attacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

Cybersecurity M&A Roundup: 25 Deals Announced in July 2024

Roundup of the more than two dozen cybersecurity-related merger and acquisition (M&A) deals announced in July 2024.

The post Cybersecurity M&A Roundup: 25 Deals Announced in July 2024 appeared first on SecurityWeek.

SecurityWeek – ​Read More

Russia, Moldova Targeted by Obscure Hacking Group in New Cyberespionage Campaign

A cyberespionage group known as XDSpy targeted Russia and Moldova with new malware. The group sent phishing emails to Russian targets, including a tech company and an organization in Transnistria.

Cyware News – Latest Cyber News – ​Read More

Malicious Package Hidden in PyPI Discovered

The FortiGuard Labs team has discovered a malicious PyPI package that poses a significant risk to individuals and institutions by potentially leaking credentials and sensitive information.

Cyware News – Latest Cyber News – ​Read More

Cybercriminals Abusing Cloudflare Tunnels to Evade Detection and Spread Malware

Cybersecurity companies are warning about an uptick in the abuse of Clouflare’s TryCloudflare free service for malware delivery.
The activity, documented by both eSentire and Proofpoint, entails the use of TryCloudflare to create a one-time tunnel that acts as a conduit to relay traffic from an attacker-controlled server to a local machine through Cloudflare’s infrastructure.
Attack chains

The Hacker News – ​Read More