
SmoothOperator Supply Chain Attack Targeting 3CX VOIP Desktop Client
SmoothOperator Supply Chain Attack Targeting 3CX VOIP Desktop Client [Update] June 21, 2023: Researchers found exposed Elasticsearch and Kibana instances of a third-party vendor of 3CX. Find under the...

Top 20 Cybersecurity Newsletters
Top 20 Cybersecurity Newsletters New threat actors, vulnerabilities, fraud schemes, and other attack campaigns each day make it more challenging to stay current with the cyber world; however, staying ...

How to Maintain Your Online Security? (2023 Edition)
How to Maintain Your Online Security? (2023 Edition) If you’re concerned about your online security and getting more nervous about that, that’s entirely normal. Every day we hear the news ...

Twitter Source Code Leaked on Public GitHub Repository
Twitter Source Code Leaked on Public GitHub Repository The popular social media platform Twitter is actively searching for the person responsible for a recent data leak and any other individ...

Hacktivism on the Rise: KillNet Anonymous Sudan's Cyber Campaign Targe...
Hacktivism on the Rise: KillNet Anonymous Sudan’s Cyber Campaign Targets Australia The world of cyberattacks continues to evolve with the emergence of new hacktivist groups that target different count...

Clop Serial Attacks, TP-Link Exploit & macOS Stealer
Clop Serial Attacks, TP-Link Exploit & macOS Stealer Powered by DarkMirror™ Last week, the dark web’s most spectacular news was the victims that Clop announced one after the other. The threa...

CEO Fraud: Investigating A Gift Card Scam
CEO Fraud: Investigating A Gift Card Scam On March 8, 2023, SOCRadar announced that it received a $5 million Series A investment from 212, a leading equity fund investing in B2B technology start-ups. ...

Magecart Skimmer Attack Targets WooCommerce and Authorize.net Payment ...
Magecart Skimmer Attack Targets WooCommerce and Authorize.net Payment Gateway Plugin Online transactions ease our daily lives but also pose a serious risk to both businesses and their customers. ...

CISA Issues a New Warning for Vulnerabilities in Industrial Control Sy...
CISA Issues a New Warning for Vulnerabilities in Industrial Control Systems (ICS) The recent advisories issued by the US Cybersecurity and Infrastructure Security Agency (CISA) highlight the serious v...

APT Profile: Sandworm
APT Profile: Sandworm Threat actors range from teenagers eager to earn quick cash to state-sponsored actors with agendas behind their operations. The agendas of these state-sponsored groups may includ...

Attackers Exploit Adobe Acrobat Sign to Distribute RedLine Stealer Mal...
Attackers Exploit Adobe Acrobat Sign to Distribute RedLine Stealer Malware Cybercriminals employ many ways to distribute malware, including taking advantage of legitimate services. Recently, security ...

Analysis of the Critical Infrastructure Industries From a Cybersecurit...
Analysis of the Critical Infrastructure Industries From a Cybersecurity Perspective ‘By 2024, a cyberattack will so damage critical infrastructure that a member of the G20 will reciprocate with ...

LockBit and AlphVM Announce New Victims
LockBit and AlphVM Announce New Victims Powered by DarkMirror™ Last week, two notorious ransomware groups added two more names to their victim lists. AlphVM/BlackCat announced the Amazon-owned Ring on...

Telegram 2.0: A New Era of Privacy
Telegram 2.0: A New Era of Privacy On December 6, 2022, Telegram shared a new update blog on its blog page. In this blog post, specific topics attract attention, primarily based on privacy, and will a...

APT Profile: Cozy Bear / APT29
APT Profile: Cozy Bear / APT29 [Update] October 11, 2024: “Joint Advisory Warns of Mass Exploitation of Zimbra and TeamCity Servers by APT29” [Update] February 27, 2024: See the subheading: “Joint Adv...

SAP Fixes Multiple Critical Vulnerabilities on March 2023 Patch Day
SAP Fixes Multiple Critical Vulnerabilities on March 2023 Patch Day SAP has recently fixed 19 vulnerabilities as part of its March 2023 patch day. Five vulnerabilities are rated critical and...

Microsoft Fixes Exploited Zero-Days in March Patch Tuesday (CVE-2023-2...
Microsoft Fixes Exploited Zero-Days in March Patch Tuesday (CVE-2023-23397 & CVE-2023-24880) [Update] December 5, 2023: Microsoft has officially attributed the exploitation of CVE-2023-23397 to AP...

Data of Many Governments are on Sale
Data of Many Governments are on Sale Powered by DarkMirror™ Data held by states is valuable to many threat actors. This information is sometimes used for fraud and sometimes for larger attacks. Data...

What is Malware as a service (MaaS)?
What is Malware as a service (MaaS)? In time, the hacker underworld creates a similar model of Software-as-a-Service (SaaS). Malware as a service and SaaS have a similar duty with one main difference;...

Third-Party Breach Led to Exposure of 9M AT&T Customers' Informati...
Third-Party Breach Led to Exposure of 9M AT&T Customers’ Information Recently, AT&T revealed that a data breach in January compromised the personal information of about 9 ...