News:

Lab - Just Launched!

Main Menu

Recent posts

#71
IT News / Chinese Hackers Deploy SpiceRA...
Last post by ixsky -
Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign

A previously undocumented Chinese-speaking threat actor codenamed SneakyChef has been linked to an espionage campaign primarily targeting government entities across Asia and EMEA (Europe, Middle East, and Africa) with SugarGh0st malware since at least August 2023.
"SneakyChef uses lures that are scanned documents of government agencies, most of which are related to various countries' Ministries

Source: Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign
#72
IT News / Military-themed Email Scam Spr...
Last post by ixsky -
Military-themed Email Scam Spreads Malware to Infect Pakistani Users

Cybersecurity researchers have shed light on a new phishing campaign that has been identified as targeting people in Pakistan using a custom backdoor.
Dubbed PHANTOM#SPIKE by Securonix, the unknown threat actors behind the activity have leveraged military-related phishing documents to activate the infection sequence.
"While there are many methods used today to deploy malware, the threat actors

Source: Military-themed Email Scam Spreads Malware to Infect Pakistani Users
#73
IT News / U.K. Hacker Linked to Notoriou...
Last post by ixsky -
U.K. Hacker Linked to Notorious Scattered Spider Group Arrested in Spain

Law enforcement authorities have allegedly arrested a key member of the notorious cybercrime group called Scattered Spider.
The individual, a 22-year-old man from the United Kingdom, was arrested this week in the Spanish city of Palma de Mallorca as he attempted to board a flight to Italy. The move is part of a joint effort between the U.S. Federal Bureau of Investigation (FBI) and the Spanish

Source: U.K. Hacker Linked to Notorious Scattered Spider Group Arrested in Spain
#74
IT News / Infocon: green
Last post by ixsky -
Infocon: green

ISC Stormcast For Friday, June 21st, 2024 https://isc.sans.edu/podcastdetail/9030

Source: Infocon: green
#75
IT News / Advance Auto Parts confirms da...
Last post by ixsky -
Advance Auto Parts confirms data breach exposed employee information

Advance Auto Parts has confirmed it suffered a data breach after a threat actor attempted to sell stolen data on a hacking forum earlier this month. [...]

Source: Advance Auto Parts confirms data breach exposed employee information
#76
IT News / How to Use Tines's SOC Automat...
Last post by ixsky -
How to Use Tines's SOC Automation Capability Matrix

Created by John Tuckner and the team at automation and AI-powered workflow platform Tines, the SOC Automation Capability Matrix (SOC ACM) is a set of techniques designed to help security operations teams understand their automation capabilities and respond more effectively to incidents. 
A customizable, vendor-agnostic tool featuring lists of automation opportunities, it's

Source: How to Use Tines's SOC Automation Capability Matrix
#77
IT News / Oyster Backdoor Spreading via ...
Last post by ixsky -
Oyster Backdoor Spreading via Trojanized Popular Software Downloads

A malvertising campaign is leveraging trojanized installers for popular software such as Google Chrome and Microsoft Teams to drop a backdoor called Oyster (aka Broomstick and CleanUpLoader).
That's according to findings from Rapid7, which identified lookalike websites hosting the malicious payloads that users are redirected to after searching for them on search engines like Google and Bing.
The

Source: Oyster Backdoor Spreading via Trojanized Popular Software Downloads
#78
IT News / SolarWinds Serv-U Vulnerabilit...
Last post by ixsky -
SolarWinds Serv-U Vulnerability Under Active Attack - Patch Immediately

A recently patched high-severity flaw impacting SolarWinds Serv-U file transfer software is being actively exploited by malicious actors in the wild.
The vulnerability, tracked as CVE-2024-28995 (CVSS score: 8.6), concerns a directory transversal bug that could allow attackers to read sensitive files on the host machine.
Affecting all versions of the software prior to and including Serv-U 15.4.2

Source: SolarWinds Serv-U Vulnerability Under Active Attack - Patch Immediately
#79
IT News / ISC Stormcast For Friday, June...
Last post by ixsky -
ISC Stormcast For Friday, June 21st, 2024 https://isc.sans.edu/podcastdetail/9030, (Fri, Jun 21st)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Source: ISC Stormcast For Friday, June 21st, 2024 https://isc.sans.edu/podcastdetail/9030, (Fri, Jun 21st)
#80
IT News / CDK Global cyberattack impacts...
Last post by ixsky -
CDK Global cyberattack impacts thousands of US car dealerships

Car dealership software-as-a-service provider CDK Global was hit by a massive cyberattack, causing the company to shut down its systems and leaving clients unable to operate their business normally. [...]

Source: CDK Global cyberattack impacts thousands of US car dealerships