Security news that informs and inspires

All Articles

2327 articles:

MacOS Attackers Likely to Abuse Go-Based Cobalt Strike Variant

Researchers warn that a Go-based implementation of Cobalt Strike beacons, called "Geacon," is lucrative for threat actors in attacks targeting macOS.

Macos, Cobalt Strike

CISA Warns BianLian Ransomware Group Has Moved to Extortion Model

In a new advisory, the FBI and CISA warn that the BianLian ransomware group has moved to a data theft and extortion model.

Ransomware

U.S. Hits Alleged Key Ransomware Actor With Charges, Sanctions

The Russian national allegedly used three well-known ransomware variants - LockBit, Babuk and Hive - to target critical infrastructure victims.

Ransomware, Lockbit, Hive

Microsoft Azure Serial Console Abused in UNC3944 Attacks

An UNC3944 attack highlights how threat actors can abuse legitimate cloud resources for various purposes after compromising the Azure administrator's account.

Azure, Azure AD, Microsoft

Camaro Dragon Group Targets Routers With Malicious Firmware

A Chinese state-affiliated attack group known as Camaro Dragon is targeting some TP-Link routers to install malicious firmware images.

China

Newly Discovered Backdoor Used in Lancefly APT Attacks

A "powerful" backdoor has been uncovered in highly targeted, intel-gathering APT attacks.

APT, Backdoors

Decipher Podcast: Source Code 5/12

Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.

Source Code, Podcast

Ransomware Group Exploits PaperCut Flaw in Education Sector Cyberattacks

CISA warned that a ransomware group exploited vulnerable PaperCut servers in May in order to target the education facilities subsector.

Ransomware, Education

Successful Critical Infrastructure Security Regulations Use Risk-Informed Approach

In order to get critical infrastructure cybersecurity regulations right, regulators need to focus on risk reduction and performance outcomes rather than prescriptive measures, according to a panel at Hack the Capitol 6.0.

Regulation, Government, Critical Infrastructure

Ransomware Actors Adopt Leaked Babuk Code to Hit Linux Systems

Various threat groups are increasingly using Babuk’s leaked source code to build ESXi lockers, including a never-before-seen Linux version of the Play ransomware.

Linux

Greatness Phishing Service Targets Microsoft 365 Users

A new phishing service called Greatness is targeting Office 365 organizations in the U.S. and elsewhere.

Phishing

Ransomware Group Targeted Dragos in Unsuccessful Extortion Attempt

A known ransomware group was able to access limited information resources, which it then attempted to use in an unsuccessful extortion attempt against the company.

Critical Infrastructure Security, Critical Infrastructure, Operational Technology

FBI Disrupts Turla Espionage Malware Network

While Operation Medusa disrupts long standing espionage efforts by Turla, security researchers say that its effects will only be temporary.

Malware

GitHub Enables Push Protection to Prevent Secret Leaks

GitHub has released a new push protection feature to prevent developers from accidentally including secrets in commits.

Github

Intel BootGuard, Firmware Signing Keys Found in MSI Data Leak

Researchers have discovered the firmware signing keys and Intel BootGuard keys for several manufacturers in data dumped by attackers who breached Taiwanese hardware maker MSI.

Data Breach