Infosec News

InfoSec News 20250404

  • Publicado: Sex, 04/04/2025 - 13:43

Top News


  • Microsoft Warns of Tax-Themed Email Attacks Using PDFs and QR Codes to Deliver Malware

"Microsoft is warning of several phishing campaigns that are leveraging tax-related themes to deploy malware and steal credentials."

Link

TLP1 : Green

InfoSec News 20250402

  • Publicado: Qua, 02/04/2025 - 14:05

Top News


  • Nearly 24,000 IPs Target PAN-OS GlobalProtect in Coordinated Login Scan Campaign

"Cybersecurity researchers are warning of a spike in suspicious login scanning activity targeting Palo Alto Networks PAN-OS GlobalProtect gateways, with nearly 24,000 unique IP addresses attempting to access these portals."

Link

TLP1 : Green

InfoSec News 20250401

  • Publicado: Ter, 01/04/2025 - 14:04

Top News


  • KoiLoader Reloaded: New Variant Uses LNK Abuse, Script Chains, and PowerShell to Deliver Stealer Payload

"eSentire’s Threat Response Unit (TRU) has detected an intrusion attempt involving a new version of KoiLoader, a malware loader used to facilitate Command and Control (C&C) and deploy Koi Stealer, an information stealer."

Link

InfoSec News 20250331

  • Publicado: Seg, 31/03/2025 - 14:38

Top News


  • Phishing-as-a-service operation uses DNS-over-HTTPS for evasion

"A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection."

Link

TLP1 : Green

InfoSec News 20250328

  • Publicado: Sex, 28/03/2025 - 14:03

Top News


  • 150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling Platforms

"An ongoing campaign that infiltrates legitimate websites with malicious JavaScript injects to promote Chinese-language gambling platforms has ballooned to compromise approximately 150,000 sites to date."

Link

TLP1 : Green

InfoSec News 20250326

  • Publicado: Qua, 26/03/2025 - 13:27

Top News


  • Hackers Using E-Crime Tool Atlantis AIO for Credential Stuffing on 140+ Platforms

"Threat actors are leveraging an e-crime tool called Atlantis AIO Multi-Checker to automate credential stuffing attacks, according to findings from Abnormal Security."

Link

TLP1 : Green

InfoSec News 20250325

  • Publicado: Ter, 25/03/2025 - 14:51

Top News


  • Rilide: The Browser Extension Stealing Your Crypto

A new threat has emerged in the form of a browser extension designed to steal your sensitive information. Pulsedive Threat Research has uncovered “Rilide,” an information stealer masquerading as a legitimate browser extension.

Link

TLP1 : Green

InfoSec News 20250324

  • Publicado: Seg, 24/03/2025 - 14:09

Top News


  • Don’t Click! Fake Chat Used in Meta Business Account Phishing

"In the digital world of likes, follows, and ad conversions, a single email can unravel your entire marketing infrastructure. That’s exactly what a sophisticated phishing campaign discovered by the Cofense Phishing Defense Center (PDC) is exploiting"

Link

TLP1 : Green

InfoSec News 20250321

  • Publicado: Sex, 21/03/2025 - 13:46

Top News


  • Rust Beacon Deploys Cobalt Strike in South Korean Cyber Intrusion Campaign

"Hunt researchers have uncovered a cyber intrusion campaign targeting South Korean organizations, utilizing a sophisticated combination of tools and techniques."

Link

TLP1 : Green

InfoSec News 20250320

  • Publicado: Qui, 20/03/2025 - 14:08

Top News


  • New Arcane infostealer infects YouTube, Discord users via game cheats

"A newly discovered information-stealing malware called Arcane is stealing extensive user data, including VPN account credentials, gaming clients, messaging apps, and information stored in web browsers."

Link

TLP1 : Green

Páginas