Infosec News

InfoSec News 20241219

  • Publicado: Qui, 19/12/2024 - 14:17

Top News


  • SADBRIDGE Loader Unveils GOSAR Backdoor in Cyber Attacks

"Elastic Security Labs has revealed a significant evolution in malware development with the discovery of GOSAR, a Golang-based rewrite of the widely recognized QUASAR Remote Access Trojan (RAT). This newly developed variant surfaced during investigations into campaigns targeting Chinese-speaking regions, where attackers used SADBRIDGE, a custom malware loader, to deploy GOSAR backdoor."

InfoSec News 20241218

  • Publicado: Qua, 18/12/2024 - 13:39

Top News


  • CoinLurker: The Stealer Powering the Next Generation of Fake Updates

"The evolution of fake update campaigns has advanced significantly with the emergence of CoinLurker, a sophisticated stealer designed to exfiltrate data while evading detection. Written in Go, CoinLurker employs cutting-edge obfuscation and anti-analysis techniques, making it a highly effective tool in modern cyberattacks. "

Link

InfoSec News 20241217

  • Publicado: Ter, 17/12/2024 - 14:20

Top News


  • New Investment Scam Leverages AI, Social Media Ads to Target Victims Worldwide

"Cybersecurity researchers are calling attention to a new kind of investment scam that leverages a combination of social media malvertising, company-branded posts, and artificial intelligence (AI) powered video testimonials featuring famous personalities, ultimately leading to financial and data loss."

Link

InfoSec News 20241216

  • Publicado: Seg, 16/12/2024 - 13:39

Top News


  • CVE-2024-11053: Curl Vulnerability Exposes User Credentials in Redirects

"A recently discovered vulnerability in the popular curl command line tool and library, tracked as CVE-2024-11053 and assigned a CVSS score of 9.1, could lead to the unintended exposure of user credentials. The vulnerability arises from the interaction between the use of .netrc files for storing credentials and curl’s handling of HTTP redirects."

InfoSec News 20241213

  • Publicado: Sex, 13/12/2024 - 14:17

Top News


  • ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms

"Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago."

Link

InfoSec News 20241212

  • Publicado: Qui, 12/12/2024 - 13:56

Top News


  • Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts

"Cybersecurity researchers have flagged a "critical" security vulnerability in Microsoft's multi-factor authentication (MFA) implementation that allows an attacker to trivially sidestep the protection and gain unauthorized access to a victim's account."

Link

InfoSec News 20241210

  • Publicado: Ter, 10/12/2024 - 14:48

Top News


  • Socks5Systemz Botnet Powers Illegal Proxy Service with 85,000+ Hacked Devices

"A malicious botnet called Socks5Systemz is powering a proxy service called PROXY.AM, according to new findings from Bitsight."

Link

TLP1 : Green

InfoSec News 20241209

  • Publicado: Seg, 09/12/2024 - 14:54

Top News


  • Hackers Leveraging Cloudflare Tunnels, DNS Fast-Flux to Hide GammaDrop Malware

"The threat actor known as Gamaredon has been observed leveraging Cloudflare Tunnels as a tactic to conceal its staging infrastructure hosting a malware called GammaDrop."

Link

TLP1 : Green

InfoSec News 20241206

  • Publicado: Sex, 06/12/2024 - 13:36

Top News


  • CVE-2024-53990 (CVSS 9.2): AsyncHttpClient Vulnerability Puts Java Applications at Risk

"A critical severity vulnerability (CVE-2024-53990) has been discovered in the AsyncHttpClient (AHC) library, a popular Java library used for making asynchronous HTTP requests. This vulnerability, with a CVSS score of 9.2, could allow attackers to exploit user sessions and potentially gain unauthorized access to sensitive information."

Páginas