Infosec News

InfoSec News 20250331

  • Publicado: Seg, 31/03/2025 - 14:38

Top News


  • Phishing-as-a-service operation uses DNS-over-HTTPS for evasion

"A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection."

Link

TLP1 : Green

InfoSec News 20250328

  • Publicado: Sex, 28/03/2025 - 14:03

Top News


  • 150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling Platforms

"An ongoing campaign that infiltrates legitimate websites with malicious JavaScript injects to promote Chinese-language gambling platforms has ballooned to compromise approximately 150,000 sites to date."

Link

TLP1 : Green

InfoSec News 20250326

  • Publicado: Qua, 26/03/2025 - 13:27

Top News


  • Hackers Using E-Crime Tool Atlantis AIO for Credential Stuffing on 140+ Platforms

"Threat actors are leveraging an e-crime tool called Atlantis AIO Multi-Checker to automate credential stuffing attacks, according to findings from Abnormal Security."

Link

TLP1 : Green

InfoSec News 20250325

  • Publicado: Ter, 25/03/2025 - 14:51

Top News


  • Rilide: The Browser Extension Stealing Your Crypto

A new threat has emerged in the form of a browser extension designed to steal your sensitive information. Pulsedive Threat Research has uncovered “Rilide,” an information stealer masquerading as a legitimate browser extension.

Link

TLP1 : Green

InfoSec News 20250324

  • Publicado: Seg, 24/03/2025 - 14:09

Top News


  • Don’t Click! Fake Chat Used in Meta Business Account Phishing

"In the digital world of likes, follows, and ad conversions, a single email can unravel your entire marketing infrastructure. That’s exactly what a sophisticated phishing campaign discovered by the Cofense Phishing Defense Center (PDC) is exploiting"

Link

TLP1 : Green

InfoSec News 20250321

  • Publicado: Sex, 21/03/2025 - 13:46

Top News


  • Rust Beacon Deploys Cobalt Strike in South Korean Cyber Intrusion Campaign

"Hunt researchers have uncovered a cyber intrusion campaign targeting South Korean organizations, utilizing a sophisticated combination of tools and techniques."

Link

TLP1 : Green

InfoSec News 20250320

  • Publicado: Qui, 20/03/2025 - 14:08

Top News


  • New Arcane infostealer infects YouTube, Discord users via game cheats

"A newly discovered information-stealing malware called Arcane is stealing extensive user data, including VPN account credentials, gaming clients, messaging apps, and information stored in web browsers."

Link

TLP1 : Green

InfoSec News 20250319

  • Publicado: Qua, 19/03/2025 - 13:12

Top News


  • New 'Rules File Backdoor' Attack Lets Hackers Inject Malicious Code via AI Code Editors

"Cybersecurity researchers have disclosed details of a new supply chain attack vector dubbed Rules File Backdoor that affects artificial intelligence (AI)-powered code editors like GitHub Copilot and Cursor, causing them to inject malicious code."

Link

TLP1 : Green

InfoSec News 20250318

  • Publicado: Ter, 18/03/2025 - 13:47

Top News


  • OctoV2 Android Banking Trojan Masquerades as Deepseek AI in Phishing Attack

"A new report from K7 Labs has uncovered a sophisticated Android banking Trojan campaign that uses the guise of a popular AI chatbot to deceive users. The malware, known as OctoV2, is being spread through deceptive websites that mimic the official Deepseek AI chatbot application."

Link

InfoSec News 20250317

  • Publicado: Seg, 17/03/2025 - 14:54

Top News


  • Squid Werewolf APT Masquerades as Recruiters in Espionage Campaign Targeting Key Employees

"The BI.ZONE Threat Intelligence team has uncovered a new cyber-espionage campaign attributed to Squid Werewolf, also known as APT37, Ricochet Chollima, ScarCruft, and Reaper Group."

Link

TLP1 : Green

Páginas