Infosec News

InfoSec News 20250217

  • Publicado: Seg, 17/02/2025 - 14:32

Top News


  • OAuth Phishing Alert: Fake 'Adobe Drive X' App Abusing Microsoft Login

"Threat actors have taken phishing to the next level by weaponizing custom Microsoft 365 applications to request sensitive information from users."

Link

TLP1 : Green

InfoSec News 20250214

  • Publicado: Sex, 14/02/2025 - 14:38

Top News


  • whoAMI attacks give hackers code execution on Amazon EC2 instances

"Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name."

Link

TLP1 : Green

InfoSec News 20250213

  • Publicado: Qui, 13/02/2025 - 14:16

Top News


  • Russia-linked APT Seashell Blizzard is behind the long running global access operation BadPilot campaign

"A subgroup of the Russia-linked Seashell Blizzard APT group (aka Sandworm) ran a global multi-year initial access operation called BadPilot."

Link

TLP1 : Green

InfoSec News 20250212

  • Publicado: Qua, 12/02/2025 - 15:13

Top News


  • North Korea-linked APT Emerald Sleet is using a new tactic

"Microsoft Threat Intelligence has observed North Korea-linked APT Emerald Sleet using a new tactic, tricking targets into running PowerShell."

Link

TLP1 : Green

InfoSec News 20250211

  • Publicado: Ter, 11/02/2025 - 14:52

Top News


  • Crooks use Google Tag Manager skimmer to steal credit card data from a Magento-based e-stores

"Sucuri researchers observed threat actors leveraging Google Tag Manager (GTM) to install e-skimmer software on Magento-based e-stores."

Link

TLP1 : Green

InfoSec News 20250210

  • Publicado: Seg, 10/02/2025 - 14:41

Top News


  • Massive brute force attack uses 2.8 million IPs to target VPN devices

"A large-scale brute force password attack using almost 2.8 million IP addresses is underway, attempting to guess the credentials for a wide range of networking devices, including those from Palo Alto Networks, Ivanti, and SonicWall."

Link

TLP1 : Green

InfoSec News 20250207

  • Publicado: Sex, 07/02/2025 - 13:39

Top News


  • Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam

"Bitdefender Labs warns of an active campaign by the North Korea-linked Lazarus Group, targeting organizations by capturing credentials and delivering malware through fake LinkedIn job offers."

Link

TLP1 : Green

InfoSec News 20250206

  • Publicado: Qui, 06/02/2025 - 14:12

Top News


  • Hackers spoof Microsoft ADFS login pages to steal credentials

"A help desk phishing campaign targets an organization's Microsoft Active Directory Federation Services (ADFS) using spoofed login pages to steal credentials and bypass multi-factor authentication (MFA) protections."

Link

TLP1 : Green

InfoSec News 20250205

  • Publicado: Qua, 05/02/2025 - 14:10

Top News


  • AsyncRAT Abusing Python and TryCloudflare For Stealthy Malware Delivery

"In a significant finding, Forcepoint’s X-Labs research team has uncovered a new malware campaign that uses AsyncRAT, a notorious remote access trojan (RAT), along with Python scripting and TryCloudflare tunnels to deliver malicious payloads with enhanced stealth."

Link

TLP1 : Green

InfoSec News 20250204

  • Publicado: Ter, 04/02/2025 - 14:41

Top News


  • 1-Click Phishing Campaign Targets High-Profile X Accounts

"In an attack vector that's been used before, threat actors aim to commit crypto fraud by hijacking highly followed users, thus reaching a broad audience of secondary victims."

Link

TLP1 : Green

Páginas