Infosec News

InfoSec News 20231219

  • Publicado: Ter, 19/12/2023 - 15:08

Top News


  • Hackers Abusing GitHub to Evade Detection and Control Compromised Hosts

"Threat actors are increasingly making use of GitHub for malicious purposes through novel methods, including abusing secret Gists and issuing malicious commands via git commit messages."

Link

TLP1 : Green

InfoSec News 20231218

  • Publicado: Seg, 18/12/2023 - 16:51

Top News


  • CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats

"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging manufacturers to get rid of default passwords on internet-exposed systems altogether, citing severe risks that could be exploited by malicious actors to gain initial access to, and move laterally within, organizations."

Link

InfoSec News 20231215

  • Publicado: Sex, 15/12/2023 - 16:51

Top News


  • New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks

"A new botnet consisting of firewalls and routers from Cisco, DrayTek, Fortinet, and NETGEAR is being used as a covert data transfer network for advanced persistent threat actors, including the China-linked threat actor called Volt Typhoon."

Link

TLP1 : Green

InfoSec News 20231214

  • Publicado: Qui, 14/12/2023 - 15:35

Top News


  • Microsoft Takes Legal Action to Crack Down on Storm-1152's Cybercrime Network

"Microsoft on Wednesday said it obtained a court order to seize infrastructure set up by a group called Storm-1152 that peddled roughly 750 million fraudulent Microsoft accounts and tools through a network of bogus websites and social media pages to other criminal actors, netting them millions of dollars in illicit revenue."

Link

InfoSec News 20231213

  • Publicado: Qua, 13/12/2023 - 13:21

Top News


  • Microsoft Warns of Hackers Exploiting OAuth for Cryptocurrency Mining and Phishing

"Microsoft has warned that adversaries are using OAuth applications as an automation tool to deploy virtual machines (VMs) for cryptocurrency mining and launch phishing attacks."

Link

TLP1 : Green

InfoSec News 20231212

  • Publicado: Ter, 12/12/2023 - 15:03

Top News


  • New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam

"A phishing campaign has been observed delivering an information stealer malware called MrAnon Stealer to unsuspecting victims via seemingly benign booking-themed PDF lures."

Link

TLP1 : Green

InfoSec News 20231211

  • Publicado: Seg, 11/12/2023 - 15:46

Top News


  • AutoSpill attack steals credentials from Android password managers

"Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation."

Link

TLP1 : Green

InfoSec News 20231207

  • Publicado: Qui, 07/12/2023 - 14:54

Top News


  • New Stealthy 'Krasue' Linux Trojan Targeting Telecom Firms in Thailand

"A previously unknown Linux remote access trojan called Krasue has been observed targeting telecom companies in Thailand by threat actors to main covert access to victim networks at lease since 2021."

Link

InfoSec News 20231206

  • Publicado: Qua, 06/12/2023 - 14:20

Top News


  • Alert: Threat Actors Can Leverage AWS STS to Infiltrate Cloud Accounts

"Threat actors can take advantage of Amazon Web Services Security Token Service (AWS STS) as a way to infiltrate cloud accounts and conduct follow-on attacks."

Link

TLP1 : Green

InfoSec News 20231205

  • Publicado: Ter, 05/12/2023 - 14:27

Top News


  • Britain says no evidence of Sellafield nuclear site hacking

"Britain has no records or evidence to suggest that networks at the Sellafield nuclear site were the victim of a successful cyber attack by state actors, the government said on Monday following a report by the Guardian newspaper."

Link

Páginas