Cyber Security News

Windows Vulnerability Actively Exploited By Void Banshee
Date

Windows Vulnerability Actively Exploited By Void Banshee

A recently discovered and patched Windows vulnerability, CVE-2024-43461, has been seen used in the wild by the advanced persistent threat (APT) group Void Banshee. Microsoft describes the vulnerability as a "Windows MSHTML spoofing vulnerability" and first disclosed it to the public following Septem

MacroPack Abused By Threat Actors To Deploy Brute Ratel
Date

MacroPack Abused By Threat Actors To Deploy Brute Ratel

MacroPack, a framework developed by security researchers for red team exercises, has been abused by various threat actors to deliver several malware payloads to victims. Cisco Talos discovered that threat actors were using MacroPack to deploy malicious payloads that included Havoc, Brute Ratel, and

Halliburton Cyberattack Linked To RansomHub
Date

Halliburton Cyberattack Linked To RansomHub

In a recent filing to the U.S. Securities and Exchange Commission (SEC), oil and gas services giant Halliburton revealed they had suffered a cyberattack that disrupted the company's IT systems and business operations. According to the filing, the company reported the attack on August 21, 2024.

South Korean APT Group Exploits WPS Office Zero-Day
Date

South Korean APT Group Exploits WPS Office Zero-Day

In recently published research, researchers at security firm ESET discovered a zero-day vulnerability impacting WPS Office for Windows. WPS Office, developed by Chinese firm Kingsoft, is incredibly popular in Asia. Reportedly, it has over 500 million active users worldwide. ESET researchers discove

Banking Credentials Stolen Via PWA Apps
Date

Banking Credentials Stolen Via PWA Apps

Threat actors have begun using progressive web applications (PWA) to impersonate banking apps with the goal of tricking victims into unwillingly handing over online banking credentials. PWAs have been defined as, ...an app that's built using web platform technologies, but that provides a us

3AM Ransomware Targets Non-Profit Healthcare
Date

3AM Ransomware Targets Non-Profit Healthcare

Kootenai Health, a not-for-profit healthcare provider in Idaho, operating the largest hospital in the region, offering a wide range of medical services, including emergency care, surgery, cancer treatment, cardiac care, and orthopedics, disclosed they had suffered a data breach. Approximately over

GPS Spoofers "Hack Time"
Date

GPS Spoofers "Hack Time"

A recent article published by Reuters shows a marked increase in GPS Spoofing attacks targeting airlines. GPS spoofing is a malicious attack in which Global Positioning System (GPS) data is manipulated to mislead a GPS receiver about its actual location. This could cause significant disruptions, as

Dark Angels Ransomware Gets Record Breaking Ransom Payment
Date

Dark Angels Ransomware Gets Record Breaking Ransom Payment

A recent report by Zscaler revealed that the Dark Angels ransomware gang received a record-breaking 75 million USD ransom payment from a Fortune 50 company. The report stated, In early 2024, ThreatLabz uncovered a victim who paid Dark Angels $75 million, higher than any publicly known amoun