Category: News

‘Azurescape’ Kubernetes Attack Allows Cross-Container Cloud Compromise

A chain of exploits could allow a malicious Azure user to infiltrate other customers’ cloud instances within Microsoft’s container-as-a-service offering.

SideWalk Backdoor Linked to China-Linked Spy Group ‘Grayfly’

Grayfly campaigns have launched the novel malware against businesses in Taiwan, Vietnam, the US and Mexico and are targeting Exchange and MySQL servers. 

Zoho Password Manager Zero-Day Bug Under Active Attack Gets a Fix

An authentication bypass vulnerability leading to remote code execution offers up the keys to the corporate kingdom.

BladeHawk Attackers Target Kurds with Android Apps

Pro-Kurd Facebook profiles deliver ‘888 RAT’ and ‘SpyNote’ trojans, masked as legitimate apps, to perform mobile espionage.

What Ragnar Locker Got Wrong About Ransomware Negotiators – Podcast

There are a lot of “tells” that the ransomware group doesn’t understand how negotiators work, despite threatening to dox data if victims call for help.

Tooling Network Detection & Response for Ransomware

Justin Jett, director of audit and compliance at Plixer, discusses how to effectively use network flow data in the fight against ransomware.

Spoofing Bug Highlights Cybersecurity for Digital Vaccine Passports

Australian immunization app bug lets attackers fake vaccine status.

TeamTNT’s New Tools Target Multiple OS

The attackers are indiscriminately striking thousands of victims worldwide with their new “Chimaera” campaign.

Microsoft, CISA Urge Mitigations for Zero-Day RCE Flaw in Windows

Attackers are actively attempting to exploit a vulnerability in MSHTML that allows them to craft a malicious ActiveX control to be used by Microsoft Office files.

Ragnar Locker Gang Warns Victims Not to Call the FBI

Investigators/the FBI/ransomware negotiators just screw everything up, the ransomware gang said, threatening to publish files if victims look for help.