Threatpost: Recent Episodes

None

The First Stop For Security News

View Details

2.5 million people were affected, in a breach that could spell more trouble down the line.

View Details

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

View Details

Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.

View Details

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

View Details

Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

View Details

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

View Details

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

View Details

Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.

View Details

Apple is urging macOS, iPhone and iPad users immediately to install respective updates this week that includes fixes for two zero-days under active attack. The patches are for vulnerabilities that allow attackers to execute arbitrary code and ultimately take over devices. iOS 15.6.1 and macOS Monterey 12.5.1 both patch the two flaws, which basically impact […]

View Details

Google has patched the fifth actively exploited zero-day vulnerability discovered in Chrome this year as one in a series of fixes included in a stable channel update released Wednesday. The bug, tracked as CVE-2022-2856 and rated as high on the Common Vulnerability Scoring System (CVSS), is associated with “insufficient validation of untrusted input in Intents,” […]

View Details

The North Korean APT is using a fake job posting for Coinbase in a cyberespionage campaign targeting users of both Apple and Intel-based systems.

View Details

The incident disrupted corporate IT systems at one company while attackers misidentified the victim in a post on its website that leaked stolen data.

View Details

Mobile transactions could’ve been disabled, created and signed by attackers.

View Details

‘Summer Camp’ for hackers features a compromised satellite, a homecoming for hackers and cyberwarfare warnings.

View Details

The CISA has seen a resurgence of the malware targeting a range of verticals and critical infrastructure organizations by exploiting RDP, firewall vulnerabilities.

View Details

Researcher shows how Instagram and Facebook’s use of an in-app browser within both its iOS apps can track interactions with external websites.

View Details

Belgian researcher Lennert Wouters revealed at Black Hat how he mounted a successful fault injection attack on a user terminal for SpaceX’s satellite-based internet system

View Details

A uniquely politically motivated site called DUMPS focuses solely on threat activity directed against Russia and Belarus

View Details

Networking giant says attackers gained initial access to an employee’s VPN client via a compromised Google account.

View Details

This edition of the Threatpost podcast is sponsored by Egress.

View Details

August Patch Tuesday tackles 121 CVEs, 17 critical bugs and one zero-day bug exploited in the wild.

View Details

U.S. Treasury blocked the business of the virtual currency mixer for laundering more than $7 billion for hackers, including $455 million to help fund North Korea’s missile program.

View Details

Attackers are spoofing the widely used cryptocurrency exchange to trick users into logging in so they can steal their credentials and eventually their funds.

View Details

Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims.

View Details

Vulnerability—for which a proof-of-concept is forthcoming—is one of a string of flaws the company fixed that could lead to an attack chain.

View Details

DMARC analysis by Proofpoint shows that institutions in the U.S. have among some of the poorest protections to prevent domain spoofing and lack protections to block fraudulent emails.

View Details

Infosec expert Rani Osnat lays out security challenges and offers hope for organizations migrating their IT stack to the private and public cloud environments.

View Details

Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods.

View Details

Cybercriminals turn to container files and other tactics to get around the company’s attempt to thwart a popular way to deliver malicious phishing payloads.

View Details

Built-in Telegram and Discord services are fertile ground for storing stolen data, hosting malware and using bots for nefarious purposes.

View Details

Newly discovered malware linked to Vietnamese threat actors targets users through a LinkedIn phishing campaign to steal data and admin privileges for financial gain.

View Details

Instances of phishing attacks leveraging the Microsoft brand increased 266 percent in Q1 compared to the year prior.

View Details

The increased proliferation of IoT devices paved the way for the rise of IoT botnets that amplifies DDoS attacks today. This is a dangerous warning that the possibility of a sophisticated DDoS attack and a prolonged service outage will prevent businesses from growing.

View Details

SecuriThings' CEO Roy Dagan tackles the sometimes overlooked security step of physical security maintenance and breaks down why it is important.

View Details

Also known as the Atlantis Cyber-Army, the emerging organization has an enigmatic leader and a core set of admins that offer a range of services, including exclusive data leaks, DDoS and RDP.

View Details

Aamir Lakhani, with FortiGuard Labs, answers the question; Why is the Conti ransomware gang targeting people and businesses in Costa Rica?

View Details

300 restaurants and at least 50,000 payment cards compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services.

View Details

Four newly discovered attack paths could lead to PII exposure, account takeover, even organizational data destruction.

View Details

Threat actors offer victims what appear to be investment services from legitimate companies to lure them into downloading malicious apps aimed at defrauding them.

View Details

Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.

View Details

Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.

View Details

Microsoft has linked a threat that emerged in June 2021 and targets small-to-mid-sized businesses to state-sponsored actors tracked as DEV-0530.

View Details

Since 2021, various state-aligned threat groups have turned up their targeting of journalists to siphon data and credentials and also track them.

View Details

Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.

View Details

Chris Hallenbeck, CISO for the Americas at Tanium, discusses the impact of geopolitical conflict on the cybersecurity insurance market.

View Details

Victims instructed to make a phone call that will direct them to a link for downloading malware.

View Details

Find out why a vital component of vulnerability management needs to be the capacity to prioritize from Mariano Nunez, CEO of Onapsis and Threatpost Infosec Insiders columnist.

View Details

In March, a North Korean APT siphoned blockchain gaming platform Axie Infinity of $540M.

View Details

The novel threat steals data and can affect all processes running on the OS, stealing information from different commands and utilities and then storing it on the affected machine.

View Details

State-sponsored actors are deploying the unique malware--which targets specific files and leaves no ransomware note--in ongoing attacks.

View Details

A radio control system for drones is vulnerable to remote takeover, thanks to a weakness in the mechanism that binds transmitter and receiver.

View Details

A developer appears to have divulged credentials to a police database on a popular developer forum, leading to a breach and subsequent bid to sell 23 terabytes of personal data on the dark web.

View Details

Iran's steel manufacturing industry is victim to ongoing cyberattacks that previously impacted the country's rail system.

View Details

The heap buffer overflow issue in the browser’s WebRTC engine could allow attackers to execute arbitrary code.

View Details

Devices from Cisco, Netgear and others at risk from the multi-stage malware, which has been active since April 2020 and shows the work of a sophisticated threat actor.

View Details

Oliver Tavakoli, CTO at Vectra AI, gives us hope that surviving a ransomware attack is possible, so long as we apply preparation and intentionality to our defense posture.

View Details

Hackers with Amazon users’ authentication tokens could’ve stolen or encrypted personal photos and documents.

View Details

Attacks against U.S. companies spike in Q1 2022 with patchable and preventable external vulnerabilities responsible for bulk of attacks.

View Details

Shrav Mehta, CEO, Secureframe, outlines the top six bad habits security teams need to break to prevent costly breaches, ransomware attacks and prevent phishing-based endpoint attacks.

View Details

Researchers warn threat actors are using a novel remote code execution exploit to gain initial access to victim’s environments.

View Details

Cyber collective Killnet claims it won’t let up until the Baltic country opens trade routes to and from the Russian exclave of Kaliningrad.

View Details

CISA warns that threat actors are ramping up attacks against unpatched Log4Shell vulnerability in VMware servers.

View Details

The company is warning victims in Italy and Kazakhstan that they have been targeted by the malware from Italian firm RCS Labs.

View Details

The APT is pairing a known Microsoft flaw with a malicious document to load malware that nabs credentials from Chrome, Firefox and Edge browsers.

View Details

Joseph Carson, Chief Security Scientist and Advisory CISO at Delinea, explores why gamified platforms and hacking esports are the future.

View Details

Culture of ‘insecure-by-design’ security is cited in discovery of bug-riddled operational technology devices.

View Details

The threat actor targets institutions and companies in Europe and Asia.

View Details

Traditional vulnerability management programs are outdated, with little to no innovation in the last two decades. Today's dynamic IT environment demands an advanced vulnerability management program to deal with the complex attack surface and curb security risks.

View Details

Researchers have discovered that a Kazakhstan government entity deployed sophisticated Italian spyware within its borders.

View Details

A reported a "potentially dangerous piece of functionality" allows an attacker to launch an attack on cloud infrastructure and ransom files stored in SharePoint and OneDrive.

View Details

Attackers are targeting a number of key vertical markets in the U.S. with the active campaign, which impersonates the organization and Microsoft to lift Office365 and Outlook log-in details.

View Details

Evidence suggests that a just-discovered APT has been active since 2013.

View Details

Analysts have uncovered an Iran-linked APT sending malicious emails to top Israeli government officials.

View Details

Ryan Witt, Proofpoint's Healthcare Cybersecurity Leader, examines the impact of ransomware on patient care.

View Details

One well crafted phishing message sent via Facebook Messenger ensnared 10 million Facebook users and counting.

View Details

In response to a comment about the Prophet Mohammed, a hacktivist group in Malaysia has unleashed a wave of cyber attacks in India.

View Details

Upsurge in the tourism industry after the COVID-19 pandemic grabs the attention of cybercriminals to scam the tourists.

View Details

The dangers to SMBs and businesses of all sizes from cyberattacks are well known. But what’s driving these attacks, and what do cybersecurity stakeholders need to do that they’re not already doing?

View Details

Attackers gained access to private account details through an email compromise incident that occurred in April.

View Details

Symbiote, discovered in November, parasitically infects running processes so it can steal credentials, gain rootlkit functionality and install a backdoor for remote access.

View Details

Researchers demonstrated a possible way to track individuals via Bluetooth signals.

View Details

Environmentalists and policymakers warn water treatment plants are ripe for attack.

View Details

The dangerous malware appears to be well and truly back in action, sporting new variants and security-dodging behaviors in a wave of recent phishing campaigns.

View Details

Sabre and Travelport had to report the weekly activities of former “Cardplanet” cybercriminal Aleksei Burkov for two years, info that eventually led to his arrest and prosecution.

View Details

Rob Gurzeev, CEO and Co-Founder at CyCognito, explores external attack surface soft spots tied to an ever-expanding number of digital assets companies too often struggle to keep track of and manage effectively.

View Details

Ransomware attackers often strike targets twice, regardless of whether the ransom was paid.

View Details

The novel cybercriminal group tapped the ever-evolving info-stealing trojan to move laterally on a network in a recent attack, researchers have found.

View Details

The costs associated with a cyberattack can be significant, especially if a company does not have an Incident Response plan that addresses risk.

View Details

Insider Risk Management requires a different approach than to those from external threats. IRM is unique from other domains of security in that the data sources which serve as inputs are as often people as they are tools. Shifting the analyst‘s mindset when handling risks presented by insiders requires us to move through the stages of inquiry, investigation, and determining outcomes.

View Details

A government-aligned attacker tried using a Microsoft vulnerability to attack U.S. and E.U. government targets.

View Details

The vulnerability remains unpatched on many versions of the collaboration tool and has potential to create a SolarWinds-type scenario.

View Details

Deja-Vu data from this year's DBIR report feels like we are stuck in the movie 'Groundhog Day.'

View Details

The cybercriminal group is distancing itself from its previous branding by shifting tactics and tools once again in an aim to continue to profit from its nefarious activity.

View Details

Melissa Bischoping, security researcher with Tanium and Infosec Insiders columnist, urges firms to consider the upstream and downstream impact of "triple extortion" ransomware attacks.

View Details

Hackers escalate phishing and scamming attacks to exploit popular Discord bot and persuade users to click on the malicious links.

View Details

The info-stealing trojan used SMS messages and lifted contact credentials to spread with unprecedented speed across Android devices globally since December 2020.

View Details

There is no question that the level of threats facing today’s businesses continues to change on a daily basis. So what are the trends that CISOs need to be on the lookout for? For this episode of the Threatpost podcast, I am joined by Derek Manky, Chief Security Strategist & VP Global Threat Intelligence, Fortinet’s […]

View Details

Threat actors already are exploiting vulnerability, dubbed ‘Follina’ and originally identified back in April, to target organizations in Russia and Tibet, researchers said.

View Details

Malware borrows generously from code used by other botnets such as Mirai, Qbot and Zbot.

View Details

The malvertiser’s use of PowerShell could push it beyond its basic capabilities to spread ransomware, spyware or steal data from browser sessions, researchers warn.

View Details

Malware loads itself from remote servers and bypasses Microsoft's Defender AV scanner, according to reports.

View Details

Cisco Talos discovered eight vulnerabilities in the Open Automation Software, two of them critical, that pose risk for critical infrastructure networks.

View Details

Actors claiming to be the defunct ransomware group are targeting one of Akami’s customers with a Layer 7 attack, demanding an extortion payment in Bitcoin.

View Details

A slip-up by a malware author has allowed researchers to taxonomize three ransomware variations going by different names.

View Details

The Google Project Zero researcher found a bug in XML parsing on the Zoom client and server.

View Details

2022’s DBIR also highlighted the far-reaching impact of supply-chain breaches and how organizations and their employees are the reasons why incidents occur.

View Details

Fronton botnet has far more ability than launching DDOS attack, can track social media trends and launch suitable propaganda.

View Details

An account promoting the project—which offers a range of threat activity from info-stealing to crypto-mining to ransomware as individual modules—has more than 500 subscribers.

View Details

Researchers discovered a simple malware builder designed to steal credentials, then pinging them to Discord webhooks.

View Details

Tony Lauro, director of security technology and strategy at Akamai, discusses reducing your company's attack surface and the "blast radius" of a potential attack.

View Details

The stealthy, feature-rich malware has multistage evasion tactics to fly under the radar of security analysis, researchers at Proofpoint have found.

View Details

Dell and HP were among the first to release patches and fixes for the bug.

View Details

A novel form of phishing takes advantage of a disparity between how browsers and email inboxes read web domains.

View Details

Microsoft's May Patch Tuesday roundup also included critical fixes for a number of flaws found in infrastructure present in many enterprise and cloud environments.

View Details

Why a private college that stayed in business for 157 years had to close after the combo of COVID-19 and ransomware proved too much.

View Details

The bug has a severe rating of 9.8, public exploits are released.

View Details

The threat group has leaked data that it claims was stolen in the breach and is promising more government-targeted attacks.

View Details

A state-sponsored threat actor designed a house-of-cards style infection chain to exfiltrate massive troves of highly sensitive data.

View Details

A sophisticated campaign utilizes a novel anti-detection method.

View Details

A flaw in all versions of the popular C standard libraries uClibe and uClibe-ng can allow for DNS poisoning attacks against target devices.

View Details

Popular apps to support people’s psychological and spiritual well-being can harm them by sharing their personal and sensitive data with third parties, among other privacy offenses.

View Details

Aamir Lakhani, global security strategist and researcher at FortiGuard Labs, zeroes in on how adversaries are targeting 'remote everything'.

View Details

A deep dive into securing containerized environments and understanding how they present unique security challenges.

View Details

Exclusive Threatpost research examines organizations’ top cloud security concerns, attitudes towards zero-trust and DevSecOps.

View Details

The threat group known as TA410 that wields the sophisticated FlowCloud RAT actually has three subgroups operating globally, each with their own toolsets and targets.

View Details

GitHub shared the timeline of breaches in April 2022, this timeline encompasses the information related to when a threat actor gained access and stole private repositories belonging to dozens of organizations.

View Details

At least five APTs are believed involved with attacks tied ground campaigns and designed to damage Ukraine's digital infrastructure.

View Details

In the latest software supply-chain attack, the code maintainer added malicious code to the hugely popular node-ipc library to replace files with a heart emoji and a peacenotwar module.

View Details

Five percent of the databases are vulnerable to threat actors: It's a gold mine of exploit opportunity in thousands of mobile apps, researchers say.

View Details

It’s about time, AttackIQ’s Jonathan Reiber said about 24H/72H report deadlines mandated in the new spending bill. As it is, visibility into adversary behavior has been muck.

View Details

Scammers are bypassing Apple's App Store security, stealing thousands of dollars’ worth of cryptocurrency from the unwitting, using the TestFlight and WebClips programs.

View Details

CaddyWiper is one in a barrage of data-wiping cyber-attacks to hit the country since January as the war on the ground with Russia marches on.

View Details

The phishing scam tried to steal login credentials by threatening account shutdown, due to users having purportedly shared “fake content.”

View Details

DDoS attacks against Israel telecom companies took down government sites, sparking a temporary state of emergency.

View Details

There are currently no mitigations for the severe Linux kernel bug, QNAP warned on Monday.

View Details

Denso confirmed that cybercriminals leaked stolen, classified information from the Japan-based car-components manufacturer after an attack on one of its offices in Germany.

View Details

The ransomware group’s benefits – bonuses, employee of the month, performance reviews & top-notch training – might be better than yours, says BreachQuest’s Marco Figueroa.

View Details

The infamous trojan is likely making some major operational changes, researchers believe.

View Details

The ransomware gang known as Cuba is increasingly shifting to exploiting Exchange bugs – including crooks' favorites, ProxyShell and ProxyLogon – as initial infection vectors.

View Details

Ransomware is getting worse, but Daniel Spicer, chief security officer at Ivanti, offers a checklist for choosing defense solutions to meet the challenge.

View Details

The options reportedly included tampering with trains, electric service and internet connectivity, hampering Russia's military operations in Ukraine.

View Details

Sonya Duffin, ransomware and data-protection expert at Veritas Technologies, shares three steps organizations can take today to reduce cyberattack fallout.

View Details

A pair of bugs in the Snap-owned tracking app reveal phone numbers and allow account hijacking.

View Details

The SEO poisoning bot, capable of full system takeover, is actively taking over social media accounts, masquerading as popular games like Temple Run.

View Details

Demand for public Wi-Fi is on the rise. Usually free of charge, but there is a risk of expensive losses. Learn ways to protect yourself from cyber-threats.

View Details

A targeted phishing attack takes aim at a major U.S. payments company.

View Details

With human error being the common factor in most cyberattacks, employee training has got to get better. To that end, Trustwave cybersec training expert Darren Van Booven explains the importance of fish stress balls and management buy-in.