Stealth malware strikes WordPress via MU-Plugins: a technical deep dive
The Sucuri research team has recently uncovered a concerning trend: threat actors are increasingly leveraging the WordPress mu-plugins directory to conceal malicious code. This tactic1 is particularly insidious...
New breed of Android malware leverages .NET MAUI to slip past defenses
Exploiting cross-platform development frameworks to deliver insidious malware. A recent report from McAfee highlights the emergence of Android malware campaigns that are leveraging the .NET MAUI framework to...
Mamona ransomware group compromised: DragonForce exploits OPSEC failures
The cybersecurity landscape is once again witnessing the fallout of poor operational security (OPSEC) among ransomware operators. In the latest turn of events, Mamona, a ransomware group rebranded...
Western Alliance Bank data breach: 21,899 customers impacted
The recent data breach at Western Alliance Bank underscores a growing concern in the cybersecurity landscape: the risks posed by third-party software vulnerabilities. This incident not only highlights...
MassJacker malware targets cryptocurrency of piracy users
A new and sophisticated malware campaign, known as MassJacker, has been uncovered by cybersecurity researchers at CyberArk. This malware targets users who download pirated software, particularly from websites...
New Android spyware “KoSpy” linked to North Korean APT37
A new Android spyware, dubbed “KoSpy,” has been discovered by researchers at Lookout, adding another concerning tool to the arsenal of North Korean threat actors. This spyware, attributed...
The Ballista Botnet: a new IoT threat with italian roots
Cato Networks has uncovered a sophisticated IoT botnet, dubbed Ballista, targeting TP-Link Archer routers by exploiting a two-year-old vulnerability (CVE-2023-1389). This threat, linked to an Italian threat actor,...
Akira ransomware’s ingenious IoT gambit: when webcams become cyberweapons
Akira group demonstrated how unsecured IoT devices can bypass enterprise-grade defenses. In a case analyzed by S-RM, attackers weaponized a vulnerable webcam to execute an end-run around EDR...