ToddyCat’s new tricks: email hacking evolves with the cloud
The age-old adage “if it ain’t broke, don’t fix it” doesn’t always hold true in cybersecurity. As attackers are increasingly leveraging cloud services to protect sensitive data, their...
Akira: a CAPTCHA breach unravels enterprise security
The recent escalation of attacks attributed to the Howling Scorpius ransomware group has highlighted a chillingly simple, yet devastatingly effective, entry vector. While often touted as the vanguard...
WhatsApp’s silent threat: the screen-sharing scams
The current wave of WhatsApp scams, fueled by the platform’s recently introduced screen-sharing feature, is a prime example. It’s a chilling demonstration of how a seemingly innocuous feature...
Trojanized KeePass campaign: novel loader and credential theft in ransomware operations
A recent investigation by WithSecure’s Threat Intelligence team has uncovered a sophisticated malware campaign leveraging a trojanized version of the open-source password manager KeePass. This operation, active for...
Lazarus group’s Billion-Dollar Bybit heist: a cyber forensics analysis
The Lazarus Group, a notorious North Korean state-sponsored hacking collective, has once again demonstrated its sophistication and audacity with a staggering $1.5 billion cryptocurrency heist targeting Bybit, a...
RedMike (Salt Typhoon) continues global Telecom attacks
Despite widespread awareness and U.S. sanctions, the Chinese state-sponsored threat group RedMike (also known as Salt Typhoon) remains a persistent danger to telecommunications providers worldwide. Recent activity reveals...
November 2024 APT attack trends in South Korea
In November 2024, South Korea faced a surge in Advanced Persistent Threats (APTs), with spear phishing being the most prevalent attack vector. This report by AhnLab highlights key...
TeamTNT resurfaces: cybersecurity experts warn of new cloud server attacks
The notorious hacking group TeamTNT has returned with a new campaign targeting Virtual Private Server (VPS) infrastructures running on the CentOS operating system. This attack highlights the escalating...