Malicious NPM packages targeting PayPal users: a recap analysis
FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages, created between March 5 and March 14, were...
Everest ransomware gang faces unprecedented blow: leak site hacked and defaced
In a surprising turn of events, the Everest ransomware gang—a notorious Russia-linked cybercriminal organization—has suffered a significant setback. Over the weekend, their dark web leak site was hacked...
Crocodilus: a sophisticated new Android banking trojan emerges
A new Android banking trojan, dubbed Crocodilus, has been discovered targeting users primarily in Spain and Turkey. This malware isn’t just another clone; it’s a fully-fledged threat employing...
Stealth malware strikes WordPress via MU-Plugins: a technical deep dive
The Sucuri research team has recently uncovered a concerning trend: threat actors are increasingly leveraging the WordPress mu-plugins directory to conceal malicious code. This tactic1 is particularly insidious...
New breed of Android malware leverages .NET MAUI to slip past defenses
Exploiting cross-platform development frameworks to deliver insidious malware. A recent report from McAfee highlights the emergence of Android malware campaigns that are leveraging the .NET MAUI framework to...
Western Alliance Bank data breach: 21,899 customers impacted
The recent data breach at Western Alliance Bank underscores a growing concern in the cybersecurity landscape: the risks posed by third-party software vulnerabilities. This incident not only highlights...
New Android spyware “KoSpy” linked to North Korean APT37
A new Android spyware, dubbed “KoSpy,” has been discovered by researchers at Lookout, adding another concerning tool to the arsenal of North Korean threat actors. This spyware, attributed...
Akira ransomware’s ingenious IoT gambit: when webcams become cyberweapons
Akira group demonstrated how unsecured IoT devices can bypass enterprise-grade defenses. In a case analyzed by S-RM, attackers weaponized a vulnerable webcam to execute an end-run around EDR...