Infosecurity News

Russian APT Intensifies Cyber Espionage Activities Amid Ukrainian Counter-Offensive
The Gamaredon group has ramped up attacks against Ukrainian military entities, with the aim of hindering Ukraine’s counter-offensive operations

Classiscam Spreads: $64.5M Scheme Targets 79 Countries
Group-IB’s analysis showed that between H1 2021 and H1 2023, 251 brands were targeted by Classiscam

Flaw Exposes WP Migration Plugin to Hacks
The vulnerable code was identified by the security research team at PatchStack

Chinese APT Group GREF Use BadBazaar in Android Espionage
ESET said BadBazaar was available via the Google Play Store, Samsung Galaxy Store and various app sites

Chinese Hackers Target US, Other Govts With Barracuda Flaw
The campaign deployed many malware families, including Skipjack, DepthCharge, Foxglove and Foxtrot

FBI-Led Operation Duck Hunt Shuts Down QakBot Malware
With Operation Duck Hunt, the FBI took control of the botnet, allowed victims to uninstall the malware loader and seized $8.6m in cryptocurrency

OpenAI Promises Enterprise-Grade Security with ChatGPT for Business
OpenAI has launched ChatGPT Enterprise highlighting high-profile customers including Klarna, PwC and The Estee Lauder Companies

NCSC Issues Cyber Warning Over AI Chatbots
The UK cyber agency highlights the lack of understanding of LLMs among industry and academia

LockBit 3.0 Ransomware Variants Surge Post Builder Leak
Kaspersky explained that LockBit 3.0, also known as LockBit Black, first emerged in June 2022

New Ransomware Campaign Targets Citrix NetScaler Flaw
Sophos X-Ops suspects the involvement of a well-known ransomware threat actor known as STAC4663

Report Reveals Growing Disparity in Cyber Insurance Landscape
Delinea’s report shows gap grows as firms struggle for cyber insurance, longer policy wait times

Microsoft Warns of Adversary-in-the-Middle Uptick on Phishing Platforms
Existing phishing-as-a-service platforms are increasingly incorporating adversary-in-the-middle capabilities

Four in Five Cyber-Attacks Powered by Just Three Malware Loaders
ReliaQuest found that 80% of cyber intrusion campaigns used either QakBot, SocGholish or Raspberry Robin

Privacy Regulator Warns of Surge in “Text Pest” Cases
Nearly one in three young adults has had their personal information misused

Researchers Discover Reply URL Takeover Issue in Azure
Vulnerability could be exploited to gain elevated privileges

FBI: Barracuda Appliances Still Being Exploited By China
Feds warn that patching will not rid system of APT group

Lazarus Group Targets Internet Infrastructure and Healthcare with 'QuiteRAT' Malware
QuiteRAT, the North-Korea-Backed group’s new malware, exploits a 2022 ManageEngine ServiceDesk vulnerability

Creative QakBot Attack Tactics Challenge Security Defenses
Threat actors use unique infection chains to deploy QakBot malware

FBI Flags $40M Crypto Cash-Out Plot By North Korean Hackers
Between Monday and Tuesday, the FBI has traced approximately 1580 stolen Bitcoins

Data of 2.6 Million Duolingo Users Leaked on Hacking Forum
The compromised data includes names, usernames, email addresses and internal service-related details



