Malware - Security Boulevard https://securityboulevard.com/category/blogs/malware/ The Home of the Security Bloggers Network Fri, 29 Mar 2024 18:55:00 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Malware - Security Boulevard https://securityboulevard.com/category/blogs/malware/ 32 32 133346385 ‘Darcula’ PhaaS Campaign Sinks Fangs into Victims https://securityboulevard.com/2024/03/darcula-phaas-campaign-sinks-fangs-into-victims/ Fri, 29 Mar 2024 18:55:00 +0000 https://securityboulevard.com/?p=2013455 phishing cybersecurity

A sprawling phishing-as-a-service (PhaaS) campaign that has been running since at least last summer is using more than 20,000 fake domains to target a wide range of organizations in more than 100 countries, illustrating the capabilities of an increasingly popular tool among threat actors. The unknown hackers are using a platform called “Darcula” (sic) that..

The post ‘Darcula’ PhaaS Campaign Sinks Fangs into Victims appeared first on Security Boulevard.

]]>
2013455
PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/ Fri, 29 Mar 2024 17:19:26 +0000 https://securityboulevard.com/?p=2013426 Closeup of person going “Shhh!”

Emergency stop button: The Python Package Index was drowning in malicious code again, so they had to shut down registration for cleanup.

The post PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found appeared first on Security Boulevard.

]]>
2013426
Industrial Enterprise Operational Technology Under Threat From Cyberattacks https://securityboulevard.com/2024/03/industrial-enterprise-operational-technology-under-threat-from-cyberattacks/ Fri, 29 Mar 2024 12:00:18 +0000 https://securityboulevard.com/?p=2013254 operational supply chain ICS cybersecurity critical infrastructure environment climate

One in four industrial enterprises had to temporarily cease operations due to cyberattacks within the past year, suggesting operational technology must improve.

The post Industrial Enterprise Operational Technology Under Threat From Cyberattacks appeared first on Security Boulevard.

]]>
2013254
What is Threat Management? https://securityboulevard.com/2024/03/what-is-threat-management/ https://securityboulevard.com/2024/03/what-is-threat-management/#respond Thu, 28 Mar 2024 22:01:48 +0000 https://www.seceon.com/?p=17106 What is Threat ManagementThreat management is a process that is used by cybersecurity analysts, incident responders and threat hunters to prevent cyberattacks, detect cyberthreats and respond to security incidents.

The post What is Threat Management? appeared first on Seceon.

The post What is Threat Management? appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/what-is-threat-management/feed/ 0 2013375
Google: Zero-Day Attacks Rise, Spyware and China are Dangers https://securityboulevard.com/2024/03/google-zero-day-attacks-rise-spyware-and-china-are-dangers/ Thu, 28 Mar 2024 16:57:17 +0000 https://securityboulevard.com/?p=2013310 vulnerability zero day

The number of zero-day vulnerabilities that are exploited jumped in 2023, with enterprises becoming a larger target and spyware vendors and China-backed cyberespionage groups playing an increasingly bigger role, according to Google cybersecurity experts. In a report this week, researchers with Google’s Threat Analysis Group (TAG) and its Mandiant business said they saw 97 zero-day..

The post Google: Zero-Day Attacks Rise, Spyware and China are Dangers appeared first on Security Boulevard.

]]>
2013310
Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data https://securityboulevard.com/2024/03/ghostbusters-facebook-theft-snapchat-richixbw/ Wed, 27 Mar 2024 17:14:37 +0000 https://securityboulevard.com/?p=2013174 Smokey Bear / This-is-fine crossover

Meta MITM IAAP SSL bump: Zuck ordered “Project Ghostbusters”—with criminal consequences, says class action lawsuit.

The post Revealed: Facebook’s “Incredibly Aggressive” Alleged Theft of Snapchat App Data appeared first on Security Boulevard.

]]>
2013174
Beneath the Shadows: DarkGate https://securityboulevard.com/2024/03/beneath-the-shadows-darkgate/ https://securityboulevard.com/2024/03/beneath-the-shadows-darkgate/#respond Wed, 27 Mar 2024 12:49:44 +0000 https://www.attackiq.com/?p=22012 Join us as we uncover DarkGate, a malevolent force that strikes fear into the hearts of organizations worldwide. DarkGate has morphed into a sophisticated adversary, utilizing Drive-by Downloads and DanaBot deployment to wreak havoc. But fear not! With AttackIQ Flex at your side, you'll be equipped to wage war against these digital demons and emerge victorious in the fight for cybersecurity supremacy.

The post Beneath the Shadows: DarkGate appeared first on AttackIQ.

The post Beneath the Shadows: DarkGate appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/beneath-the-shadows-darkgate/feed/ 0 2013145
DarkGate Malware Campaign Exploits Patched Microsoft Flaw https://securityboulevard.com/2024/03/darkgate-malware-campaign-exploits-patched-microsoft-flaw/ https://securityboulevard.com/2024/03/darkgate-malware-campaign-exploits-patched-microsoft-flaw/#respond Wed, 27 Mar 2024 07:00:17 +0000 https://tuxcare.com/?p=16740 The Zero Day Initiative (ZDI) by Trend Micro uncovered a phishing campaign that exploited a patched Microsoft flaw to infect devices with DarkGate malware. CVE-2024-21412 was the Microsoft patch that was exploited by using fake software installers. PDFs containing Google DoubleClick Digital Marketing (DDM) open redirects were used to lure users to download the malicious […]

The post DarkGate Malware Campaign Exploits Patched Microsoft Flaw appeared first on TuxCare.

The post DarkGate Malware Campaign Exploits Patched Microsoft Flaw appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/03/darkgate-malware-campaign-exploits-patched-microsoft-flaw/feed/ 0 2013143
Complex Supply Chain Attack Targets GitHub Developers https://securityboulevard.com/2024/03/complex-supply-chain-attack-targets-github-developers/ Tue, 26 Mar 2024 18:42:46 +0000 https://securityboulevard.com/?p=2013043 supply chain, SBOM, cybersecurity, SLSA organizations third party attacks supply chain supply chain ransomware The Kill Chain Model

Unidentified threat actors used multiple tactics to launch a sophisticated software supply-chain campaign targeting developers on the GitHub platform, including members of the popular Top.gg community that includes more than 170,000 members. The attackers used a range of tactics and techniques, from leveraging stolen browser cookies to take over accounts to contributing malicious code with..

The post Complex Supply Chain Attack Targets GitHub Developers appeared first on Security Boulevard.

]]>
2013043
US, UK Accuse China of Years-Long Cyberespionage Campaign https://securityboulevard.com/2024/03/us-uk-accuse-china-of-years-long-cyberespionage-campaign/ Tue, 26 Mar 2024 14:22:21 +0000 https://securityboulevard.com/?p=2012992 China cyberespionage

The United States, the UK, and other countries this week accused a state-sponsored Chinese threat group of running a massive global hacking campaign for more than a decade that targeted political figures, journalists, businesses, political dissidents, and elections officials to steal information and spy on targets. U.S. Attorney Breon Peace called the work of the..

The post US, UK Accuse China of Years-Long Cyberespionage Campaign appeared first on Security Boulevard.

]]>
2012992