Wiz

Unpacking the Diicot Malware Targeting Linux Environments

The Diicot threat group (also known as Mexals) is known for targeting Linux systems using techniques like self-propagating tools, custom UPX packers, Internet scanning, and cryptomining malware like XMRig.

Exploring Spring Boot Actuator Misconfigurations

Researchers at Wiz examined the risks linked to misconfigurations in Spring Boot Actuator’s endpoints that can expose sensitive information like environment variables, passwords, and API keys, potentially allowing for remote code execution.
November 11, 2024

Scattered Spider Spins a New Web: Detecting 0ktapus Phishing Domains

According to researchers, 0ktapus creates phishing landing pages mimicking legitimate login sites to steal credentials, which are then used for gaining unauthorized access, deploying ransomware, and extortion.

SeleniumGreed Cryptomining Campaign Exploiting Publicly Exposed Grid Services

Researchers at Wiz have identified an ongoing campaign targeting exposed Selenium Grid services for illicit cryptocurrency mining. The campaign, known as SeleniumGreed, is exploiting older versions of Selenium to run a modified XMRig miner.

DERO Cryptojacking Campaign Adopts New Techniques to Evade Detection

Cybersecurity researchers have warned of an ongoing cryptojacking campaign targeting misconfigured Kubernetes clusters to mine Dero cryptocurrency. The campaign is an updated variant of a financially motivated operation first reported in March 2023.

Sensitive Information From Over 80 US Municipalities Left Vulnerable in Massive Data Breach at PeopleGIS

WizCase’s team of ethical hackers, led by Ata Hakç?l, has found a major breach exposing a number of US cities, all of them using the same web service provider aimed at municipalities.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags