sans

Be Careful With Fake Zoom Client Downloads

A new phishing campaign is targeting remote workers by impersonating Zoom update notifications. The campaign exploits users' urgency to stay updated with the latest software versions, a common requirement for remote collaboration tools.

Increased Botnet Activity Against Apache OFBiz Exploiting CVE-2024-32113

The open-source ERP framework OFBiz is being targeted by the Mirai botnet due to a critical directory traversal vulnerability that allows for remote command execution. This vulnerability was patched in May for versions before 18.12.13.

Persistent Magento Backdoor Hidden in XML

Attackers are using a new method for malware persistence on Magento servers. Sansec discovered a cleverly crafted layout template in the database, which was used to automatically inject malware.

Malicious PowerShell Targeting Cryptocurrency Browser Extensions

Researchers found a malicious PowerShell script targeting browser extensions related to cryptocurrency apps like Coinbase, Binance, Exodus, Atomic, Electrum, Ledger, Jaxx, Guarda, Armory, Trezor, and others.

McAfee Phishing Campaign with a Nice Fake Scan

Researchers found a phishing campaign that abuses the McAfee antivirus to scare people. It starts with a classic email that notifies the targeted user that a McAfee subscription expired.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags