Tuesday, February 25, 2025

THREATS

Fortinet FortiOS Flaw Let Attacker Execute Malicious JavaScript Code

Fortinet FortiOS has been discovered with Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities, which threat actors can use for malicious purposes.These vulnerabilities...

Pro-Russian Actors Initiated A DDoS Attack Against Canadian Organizations

The Canadian government, banking, and transportation industries have recently been the targets of many distributed denial of service (DDoS) attacks.This criminal activity is linked...

3AM Ransomware Attack – Stop Services & Delete Shadow Copies Before Encrypting

Ransomware is a universal threat to enterprises, targeting anyone handling sensitive data when profit potential is high.A new ransomware named 3AM has surfaced and...

Microsoft Teams as a Tool for Storm-0324 Threat Group to Hack Corporate Networks

According to recent reports, a threat actor known as Storm-0324 has been using email-based initial infection vectors to attack organizations.However, as of July...

Weaponized Free Download Manager for Linux Steals System Data & Passwords 

In recent years, Linux systems gained prominence among diverse threat actors, with more than 260,000 unique samples emerging in H1 2023.In the case of...

Chinese Redfly Hacked National Power Grid & Maintained Access for 6 Months

Cybersecurity researchers at Symantec's Threat Hunter Team recently discovered that the Redfly threat actor group used ShadowPad Trojan to breach an Asian national grid...

New Sponsor Malware Attacking Government & Healthcare Organizations

The Ballistic Bobcat is an Iran-aligned APT group, and initially, about two years ago, cybersecurity researchers at ESET tracked this threat group. Here below,...

Chinese Hack of Microsoft Consumer Key Stemmed From its Engineer’s Corporate Account

Storm-0558, a threat actor based in China, has recently gained access to a Microsoft account consumer key. This has allowed them to infiltrate and...