Category: Information Security

Inception Attack

Meta Quest VR Hack: “Inception Attack” Exposed

A new study by the University of Chicago has uncovered a vulnerability within the Meta Quest VR system that allows malefactors to hijack user devices, pilfer confidential information, and manipulate social interactions using generative...

Kansas State University cyberattack

BianLian Exploits TeamCity Flaws for Ransomware

GuidePoint Security, a cybersecurity firm, has uncovered that the BianLian group is exploiting vulnerabilities in the JetBrains TeamCity software to carry out ransomware attacks. Experts have documented a sequence of attacks initiated through the...

CVE-2024-1220

Moxa NPort Bug: Remote Code Execution Possible

Moxa expressed its gratitude to the experts at Positive Technologies for identifying a dangerous vulnerability in the NPort series of wireless industrial converters. Classified as CVE-2024-1220, this vulnerability was rated as high risk with...

CVE-2024-21762

150,000 Devices at Risk: Fortinet Bug Exploited

A critical vulnerability in Fortinet’s security systems has impacted approximately 150,000 devices worldwide. The vulnerability, CVE-2024-21762 (CVSS score: 9.8), is characterized as an out-of-bounds write issue in FortiOS, enabling an unauthenticated attacker to execute...

TA4903

Fake Government Emails: TA4903 Targets Businesses

A report by the leading company Proofpoint has unveiled a sophisticated cyber fraud scheme orchestrated by the hacker group TA4903. This gang specializes in Business Email Compromise (BEC) attacks and has, over the past...

Snake Python infostealer

Beware! Snake Infostealer Targets Facebook Users

Cybereason has identified a new malware variant named Snake, which proliferates through Facebook messages. This Python-written infostealer is designed to pilfer confidential user data. The stolen data are transmitted across various platforms, including Discord,...

ICS Attack Framework “TRITON”

FINTRAC Shuts Down Systems After Cyberattack

The Canadian Financial Transactions and Reports Analysis Centre (FINTRAC) announced the shutdown of its corporate systems due to a cybersecurity incident. Details of the incident remain undisclosed; however, it is known that FINTRAC is...

Stormous Ransomware

GhostLocker & Stormous: Ransomware Duo Wreaks Havoc

The international cybercriminal syndicate GhostSec, implicated in the creation and dissemination of ransomware named GhostLocker, is rapidly expanding the scope of its malevolent operations, encroaching upon an increasing number of countries. According to a...

CVE-2024-21410

Warning: Lotus Bane Cyberattack Breaches Vietnam

A financial institution in Vietnam became the target of a previously unknown hacking collective, dubbed Lotus Bane. This group was identified by cybersecurity experts in March 2023, though it is believed to have been...

CHAVECLOAK banking trojan

Urgent: Contract Scam Spreads CHAVECLOAK Banking Trojan

Specialists at FortiGuard Labs have uncovered a new threat to the financial sector in South America, specifically targeting Brazilian residents for bank credential theft. The banking trojan, dubbed CHAVECLOAK, is spread via an infected...

Network tunneling QEMU

Cyberattack Uncovered: Network Tunneling with QEMU

In a sophisticated cyberattack targeting a major corporation, malefactors employed the open-source QEMU hypervisor platform as a tool for creating a network tunnel. QEMU, a free emulator and hypervisor, facilitates the operation of various...

Project Titan discontinued

Apple Fixes Zero-Day Flaws Exploited by Hackers

Apple has issued critical security updates to address two zero-day vulnerabilities in iOS, which have been exploited in real-world attacks against iPhone users. The company disclosed this information on March 5th in a separate...