The pentester's Swiss knife

LummaC2

Passwords Obsolete? Hackers Target Your Web Sessions

CyberArk specialists report that malefactors are mastering new methodologies to access users’ data without the necessity for passwords or multifactor authentication requests. A prevalent technique involves intercepting web sessions through the theft of cookie...

CVE-2023-4911

Microsoft SharePoint Under Attack: CISA Issues Alert

The Cybersecurity and Infrastructure Security Agency (CISA) has expressed concern over the active exploitation of a vulnerability within the Microsoft SharePoint system, which allows malefactors to launch attacks via remote code execution (RCE). The...

malicious LumiApps SDK

28 Android VPNs Found to be Secret Proxies

Twenty-eight free VPN applications on Google Play were found to employ a malicious SDK, transforming Android devices into residential proxies, likely utilized for cybercrimes and bot operations. The team at HUMAN discovered that these...

Xbox Game Pass keyboard

Xbox Game Pass: Keyboard & Mouse Support Arrives in Testing

Following previous indications that cloud streaming games included in the Xbox Game Pass subscription service would receive updates to support keyboard and mouse inputs, Microsoft has finally commenced testing this feature within the Alpha...

APT41 hacker

UK and US Accuse China of Election Hacking

On March 25th, the United Kingdom and the United States formally accused China of cyberattacks on democratic institutions, linking Chinese intelligence services to incidents at the Electoral Commission in 2021 and attempting to hack...

Windows ARM Chrome

Say Goodbye to Lag: Chrome Update Tailored for Snapdragon

Google and Qualcomm have announced the introduction of a Chrome browser optimized for Arm architecture Windows PCs equipped with Snapdragon processors, promising an enhanced browsing experience. This refinement is set to elevate the user...

MuddyWater

MuddyWater Phishing: Atera Used to Spy on Israel

The cybersecurity firm Proofpoint has uncovered a new phishing campaign orchestrated by the Iranian faction MuddyWater. This operation disseminates legitimate remote monitoring and management software, Atera, among Israeli organizations within the global manufacturing, technology,...