✨ General Cyber News ✨
🏴☠️ Securotrop has just published a new victim : Pocatello Ready Mix
—
Summary:
Status: AWAITING
Size: 274 GB
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 09:16
#just #general_cyber_news #securotrop
https://www.ransomware.live/id/UG9jYXRlbGxvIFJlYWR5IE1peEBzZWN1cm90cm9w
🏴☠️ Securotrop has just published a new victim : Pocatello Ready Mix
—
Summary:
Status: AWAITING
Size: 274 GB
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 09:16
#just #general_cyber_news #securotrop
https://www.ransomware.live/id/UG9jYXRlbGxvIFJlYWR5IE1peEBzZWN1cm90cm9w
Ransomware.live
Victim: Pocatello Ready Mix – securotrop
Ransomware.live discovered on 2025-11-08 that Pocatello Ready Mix has been claimed by Securotrop ransomware group
✨ General Cyber News ✨
🏴☠️ Qilin has just published a new victim : Advanced Delivery Services
—
Summary:
N/A
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 08:49
#just #general_cyber_news #qilin
https://www.ransomware.live/id/QWR2YW5jZWQgRGVsaXZlcnkgU2VydmljZXNAcWlsaW4=
🏴☠️ Qilin has just published a new victim : Advanced Delivery Services
—
Summary:
N/A
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 08:49
#just #general_cyber_news #qilin
https://www.ransomware.live/id/QWR2YW5jZWQgRGVsaXZlcnkgU2VydmljZXNAcWlsaW4=
Ransomware.live
Victim: Advanced Delivery Services – qilin
Ransomware.live discovered on 2025-11-08 that Advanced Delivery Services has been claimed by Qilin ransomware group
✨ General Cyber News ✨
🏴☠️ Qilin has just published a new victim : SHRM New Mexico
—
Summary:
N/A
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 05:51
#just #general_cyber_news #qilin
https://www.ransomware.live/id/U0hSTSBOZXcgTWV4aWNvQHFpbGlu
🏴☠️ Qilin has just published a new victim : SHRM New Mexico
—
Summary:
N/A
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 05:51
#just #general_cyber_news #qilin
https://www.ransomware.live/id/U0hSTSBOZXcgTWV4aWNvQHFpbGlu
Ransomware.live
Victim: SHRM New Mexico – qilin
Ransomware.live discovered on 2025-11-08 that SHRM New Mexico has been claimed by Qilin ransomware group
✨ General Cyber News ✨
🏴☠️ Qilin has just published a new victim : Scouts Canada
—
Summary:
N/A
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 05:50
#just #general_cyber_news #qilin
https://www.ransomware.live/id/U2NvdXRzIENhbmFkYUBxaWxpbg==
🏴☠️ Qilin has just published a new victim : Scouts Canada
—
Summary:
N/A
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 05:50
#just #general_cyber_news #qilin
https://www.ransomware.live/id/U2NvdXRzIENhbmFkYUBxaWxpbg==
Ransomware.live
Victim: Scouts Canada – qilin
Ransomware.live discovered on 2025-11-08 that Scouts Canada has been claimed by Qilin ransomware group
✨ General Cyber News ✨
🏴☠️ Stormous has just published a new victim : !
—
Summary:
VPN access to the company’s internal network is provided
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 01:45
#just #general_cyber_news #stormous
https://www.ransomware.live/id/IUBzdG9ybW91cw==
🏴☠️ Stormous has just published a new victim : !
—
Summary:
VPN access to the company’s internal network is provided
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 01:45
#just #general_cyber_news #stormous
https://www.ransomware.live/id/IUBzdG9ybW91cw==
Ransomware.live
Victim: ! – stormous
Ransomware.live discovered on 2025-11-09 that ! has been claimed by Stormous ransomware group
✨ General Cyber News ✨
🏴☠️ Akira has just published a new victim : Mold In Graphic Systems
—
Summary:
Mold In Graphic Systems specializes in providing permanent labeli
ng solutions for plastic durable goods using their unique Polymer
Fusion Labels.
We will upload 15gb of corporate documents soon. Employee informa
tion (Driver licenses, credit cards scans, medical information an
d so on), projects information, internal confidential files, agre
ements and contracts, NDAs, etc.
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 00:44
#akira #general_cyber_news #just
https://www.ransomware.live/id/TW9sZCBJbiBHcmFwaGljIFN5c3RlbXNAYWtpcmE=
🏴☠️ Akira has just published a new victim : Mold In Graphic Systems
—
Summary:
Mold In Graphic Systems specializes in providing permanent labeli
ng solutions for plastic durable goods using their unique Polymer
Fusion Labels.
We will upload 15gb of corporate documents soon. Employee informa
tion (Driver licenses, credit cards scans, medical information an
d so on), projects information, internal confidential files, agre
ements and contracts, NDAs, etc.
—
Source: Ransomware.live RSS Feed
Published: 2025-11-08 00:44
#akira #general_cyber_news #just
https://www.ransomware.live/id/TW9sZCBJbiBHcmFwaGljIFN5c3RlbXNAYWtpcmE=
Ransomware.live
Victim: Mold In Graphic Systems – akira
Ransomware.live discovered on 2025-11-08 that Mold In Graphic Systems has been claimed by Akira ransomware group
✨ Vulnerabilities & Exploits ✨
🏴☠️ Dragonforce has just published a new victim : GB Mail
—
Summary:
GB Mail is a privately owned and leading mailing house located centrally in the home counties. With a strong ethos of delivering mail with no fuss, on time and in full, the company boasts a dedicated and knowledgeable team passionate about all aspects of print and mail. Their services include storage & fulfilment, postal solutions, print personalisation, database cleansing, international mail, direct mail, and subscription mail.
—
Source: Ransomware.live RSS Feed
Published: 2025-11-07 22:53
#just #dragonforce #vulnerabilities__exploits
https://www.ransomware.live/id/R0IgTWFpbEBkcmFnb25mb3JjZQ==
🏴☠️ Dragonforce has just published a new victim : GB Mail
—
Summary:
GB Mail is a privately owned and leading mailing house located centrally in the home counties. With a strong ethos of delivering mail with no fuss, on time and in full, the company boasts a dedicated and knowledgeable team passionate about all aspects of print and mail. Their services include storage & fulfilment, postal solutions, print personalisation, database cleansing, international mail, direct mail, and subscription mail.
—
Source: Ransomware.live RSS Feed
Published: 2025-11-07 22:53
#just #dragonforce #vulnerabilities__exploits
https://www.ransomware.live/id/R0IgTWFpbEBkcmFnb25mb3JjZQ==
Ransomware.live
Victim: GB Mail – dragonforce
Ransomware.live discovered on 2025-11-07 that GB Mail has been claimed by Dragonforce ransomware group
✨ Vulnerabilities & Exploits ✨
🏴☠️ Dragonforce has just published a new victim : DCS TECHNOLOGIES INC.
—
Summary:
DCS Technology Inc. is providing complete IT Solutions since 2004. They are specialized in Point of Sale systems, Website Designing, Technical Support, and Computer Networking Solutions. With 17 years of experience, DCS serving over 5000 businesses in North America.
—
Source: Ransomware.live RSS Feed
Published: 2025-11-07 21:50
#just #dragonforce #vulnerabilities__exploits
https://www.ransomware.live/id/RENTIFRFQ0hOT0xPR0lFUyBJTkMuQGRyYWdvbmZvcmNl
🏴☠️ Dragonforce has just published a new victim : DCS TECHNOLOGIES INC.
—
Summary:
DCS Technology Inc. is providing complete IT Solutions since 2004. They are specialized in Point of Sale systems, Website Designing, Technical Support, and Computer Networking Solutions. With 17 years of experience, DCS serving over 5000 businesses in North America.
—
Source: Ransomware.live RSS Feed
Published: 2025-11-07 21:50
#just #dragonforce #vulnerabilities__exploits
https://www.ransomware.live/id/RENTIFRFQ0hOT0xPR0lFUyBJTkMuQGRyYWdvbmZvcmNl
Ransomware.live
Victim: DCS TECHNOLOGIES INC. – dragonforce
Ransomware.live discovered on 2025-11-07 that DCS TECHNOLOGIES INC. has been claimed by Dragonforce ransomware group
✨ Malware Analysis ✨
Balancer hack analysis and guidance for the DeFi ecosystem
—
Summary:
TL;DR
The root cause of the hack was a rounding direction issue that had been present in the code for many years.
When the bug was first introduced, the threat landscape of the blockchain ecosystem was significantly different, and arithmetic issues in particular were not widely considered likely vectors for exploitation.
As low-hanging attack paths have become increasingly scarce, attackers have become more sophisticated and will continue to hunt for novel threats, such as arithmetic edge...
—
Source: The Trail of Bits Blog
Published: 2025-11-07 23:00
#malware_analysis #hack #balancer
https://blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/
Balancer hack analysis and guidance for the DeFi ecosystem
—
Summary:
TL;DR
The root cause of the hack was a rounding direction issue that had been present in the code for many years.
When the bug was first introduced, the threat landscape of the blockchain ecosystem was significantly different, and arithmetic issues in particular were not widely considered likely vectors for exploitation.
As low-hanging attack paths have become increasingly scarce, attackers have become more sophisticated and will continue to hunt for novel threats, such as arithmetic edge...
—
Source: The Trail of Bits Blog
Published: 2025-11-07 23:00
#malware_analysis #hack #balancer
https://blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/
The Trail of Bits Blog
Balancer hack analysis and guidance for the DeFi ecosystem
A retrospective on the $100M Balancer hack that occurred in November 2025, including long-term, strategic guidance on how to avoid similar bugs.
✨ General Cyber News ✨
After MD-11 Crash Boeing Tells UPS to Ground Its Planes
—
Summary:
UPS has announced nearly 10% of its airplanes will be grounded, per the recommendation of Boeing. Out of an abundance of caution and in the interest of safety, we have made the decision to temporarily ground our MD-11 fleet. MD-11s are approximately 9% of the UPS Airlines fleet. The grounding is effective immediately. We made … Continue reading After MD-11 Crash Boeing Tells UPS to Ground Its Planes →
—
Source: flyingpenguin
Published: 2025-11-08 10:53 | Author: Davi Ottenheimer
#general_cyber_news #after #md11
https://www.flyingpenguin.com/?p=73949
After MD-11 Crash Boeing Tells UPS to Ground Its Planes
—
Summary:
UPS has announced nearly 10% of its airplanes will be grounded, per the recommendation of Boeing. Out of an abundance of caution and in the interest of safety, we have made the decision to temporarily ground our MD-11 fleet. MD-11s are approximately 9% of the UPS Airlines fleet. The grounding is effective immediately. We made … Continue reading After MD-11 Crash Boeing Tells UPS to Ground Its Planes →
—
Source: flyingpenguin
Published: 2025-11-08 10:53 | Author: Davi Ottenheimer
#general_cyber_news #after #md11
https://www.flyingpenguin.com/?p=73949
✨ General Cyber News ✨
Nick Fuentes: 40% of White House Are Nazis (((America First)))
—
Summary:
First, the infamous hate group leader Fuentes says the Heritage Foundation has mainstreamed his extremism, such that a large percentage of the White House staff have been compromised. He’s saying clearly that “America First” is back in the White House again, which isn’t really news. However, people perhaps are starting to realize or remember why … Continue reading Nick Fuentes: 40% of White House Are Nazis (((America First))) →
—
Source: flyingpenguin
Published: 2025-11-08 01:38 | Author: Davi Ottenheimer
#fuentes #general_cyber_news #nick
https://www.flyingpenguin.com/?p=73924
Nick Fuentes: 40% of White House Are Nazis (((America First)))
—
Summary:
First, the infamous hate group leader Fuentes says the Heritage Foundation has mainstreamed his extremism, such that a large percentage of the White House staff have been compromised. He’s saying clearly that “America First” is back in the White House again, which isn’t really news. However, people perhaps are starting to realize or remember why … Continue reading Nick Fuentes: 40% of White House Are Nazis (((America First))) →
—
Source: flyingpenguin
Published: 2025-11-08 01:38 | Author: Davi Ottenheimer
#fuentes #general_cyber_news #nick
https://www.flyingpenguin.com/?p=73924
✨ Threat Intelligence ✨
AI-Powered Cyber Threats Rise: Attackers Target Manufacturing Sector
—
Summary:
A comprehensive new report reveals that manufacturing organizations are grappling with a dual challenge: rapidly adopting generative AI technologies while simultaneously defending against attackers who exploit these same platforms and trusted cloud services to launch sophisticated attacks. The findings underscore an urgent need for enhanced security controls as the sector balances innovation with data protection. […]
The post AI-Powered Cyber Threats Rise: Attackers Target Manufacturing...
—
Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 06:41 | Author: Mayura Kathir
#threat_intelligence #aipowered #cyber
https://gbhackers.com/ai-powered-cyber-threats/
AI-Powered Cyber Threats Rise: Attackers Target Manufacturing Sector
—
Summary:
A comprehensive new report reveals that manufacturing organizations are grappling with a dual challenge: rapidly adopting generative AI technologies while simultaneously defending against attackers who exploit these same platforms and trusted cloud services to launch sophisticated attacks. The findings underscore an urgent need for enhanced security controls as the sector balances innovation with data protection. […]
The post AI-Powered Cyber Threats Rise: Attackers Target Manufacturing...
—
Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 06:41 | Author: Mayura Kathir
#threat_intelligence #aipowered #cyber
https://gbhackers.com/ai-powered-cyber-threats/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
AI-Powered Cyber Threats Rise: Attackers Target Manufacturing Sector
A comprehensive new report reveals that manufacturing organizations are grappling with a dual challenge: rapidly adopting generative AI technologies.
✨ Vulnerabilities & Exploits ✨
New “LANDFALL” Android Malware Uses Samsung 0-Day Vulnerability Hidden in WhatsApp Images
—
Summary:
Cybersecurity researchers at Unit 42 have uncovered a sophisticated Android spyware campaign that exploited a previously unknown zero-day vulnerability in Samsung Galaxy devices. The malware, dubbed LANDFALL, leveraged a critical vulnerability in Samsung’s image processing library to deliver commercial-grade surveillance capabilities through maliciously crafted image files sent via WhatsApp. The LANDFALL campaign exploited CVE-2025-21042, a […]
The post New “LANDFALL” Android...
—
Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 05:34 | Author: Mayura Kathir
#landfall #vulnerabilities__exploits #android
https://gbhackers.com/samsung-0-day-vulnerability/
New “LANDFALL” Android Malware Uses Samsung 0-Day Vulnerability Hidden in WhatsApp Images
—
Summary:
Cybersecurity researchers at Unit 42 have uncovered a sophisticated Android spyware campaign that exploited a previously unknown zero-day vulnerability in Samsung Galaxy devices. The malware, dubbed LANDFALL, leveraged a critical vulnerability in Samsung’s image processing library to deliver commercial-grade surveillance capabilities through maliciously crafted image files sent via WhatsApp. The LANDFALL campaign exploited CVE-2025-21042, a […]
The post New “LANDFALL” Android...
—
Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 05:34 | Author: Mayura Kathir
#landfall #vulnerabilities__exploits #android
https://gbhackers.com/samsung-0-day-vulnerability/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New “LANDFALL” Android Malware Uses Samsung 0-Day Vulnerability Hidden in WhatsApp Images
Cybersecurity researchers at Unit 42 have uncovered a sophisticated Android spyware campaign that exploited a previously unknown zero-day vulnerability in Samsung Galaxy.
✨ Threat Intelligence ✨
New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks
—
Summary:
Microsoft is poised to roll out a significant update to Teams, enabling users to initiate chats with anyone using just an email address even if the recipient isn’t a Teams user. While the feature, launching in targeted releases by early November 2025 and globally by January 2026, promises expanded connectivity across Android, desktop, iOS, Linux, […]
The post New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks appeared first on GBHackers Security | #1 Globally Trusted...
—
Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 05:00 | Author: Mayura Kathir
#threat_intelligence #microsoft #teams
https://gbhackers.com/microsoft-teams-feature/
New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks
—
Summary:
Microsoft is poised to roll out a significant update to Teams, enabling users to initiate chats with anyone using just an email address even if the recipient isn’t a Teams user. While the feature, launching in targeted releases by early November 2025 and globally by January 2026, promises expanded connectivity across Android, desktop, iOS, Linux, […]
The post New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks appeared first on GBHackers Security | #1 Globally Trusted...
—
Source: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Published: 2025-11-08 05:00 | Author: Mayura Kathir
#threat_intelligence #microsoft #teams
https://gbhackers.com/microsoft-teams-feature/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks
Microsoft is poised to roll out a significant update to Teams, enabling users to initiate chats with anyone using just an email address even if the recipient isn’t a Teams user.
✨ General Cyber News ✨
How FedRAMP Agencies Evaluate CSP SAR Submissions
—
Summary:
FedRAMP is the federal government’s framework for evaluating and enforcing standardized security across the cloud service providers operating as contractors. They take security seriously, and the protection of controlled information is their top priority. A key part of validating the security of a CSP is the SAR, or Security Assessment Report. What is the SAR, […]
—
Source: Ignyte
Published: 2025-11-07 23:07 | Author: Dan Page
#general_cyber_news #agencies #fedramp
https://www.ignyteplatform.com/blog/fedramp/fedramp-csp-sar-submissions/
How FedRAMP Agencies Evaluate CSP SAR Submissions
—
Summary:
FedRAMP is the federal government’s framework for evaluating and enforcing standardized security across the cloud service providers operating as contractors. They take security seriously, and the protection of controlled information is their top priority. A key part of validating the security of a CSP is the SAR, or Security Assessment Report. What is the SAR, […]
—
Source: Ignyte
Published: 2025-11-07 23:07 | Author: Dan Page
#general_cyber_news #agencies #fedramp
https://www.ignyteplatform.com/blog/fedramp/fedramp-csp-sar-submissions/
Ignyte
How FedRAMP Agencies Evaluate CSP SAR Submissions
Learn how FedRAMP agencies evaluate CSP SAR submissions and understand the key steps in the process to ensure security compliance and certification readiness.
✨ General Cyber News ✨
Honeypot: Requests for (Code) Repositories, (Sat, Nov 8th)
—
Summary:
This is just a quick diary entry to report that I saw requests on my honeypot for (code) repositories:
—
Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-11-08 06:09
#general_cyber_news #honeypot #requests
https://isc.sans.edu/diary/rss/32460
Honeypot: Requests for (Code) Repositories, (Sat, Nov 8th)
—
Summary:
This is just a quick diary entry to report that I saw requests on my honeypot for (code) repositories:
—
Source: SANS Internet Storm Center, InfoCON: green
Published: 2025-11-08 06:09
#general_cyber_news #honeypot #requests
https://isc.sans.edu/diary/rss/32460
SANS Internet Storm Center
Honeypot: Requests for (Code) Repositories - SANS ISC
Honeypot: Requests for (Code) Repositories, Author: Didier Stevens
✨ General Cyber News ✨
Критическая уязвимость в популярной библиотеке expr-eval угрожает системам искусственного интеллекта
—
Summary:
В широко используемой JavaScript-библиотеке expr-eval обнаружена критическая уязвимость удаленного выполнения кода (RCE), затрагивающая тысячи проектов в области искусственного интеллекта и обработки естественного языка. Уязвимость, получившая идентификатор CVE-2025-12735, представляет серьезную угрозу для серверных сред и AI-приложений, обрабатывающих пользовательский ввод. Детали уязвимости Эксперты по безопасности особенно обеспокоены масштабами потенциального воздействия, учитывая широкое...
—
Source: SEC-1275-1
Published: 2025-11-10 13:21 | Author: Vulner Queen
#expreval #general_cyber_news
https://1275.ru/vulnerability/kriticheskaya-uyazvimost-v-populyarnoy-biblioteke-expr-eval-ugrozhaet-sistemam-iskusstvennogo-intellekta_16167
Критическая уязвимость в популярной библиотеке expr-eval угрожает системам искусственного интеллекта
—
Summary:
В широко используемой JavaScript-библиотеке expr-eval обнаружена критическая уязвимость удаленного выполнения кода (RCE), затрагивающая тысячи проектов в области искусственного интеллекта и обработки естественного языка. Уязвимость, получившая идентификатор CVE-2025-12735, представляет серьезную угрозу для серверных сред и AI-приложений, обрабатывающих пользовательский ввод. Детали уязвимости Эксперты по безопасности особенно обеспокоены масштабами потенциального воздействия, учитывая широкое...
—
Source: SEC-1275-1
Published: 2025-11-10 13:21 | Author: Vulner Queen
#expreval #general_cyber_news
https://1275.ru/vulnerability/kriticheskaya-uyazvimost-v-populyarnoy-biblioteke-expr-eval-ugrozhaet-sistemam-iskusstvennogo-intellekta_16167
SEC-1275-1
Критическая уязвимость в популярной библиотеке expr-eval угрожает системам искусственного интеллекта
Критическая уязвимость в популярной библиотеке expr-eval угрожает системам искусственного интеллекта - В широко используемой JavaScript-библиотеке expr-eval обнаружена критическая уязвимость удаленного выполнения кода (RCE), затрагивающая тысячи проектов в
✨ General Cyber News ✨
Киберпреступники возродили опасную кампанию Gootloader с новыми методами обхода защиты
—
Summary:
Группа исследователей кибербезопасности из компании Huntress зафиксировала возвращение печально известной кампании Gootloader, которая после временного затишья вновь активизировалась с усовершенствованными методами атак. Об этом первыми сообщил аналитик под псевдонимом RussianPanda, чьи наблюдения позволили раскрыть новые тактики злоумышленников. Gootloader продолжает свою пятилетнюю историю использования юридической тематики в качестве приманки. Злоумышленники создали более 100 веб-сайтов с...
—
Source: SEC-1275-1
Published: 2025-11-10 13:07 | Author: SEC-1275
#gootloader #general_cyber_news
https://1275.ru/ioc/kiberprestupniki-vozrodili-opasnuyu-kampaniyu-gootloader-s-novymi-metodami-obhoda-zaschity_16078
Киберпреступники возродили опасную кампанию Gootloader с новыми методами обхода защиты
—
Summary:
Группа исследователей кибербезопасности из компании Huntress зафиксировала возвращение печально известной кампании Gootloader, которая после временного затишья вновь активизировалась с усовершенствованными методами атак. Об этом первыми сообщил аналитик под псевдонимом RussianPanda, чьи наблюдения позволили раскрыть новые тактики злоумышленников. Gootloader продолжает свою пятилетнюю историю использования юридической тематики в качестве приманки. Злоумышленники создали более 100 веб-сайтов с...
—
Source: SEC-1275-1
Published: 2025-11-10 13:07 | Author: SEC-1275
#gootloader #general_cyber_news
https://1275.ru/ioc/kiberprestupniki-vozrodili-opasnuyu-kampaniyu-gootloader-s-novymi-metodami-obhoda-zaschity_16078
SEC-1275-1
Киберпреступники возродили опасную кампанию Gootloader с новыми методами обхода защиты
Киберпреступники возродили опасную кампанию Gootloader с новыми методами обхода защиты - Группа исследователей кибербезопасности из компании Huntress зафиксировала возвращение печально известной кампании Gootloader, которая после временного
✨ General Cyber News ✨
Группа Dragon Breath атакует игорный бизнес Юго-Восточной Азии
—
Summary:
Китайский центр анализа угроз компании QiAnXin раскрыл детали многолетней хакерской кампании, нацеленной на онлайн-казино и букмекерские компании Юго-Восточной Азии. Группа, отслеживаемая под кодовым названием APT-Q-27 (Advanced Persistent Threat), демонстрирует высочайший уровень технической подготовки и адаптивности, используя сложные схемы проникновения в инфраструктуру игорного бизнеса. Специалисты отмечают, что сфера онлайн-гемблинга стала особенно привлекательной для киберпреступников в...
—
Source: SEC-1275-1
Published: 2025-11-10 12:42 | Author: SEC-1275
#dragon #breath #general_cyber_news
https://1275.ru/ioc/gruppa-dragon-breath-atakuet-igornyy-biznes-yugo-vostochnoy-azii_16077
Группа Dragon Breath атакует игорный бизнес Юго-Восточной Азии
—
Summary:
Китайский центр анализа угроз компании QiAnXin раскрыл детали многолетней хакерской кампании, нацеленной на онлайн-казино и букмекерские компании Юго-Восточной Азии. Группа, отслеживаемая под кодовым названием APT-Q-27 (Advanced Persistent Threat), демонстрирует высочайший уровень технической подготовки и адаптивности, используя сложные схемы проникновения в инфраструктуру игорного бизнеса. Специалисты отмечают, что сфера онлайн-гемблинга стала особенно привлекательной для киберпреступников в...
—
Source: SEC-1275-1
Published: 2025-11-10 12:42 | Author: SEC-1275
#dragon #breath #general_cyber_news
https://1275.ru/ioc/gruppa-dragon-breath-atakuet-igornyy-biznes-yugo-vostochnoy-azii_16077
SEC-1275-1
Группа Dragon Breath атакует игорный бизнес Юго-Восточной Азии
Группа Dragon Breath атакует игорный бизнес Юго-Восточной Азии - Китайский центр анализа угроз компании QiAnXin раскрыл детали многолетней хакерской кампании, нацеленной на онлайн-казино и букмекерские компании
✨ General Cyber News ✨
В Японии обнаружена сеть киберпреступников с использованием Cobalt Strike и других инструментов
—
Summary:
В ходе еженедельного исследования угроз безопасности, проведенного в 43-ю неделю 2025 года, в Японии была выявлена активность семи серверов управления и контроля, известных как C2-инфраструктура. Исследование проводилось с 20 по 26 октября с использованием платформы Censys, специализирующейся на сканировании интернет-активов. Обнаруженные серверы связаны с различными семействами вредоносного программного обеспечения, включая известные инструменты киберпреступников Cobalt Strike,...
—
Source: SEC-1275-1
Published: 2025-11-10 11:00 | Author: SEC-1275
#strike #cobalt #general_cyber_news
https://1275.ru/ioc/v-yaponii-obnaruzhena-set-kiberprestupnikov-s-ispolzovaniem-cobalt-strike-i-drugih-instrumentov_16075
В Японии обнаружена сеть киберпреступников с использованием Cobalt Strike и других инструментов
—
Summary:
В ходе еженедельного исследования угроз безопасности, проведенного в 43-ю неделю 2025 года, в Японии была выявлена активность семи серверов управления и контроля, известных как C2-инфраструктура. Исследование проводилось с 20 по 26 октября с использованием платформы Censys, специализирующейся на сканировании интернет-активов. Обнаруженные серверы связаны с различными семействами вредоносного программного обеспечения, включая известные инструменты киберпреступников Cobalt Strike,...
—
Source: SEC-1275-1
Published: 2025-11-10 11:00 | Author: SEC-1275
#strike #cobalt #general_cyber_news
https://1275.ru/ioc/v-yaponii-obnaruzhena-set-kiberprestupnikov-s-ispolzovaniem-cobalt-strike-i-drugih-instrumentov_16075
SEC-1275-1
В Японии обнаружена сеть киберпреступников с использованием Cobalt Strike и других инструментов
В Японии обнаружена сеть киберпреступников с использованием Cobalt Strike и других инструментов - В ходе еженедельного исследования угроз безопасности, проведенного в 43-ю неделю 2025 года, в Японии была выявлена активность семи серверов управления и
✨ General Cyber News ✨
В Польше обнаружили новую схему мошенничества с банковскими картами через NFC-ретрансляцию
—
Summary:
Польский компьютерный координационный центр CERT Polska сообщил о выявлении новой вредоносной кампании, нацеленной на клиентов польских банков. Злоумышленники используют технику NFC-ретрансляции для несанкционированного снятия наличных в банкоматах без физического завладения картами жертв. Атака получила название NGate и представляет собой сложный многоэтапный сценарий. На первом этапе жертвы получают фишинговые сообщения по электронной почте или SMS, содержащие […]
Сообщение В Польше...
—
Source: SEC-1275-1
Published: 2025-11-10 10:53 | Author: SEC-1275
#general_cyber_news
https://1275.ru/ioc/v-polshe-obnaruzhili-novuyu-shemu-moshennichestva-s-bankovskimi-kartami-cherez-nfc-retranslyatsiyu_16071
В Польше обнаружили новую схему мошенничества с банковскими картами через NFC-ретрансляцию
—
Summary:
Польский компьютерный координационный центр CERT Polska сообщил о выявлении новой вредоносной кампании, нацеленной на клиентов польских банков. Злоумышленники используют технику NFC-ретрансляции для несанкционированного снятия наличных в банкоматах без физического завладения картами жертв. Атака получила название NGate и представляет собой сложный многоэтапный сценарий. На первом этапе жертвы получают фишинговые сообщения по электронной почте или SMS, содержащие […]
Сообщение В Польше...
—
Source: SEC-1275-1
Published: 2025-11-10 10:53 | Author: SEC-1275
#general_cyber_news
https://1275.ru/ioc/v-polshe-obnaruzhili-novuyu-shemu-moshennichestva-s-bankovskimi-kartami-cherez-nfc-retranslyatsiyu_16071
SEC-1275-1
В Польше обнаружили новую схему мошенничества с банковскими картами через NFC-ретрансляцию
В Польше обнаружили новую схему мошенничества с банковскими картами через NFC-ретрансляцию - Польский компьютерный координационный центр CERT Polska сообщил о выявлении новой вредоносной кампании, нацеленной на клиентов польских банков.