Microsoft research uncovers new Zerobot capabilities

Botnet malware operations are a constantly evolving threat to devices and networks. Threat actors target Internet of Things (IoT) devices for recruitment into malicious operations as IoT devices’ configurations often leave them exposed, and the number of internet-connected devices continue Read More …

Guardian hit by serious IT incident believed to be ransomware attack

The Guardian has been hit by a serious IT incident, which is believed to be a ransomware attack. The incident began late on Tuesday night and has affected parts of the company’s technology infrastructure, with staff told to work from Read More …

Eurozone plans to formalize passenger data, improve security

The European Commission last week proposed rules governing the use of Advance Passenger Information in a bid to strengthen border security. As commissioner for home affairs Ylva Johansson explained during a press conference, travel in and out of the Schengen Read More …

As cyber criminals start targeting retail, companies must be ready to fight back

Given the current geopolitical situation, it’s easy to conflate cybersecurity with the war in Ukraine and bad actors overseas. Historically, cyber-attacks have traditionally been associated with nation states and hacktivists conducting high-profile attacks on high-profile targets to wreak havoc, make Read More …

Raspberry Robin Malware Targets Telecom, Governments

Trend Micro researchers found a malware sample allegedly capable of connecting to the Tor network to deliver its payloads. Their initial analysis of the malware, which compromised a number of organizations toward the end of September, showed that while the Read More …

Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine

Since Unit 42 last blog in early February covering the advanced persistent threat (APT) group Trident Ursa (aka Gamaredon, UAC-0010, Primitive Bear, Shuckworm), Ukraine and its cyber domain has faced ever-increasing threats from Russia. Trident Ursa is a group attributed Read More …

XLLing in Excel – threat actors using malicious add-ins

For decades, Microsoft Office applications have served as one of the most significant entry points for malicious code. Malicious actors have continued to utilize Visual Basic for Applications (VBA) macros, despite automatic warnings to users after opening Office documents containing Read More …

Twitter boosted Pentagon propaganda efforts in the Middle East

Twitter has allowed the Defense Department to use the social media platform to carry out a covert online propaganda and influence campaign for at least the last five years, the latest “Twitter Files” revealed Tuesday. At the behest of the Read More …

Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities

More than two years ago, a researcher, A2nkF, published the details of an interesting exploit chain on the Objective-See blog. He demonstrated the exploit chain from root privilege escalation to SIP-Bypass up to arbitrary kernel extension loading. After diving into the second Read More …

DHS Opens 23.1 Small Business Innovation Research Solicitation

FOR IMMEDIATE RELEASE S&T Public Affairs, 202-254-2385 WASHINGTON – The Department of Homeland Security (DHS) Small Business Innovation Research (SBIR) 23.1 Solicitation is now open and accepting applications from U.S. small businesses interested in submitting research proposals for seven diverse Read More …