Exposed toolkit reveals suspected APT28 campaign targeting Ukrainian government
The directory contained what appears to be a complete exploitation framework designed to target vulnerabilities in Roundcube.
In brief: Google fixes two Chrome zero-days, CISA updates its KEV list with four new entries, and more.
The directory contained what appears to be a complete exploitation framework designed to target vulnerabilities in Roundcube.
The attackers combined social engineering with advanced evasion techniques to infiltrate corporate systems and steal data.
The company patched two publicly disclosed flaws; neither has been observed to be actively exploited in attacks.
The malwareu2019s operators mainly exploit home and small-office networking equipment.
Attackers are exploiting recently disclosed vulnerabilities or weak credentials to gain access to FortiGate devices.
The threat actor has been using the BeardShell and Covenant custom malware implants since April 2024.