Cisco Catalyst SD-WAN zero-day flaw actively exploited in real-world attacks
Cisco’s threat hunting team said that the flaw has been exploited in the wild since at least 2023.
Cisco’s threat hunting team said that the flaw has been exploited in the wild since at least 2023.
Following the Valencia floods, Anonymous Fénix allegedly targeted multiple public administration websites, accusing authorities of responsibility for the disaster.
Researchers believe the group is Armenian-speaking and connected to Russian infrastructure.
Mercenary Akula is thought to be a financially motivated mercenary entity with links to cyber espionage and psychological operations.
Sanctions also target two Trickbot members who allegedly helped Operation Zero and their own exploit brokerage firm.
Analysis of domain registration data indicates that the threat actors are using a rotating set of domains and cloud hosting services to deliver malware.
This marks the first time the Medusa ransomware has been linked to North Korean threat actors.
The observed campaign deploys a five-stage infection chain installing a native C implant designed for persistence and lateral movement.
The attack begins with social engineering lures promoting free premium software, including pirated office productivity suite installers.
Oleksandr Didenko stole the identities of US citizens and sold them to overseas IT workers through the UpWorkSell online platform.
Showing elements 221 - 230