Oracle patches EBS RCE flaw exploited in Clop extortion attacks
The vulnerability “may be exploited over a network without the need for a username and password.”
The vulnerability “may be exploited over a network without the need for a username and password.”
The campaign began in early January and included a targeted attack on a Brazilian military organization.
In brief: Chinese hackers are exploiting a recently patched VMware flaw, a smishing campaign abuses Milesight routers for phishing, and more.
The hacker collective claims to have stolen nearly 570GB of compressed data spread across over 28,000 internal projects.
Once installed, the malicious apps gain persistent access and silently exfiltrate sensitive data.
The group blends custom tooling with shared operational infrastructure.
The campaign, active since at least February 2022, leverages a vulnerability tracked as CVE-2023-43261.
Experts note some shift in attackers’ behavior such as an adoption of the “Steal & Go” tactic.
The threat actors distributed the XLL payloads inside ZIP archives shared via the Signal messaging app.
Zhimin Qian was behind a vast fraudulent Bitcoin investment scheme that defrauded over 128,000 victims in China.
Showing elements 571 - 580