Hackers Using Fake YouTube Links to Steal Login Credentials

SectionDetailsThreat ActorsStorm1747 groupCampaign OverviewAttackers use fake YouTube links to redirect users to phishing pages designed…

Russian espionage and financial theft campaigns have ramped up, Ukraine cyber agency says

Category Details Threat Actors UAC-0010 (Gamaredon), UAC-0006, UAC-0050 (all Russia-linked hacker groups). Campaign Overview Ramp-up…

Suspected Ukrainian hackers impersonating Russian ministries to spy on industry

Category Details Threat Actors Sticky Werewolf (suspected pro-Ukraine cyberespionage or hacktivist group). Campaign Overview Targeting…

Detect Banshee Stealer: Stealthy Apple macOS Malware Evades Detection Using XProtect Encryption

Category Details Threat Actors Likely Russian-speaking cybercriminal groups (suspected origin). Campaign Overview Targeting macOS users…

Russia's largest platform for state procurement hit by cyberattack from pro-Ukraine group

Category Details Threat Actors Yellow Drift (pro-Ukraine hacker group), Ukrainian Cyber Alliance, Cyber Anarchy Squad.…

DOJ deletes China-linked PlugX malware off more than 4,200 US computers

Category Details Threat Actors Mustang Panda (a.k.a BASIN, Bronze President, etc.), linked to China's Ministry…

FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation

Category Details Threat Actors Mustang Panda (a.k.a BASIN, Bronze President, Earth Preta, RedDelta, TA416, etc.),…

US, Japan and S. Korea urge crypto industry to take action against North Korean hackers

Category Details Threat Actors North Korea, Lazarus Group, North Korean IT workers. Campaign Overview Orchestrated…

Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation

CategoryDetailsThreat ActorsUnidentified threat actors targeting macOS through SIP bypass.Campaign OverviewExploitation of CVE-2024-44243 to bypass System…

Hackers Use CVE-2024-50603 to Deploy Backdoor on Aviatrix Controllers

Category Details Threat Actors Unidentified attackers exploiting CVE-2024-50603 for cryptojacking and deploying backdoors. Campaign Overview…