RomCom exploits Firefox and Windows zero days in the wild

CategoryDetailsVulnerability IdentifiedCVE-2024-9680: A use-after-free bug in the animation timeline feature in Firefox, Thunderbird, and Tor…

Threat Hunting Case Study: Uncovering Turla

CategoryDetailsThreat ActorsTurla (FSB's Center 16), Russia's state-sponsored cyber espionage groupCampaign OverviewFocused on cyber espionage, targeting…

A Look at Trending Chinese APT Techniques

CategoryDetailsChina's Global AmbitionsMilitary, technological, and economic powers driving its challenge to the global order, with…

OSINT Updates for November 28 , 2024

https://twitter.com/fofabot/status/1862072003907440752 GitLab has released critical security updates for Community and Enterprise Editions, addressing multiple vulnerabilities,…

APT trends Report Q3 2024

Category Details Threat Actor/Family Unknown, possibly linked to OceanLotus (APT32) but not conclusively attributed. Framework…

T-Mobile rebuffed breach attempts by hackers likely connected to China’s Salt Typhoon

Category Details Threat Actors Salt Typhoon (China-linked hacking campaign). Campaign Overview Attempted infiltration of T-Mobile…

OSINT Updates for November 27 , 2024

https://twitter.com/TodayCyberNews/status/1861637269225939165 North Korea operates a Global Network of IT workers, using fake Identities and Front…

RomCom Backdoor Attacks Use Zero-Day Exploits in Mozilla and Windows (CVE-2024-9680 & CVE-2024-49039)

AspectDetailsThreat ActorsRomCom, suspected ties to Russia, also known as Tropical Scorpius, Storm-0978, or UNC2596.Campaign OverviewExploited…

Ransomware-driven data exfiltration: techniques and implications

Category Details Threat Actors Ransomware and extortion groups, including lucrative intrusion sets and state-sponsored actors.…

CyberVolk | A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks

Key DetailInformationThreat ActorsCyberVolk/GLORIAMIST, a politically motivated hacktivist collective with pro-Russia leanings.Campaign OverviewCyberVolk launched ransomware attacks…