Experts warn of Palo Alto firewall exploitation after 2,000 compromises spotted
Category Details Threat Actors Unidentified hackers exploiting Palo Alto Networks firewall vulnerabilities. Campaign Overview Thousands…
Exploring Rhysida Ransomware
CategoryDetailsThreat ActorsRhysida Ransomware group (possible connection to Vice Society Ransomware group).Campaign OverviewRhysida ransomware attacks targeted…
North Korean shell companies found impersonating US IT firms to fund missiles
CategoryDetailsThreat ActorsDPRK-affiliated groups impersonating US-based software and tech consulting businesses.Campaign OverviewNorth Korea uses fake IT…
Inside KillSec: The Rising Threat of Ransomware-as-a-Service and Its Global Impact
Key DetailInformationThreat ActorsKillSec (Eastern Europe-Russia Region)Campaign OverviewActive since October 2023, involved in ransomware attacks, data…
Google takes down fake news sites, wire services run by Chinese influence operation
Topic Details Operation Details Google removed hundreds of domains running pro-China content, attributed to four…
UK drinking water supplies disrupted by record number of undisclosed cyber incidents
Category Details Threat Actors Not explicitly named; likely a mix of cybercriminals and nation-state actors…
OSINT Updates for November 22 , 2024
https://twitter.com/SecAI_AI/status/1859770564296225267 https://twitter.com/ClefTheHacker/status/1859892350392422731 https://twitter.com/FalconFeedsio/status/1859820207201714499 https://twitter.com/cyberfeeddigest/status/1859868387976806582 https://twitter.com/cyberfeeddigest/status/1859876230989857234 https://twitter.com/DailyRansomware/status/1859872936619802914 https://twitter.com/jamessecuritytr/status/1859854138881999316 https://twitter.com/DailyRansomware/status/1859845914887704755
China-linked hackers target Linux systems with new spying malware
CategoryDetailsThreat ActorsGelsemium (China-linked state-sponsored threat actor).Campaign OverviewEspionage campaign targeting Linux systems, deploying malware strains WolfsBane…
Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 and CVE-2024-9474 (Updated Nov. 22)
CategoryDetailsThreat ActorsUnnamed actors exploiting CVE-2024-0012 and CVE-2024-9474; activity includes manual/automated scans, web shells, and C2…
Lateral Movement on macOS: Unique and Popular Techniques and In-the-Wild Examples
Topic Details Introduction Explores macOS lateral movement techniques, including SSH key theft, Apple Remote Desktop,…