Posts

The Hacker News - APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme

The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America. "The uncovered lures include a mixture of internal and publicly available documents, as well as possible actor-generated from The Hacker News https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html

KnowBe4 - Organizations Are Vulnerable to Image-based and QR Code Phishing

Image
A majority of organizations have a false sense of security regarding their resistance to phishing attacks, according to a new report from researchers at IRONSCALES and Osterman Research. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/organizations-vulnerable-to-image-based-qr-code-phishing

The Hacker News - Hackers Using Cracked Software on GitHub to Spread RisePro Info Stealer

Cybersecurity researchers have found a number of GitHub repositories offering cracked software that are used to deliver an information stealer called RisePro. The campaign, codenamed gitgub, includes 17 repositories associated with 11 different accounts, according to G DATA. The repositories in question have since been taken down by the Microsoft-owned subsidiary. "The repositories look from The Hacker News https://thehackernews.com/2024/03/hackers-using-cracked-software-on.html

Rapid 7 - Metasploit Wrap-Up 03/15/2024

Image
New module content (3) GitLab Password Reset Account Takeover Authors: asterion04 and h00die Type: Auxiliary Pull request: #18716 contributed by h00die Path: admin/http/gitlab_password_reset_account_takeover AttackerKB reference: CVE-2023-7028 Description: This adds an exploit module that leverages an account-take-over vulnerability to take control of a GitLab account without user interaction. The vulnerability lies in the password reset functionality as it’s possible to provide two email addresses so that the reset code will be sent to both. It is therefore possible to provide the email address of the target account as well as that of one we control, and to reset the password. MinIO Bootstrap Verify Information Disclosure Authors: RicterZ and joel <joel @ ndepthsecurity> Type: Auxiliary Pull request: #18775 contributed by 6a6f656c Path: gather/minio_bootstrap_verify_info_disc AttackerKB reference: CVE-2023-28432 Description: This adds an auxiliary module that ...

The Hacker News - GhostRace – New Data Leak Vulnerability Affects Modern CPUs

A group of researchers has discovered a new data leakage attack impacting modern CPU architectures supporting speculative execution. Dubbed GhostRace (CVE-2024-2193), it is a variation of the transient execution CPU vulnerability known as Spectre v1 (CVE-2017-5753). The approach combines speculative execution and race conditions. "All the common synchronization primitives implemented from The Hacker News https://thehackernews.com/2024/03/ghostrace-new-data-leak-vulnerability.html

KnowBe4 - If Social Engineering Accounts for up to 90% of Attacks, Why Is It Ignored?

Image
Social engineering and phishing are involved in 70% to 90% of all successful cybersecurity attacks . No other initial root hacking cause comes close. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/social-engineering-accounts-for-90-of-attacks-why-is-it-ignored

KnowBe4 - Sophos: Over 75% of Cyber Incidents Target Small Businesses

Image
New analysis of incident data shows threat actors are evolving their attack techniques to take advantage of budget and resource-strapped small businesses.  from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/sophos-over-75-of-cyber-incidents-target-small-businesses