Two months after the release of the security updates for the drupalgeddon2 flaw, experts continue to see vulnerable websites running on flawed versions of Drupal that hasn’t installed security patches. In March, the Drupal developers Jasper Mattsson discovered a “highly critical” vulnerability, tracked as CVE-2018-7600, aka drupalgeddon2, affecting Drupal 7 […]
Année : 2018
North Korea-Linked Covellite APT group stopped targeting organizations in the U.S.
A North Korea-linked APT group, tracked by experts at industrial cybersecurity firm Dragos as Covellite, has stopped targeting US organizations. Anyway, the group, that is believed to be linked to the notorious Lazarus APT group, is continuing to target organizations in Europe and East Asia. The group has been around at least since 2017 and […]
Crooks expand the original Mirai botnet code base with new capabilities and improvements
Cybercriminals continue to improve the infamous Mirai botnet by adding new exploits and functionalities, experts warn new dangerous variant will appear in the wild. According to Netscout’s Arbor Security Engineering and Response Team (ASERT), cybercriminals continue to improve the dreaded Mirai IoT botnet by adding new exploits and functionalities. The time to market of […]
The VPNFilter Botnet Is Attempting a Comeback
The VPNFilter botnet that was built by Russian cyberspies, which infected over 500,000 routers, and was taken down last week by the FBI is attempting a comeback, according to telemetry data gathered this week. Security researchers from JASK and GreyNoise Intelligence revealed on Friday that they had detected the same threat actor that built the first […]
Microsoft Inches Past Google to Become the Third Most Valuable Company
Microsoft has now officially become the third most valuable company in the world as it pushes Google’s parent company Alphabet into fourth place. With Microsoft’s current market cap at 766.8 billion compared to Alphabet’s 766.5 billion, Microsoft is able to retain the third place spot using market prices at the time of this writing. With Apple, […]
North Korea-linked Andariel APT Group exploited an ActiveX Zero-Day in recent attacks
A North Korea-linked APT group, tracked as AndarielGroup, leveraged an ActiveX zero-day vulnerability in targeted attacks against South Korean entities. According to a report published by South Korean cyber-security firm AhnLab, the Andariel Group is a division of the dreaded Lazarus APT Group, it already exploited ActiveX vulnerabilities in past attacks The attackers exploited at […]
Le phishing se déchaîne sur les réseaux sociaux
La fraude ciblant les utilisateurs des réseaux sociaux (ou « angler phishing ») a bondi de 200% en un trimestre, selon Proofpoint. Proofpoint a publié son rapport trimestriel sur les menaces cyber qui pèsent sur les entreprises (Quaterly Threat Report Q1 2018). Le rapport s’appuie sur l’analyse quotidienne de 5 milliards de […]
Miscreants hijacked the defunct SpamCannibal blacklist service
The SpamCannibal blacklist service was hijacked since Wednesday morning, attackers changed the DNS name server settings for the website overnight. The SpamCannibal was born to blacklist IP address of malicious servers involved in spam campaigns and DoS attacks. SpamCannibal was using a continually updated database containing the IP addresses of spam or […]
La poste tunisienne victime d’une attaque par Phishing
D’abord considéré comme une technique frauduleuse , le phishing est devenue une véritable plaie sur internet. Autant utilisée par les pirates informatiques, elle vise à récupérer des informations auprès des clients des établissements financiers avec des méthodes de plus en plus sophistiquées. Des fausses pages sur les réseaux sociaux, des […]
US-CERT issued an alert on two malware associated with North Korea-linked APT Hidden Cobra
The Department of Homeland Security (DHS) and the FBI issued a joint Technical alert on two strain on malware, the Joanap backdoor Trojan and Brambul Server Message Block worm, associated with the HIDDEN COBRA North Korea-linked APT group. “Working with U.S. government partners, DHS and FBI identified Internet Protocol (IP) addresses […]