Over 115,000 Drupal Sites still vulnerable to Drupalgeddon2, a gift to crooks

Haythem Elmir

Two months after the release of the security updates for the drupalgeddon2 flaw, experts continue to see vulnerable websites running on flawed versions of Drupal that hasn’t installed security patches. In March, the Drupal developers Jasper Mattsson discovered a “highly critical” vulnerability, tracked as CVE-2018-7600, aka drupalgeddon2, affecting Drupal 7 […]

Crooks expand the original Mirai botnet code base with new capabilities and improvements

Haythem Elmir

Cybercriminals continue to improve the infamous Mirai botnet by adding new exploits and functionalities, experts warn new dangerous variant will appear in the wild. According to Netscout’s Arbor Security Engineering and Response Team (ASERT), cybercriminals continue to improve the dreaded Mirai IoT botnet by adding new exploits and functionalities. The time to market of […]

North Korea-linked Andariel APT Group exploited an ActiveX Zero-Day in recent attacks

Haythem Elmir

A North Korea-linked APT group, tracked as  AndarielGroup, leveraged an ActiveX zero-day vulnerability in targeted attacks against South Korean entities. According to a report published by South Korean cyber-security firm AhnLab, the Andariel Group is a division of the dreaded Lazarus APT Group, it  already exploited ActiveX vulnerabilities in past attacks The attackers exploited at […]

Le phishing se déchaîne sur les réseaux sociaux

Haythem Elmir

La fraude ciblant les utilisateurs des réseaux sociaux (ou « angler phishing ») a bondi de 200% en un trimestre, selon Proofpoint. Proofpoint a publié son rapport trimestriel sur les menaces cyber qui pèsent sur les entreprises (Quaterly Threat Report Q1 2018). Le rapport s’appuie sur l’analyse quotidienne de 5 milliards de […]