Gootkit banking Trojan continues to be delivered via fake invoices via Mailgun SMTP relay service and Microsoft one drive for business

Haythem Elmir

Gootkit banking trojan is still being distributed via the Mailgun SMTP sending service, using Microsoft’s One drive business file hosting service to deliver the malicious macro enabled word docs that in turn download the gootkit banking trojan payload from another site.  These use compromised mail accounts or websites  to relay […]

Experts warn threat actors are scanning the web for Drupal installs vulnerable to Drupalgeddon2

Haythem Elmir

After the publication of a working Proof-Of-Concept for Drupalgeddon2 on GitHub for “educational or information purposes,” experts started observing bad actors attempting to exploit the flaw. At the end of March, the Drupal Security Team confirmed that a “highly critical” vulnerability (dubbed Drupalgeddon2), tracked as CVE-2018-7600, was affecting Drupal 7 and 8 core and announced the […]