Topic
Reports

CVE-2024-3094: XZ Utils Backdoor Threatens Linux Systems
A look at the recently discovered backdoor hiding in the open source XZ Utils compression service.

CTI Roundup: Tycoon Phishing-as-a-Service and TheMoon Malware Update
Researchers discover a new version of the Tycoon 2FA AiTM kit, a phishing attack disguises keylogger as bank payment notice, and TheMoon malware targets ASUS routers.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments
Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

CTI Roundup: Linux Servers Target of New Malware Campaign
New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report
Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS
Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

Tanium Reduced Software Vulnerability by 97% According to New Study
Learn how Forrester conducted the Total Economic Impact study on Tanium Converged Endpoint Management (XEM) and the value XEM can provide organizations.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise
Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram
DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware
Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware
Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack
AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.