Topic
Emerging Issue

CVE-2024-3094: XZ Utils Backdoor Threatens Linux Systems
A look at the recently discovered backdoor hiding in the open source XZ Utils compression service.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments
Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

CTI Roundup: 12 Million Secrets and Keys Leak on GitHub
BianLian threat actors exploit JetBrains TeamCity flaws, ransomware attacks continue to accelerate, and more than 12 million secrets and keys leak on GitHub.

CTI Roundup: Linux Servers Target of New Malware Campaign
New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report
Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS
Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.

CTI Roundup: Raspberry Robin, USB Malware Update, and Ransomware Victims on the Rise
Raspberry Robin malware exploits vulnerabilities, hackers use news and media hosting sites to spread USB malware payloads, and Palo Alto reports a 49% increase in ransomware victims.

CTI Roundup: DarkGate Malware Spreads on MS Teams, Phishing Rises on Telegram
DarkGate malware spreads via Teams group chats, Telegram marketplaces contribute to phishing attacks, and BianLian ransomware targets multiple industries.

CTI Roundup: Zloader Returns, VexTrio TDS, and Kasseika Ransomware
Zloader returns from hiatus, VexTrio brokers malware for over 60 affiliates, and Kasseika ransomware launches BYOVD attacks.

CTI Roundup: Medusa ransomware and a joint advisory for Androxgh0st malware
Medusa ransomware pivots to extortion, Infostealers evade macOS anti-malware, and the FBI and CISA issue a joint advisory for Androxgh0st malware.

CTI Roundup: AsyncRAT, PikaBot Malware, and MS SQL Servers Under Attack
AsyncRAT appears in a new campaign, Water Curupira distributes PikaBot loader malware, and Turkish hackers exploit global MS SQL servers.

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web
CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.