Critical Cloud Platform Vulnerabilities Put 50,000 Ruijie Network Devices at Risk
Security researchers discovered multiple critical flaws in Ruijie Networks' cloud platform that could enable remote control of network devices. The vulnerabilities, including a novel 'Open Sesame' attack method, exposed severe weaknesses in device authentication and command execution capabilities.
Malicious PyPI Packages Found Stealing User Data and Hijacking Social Media Accounts
Security researchers discovered two dangerous packages on PyPI repository that accumulated 300 downloads before removal. The malware captured keystrokes, screenshots, and sensitive data from major social platforms while employing sophisticated concealment techniques to avoid detection.
BadBox Android Malware Infects 190,000 Devices in Rapid Global Spread
A sophisticated new Android malware called BadBox has compromised 190,000 devices worldwide, demonstrating an alarming growth rate and ability to bypass security controls. Security experts urge users to take protective measures as cybersecurity teams analyze the threat and develop defenses.
North Korean Lazarus Group Targets Nuclear Facility with Advanced Modular Malware
North Korea's Lazarus Group has launched a sophisticated cyber espionage campaign against a nuclear organization using new modular malware called CookiePlus. The January 2024 attack demonstrates the group's expanding capabilities through multi-stage infection chains and evasive tactics targeting nuclear sector employees.
North Korean Hackers Target Nuclear Engineers with Advanced CookiePlus Malware
Notorious Lazarus Group launches sophisticated cyber attacks against nuclear industry employees using deceptive job recruitment tactics and new CookiePlus malware. The campaign, part of 'Operation Dream Job', demonstrates the group's evolving capabilities as North Korean hackers doubled their cryptocurrency theft to $1.34 billion in 2024.
Ukrainian Cybercriminal Behind Raccoon Infostealer Malware Gets 5-Year Prison Sentence
Mark Sokolovsky, a 28-year-old Ukrainian national, has been sentenced to 5 years in prison for operating the Raccoon Infostealer malware service that compromised over 50 million credentials worldwide. The $200/month malware subscription service enabled cybercriminals to steal sensitive financial and personal data from victims' computers.
Russian Hackers Deploy Stealthy RDP Attack Campaign Against High-Profile Targets
APT29, a Russian state-sponsored hacking group, has launched a sophisticated campaign using manipulated RDP configurations to compromise government and military targets. The attackers leverage PyRDP tool as a proxy to intercept communications while avoiding detection, targeting approximately 200 high-profile victims in a single day.
The Mask APT Returns: Advanced Cyber Espionage Group Targets Latin America After Decade of Silence
A sophisticated state-sponsored hacking group known as The Mask has emerged from a 10-year hiatus, launching new attacks against Latin American organizations. The group demonstrates enhanced capabilities through custom malware and innovative infection techniques, raising concerns in the cybersecurity landscape.
LDAP Enumeration: The Hidden Security Risk in Enterprise Networks
Organizations face a critical cybersecurity challenge as LDAP, essential for network management, becomes a prime target for sophisticated attackers. Security experts warn that threat actors are increasingly exploiting LDAP enumeration capabilities to map networks and plan devastating cyberattacks.
FBI Alerts on Chinese Security Camera Attacks: HiatusRAT Campaign Targets Western Nations
The FBI warns of an ongoing malware campaign exploiting Chinese-made security cameras and DVRs across Western countries using HiatusRAT malware. The sophisticated attacks, possibly state-sponsored, focus on gathering intelligence related to U.S. military procurement and Taiwan-based organizations.