Author: Cybernoz

VSCode
20
Mar
2025

VSCode extensions found downloading early-stage ransomware

Two malicious VSCode Marketplace extensions were found deploying in-development ransomware, exposing critical gaps in Microsoft’s review process. The extensions, named…

Gov net-zero body spins up IT environment
20
Mar
2025

Gov net-zero body spins up IT environment – Cloud

The federal government is building an independent cloud and IT environment for its recently launched energy transformation agency. The Net…

Cisco
20
Mar
2025

Critical Cisco Smart Licensing Utility flaws now exploited in attacks

Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances unpatched against a vulnerability exposing a built-in backdoor admin account….

Babuk2 Ransomware Issuing Fake Extortion Demands With Data from Old Breaches
20
Mar
2025

Babuk2 Ransomware Issuing Fake Extortion Demands With Data from Old Breaches

The Babuk2 ransomware group has been caught issuing extortion demands based on false claims and recycled data from previous breaches….

North Korean IT Workers Exploit GitHub to Launch Global Cyberattacks
20
Mar
2025

North Korean IT Workers Exploit GitHub to Launch Global Cyberattacks

A recent investigation by cybersecurity firm Nisos has uncovered a coordinated effort by North Korean IT workers to exploit GitHub…

Dell Warns of Multiple Secure Connect Gateway Vulnerabilities Let Compromise System
20
Mar
2025

Dell Warns of Multiple Secure Connect Gateway Vulnerabilities Let Compromise System

Dell Technologies has issued a critical security advisory warning customers about multiple vulnerabilities in its Secure Connect Gateway (SCG) product…

New Arcane Stealer Spreads via YouTube, Stealing VPN and Browser Login Credentials
20
Mar
2025

New Arcane Stealer Spreads via YouTube, Stealing VPN and Browser Login Credentials

A new malware campaign has been uncovered, involving a sophisticated stealer known as Arcane, which is distributed through YouTube videos…

Semrush impersonation scam hits Google Ads
20
Mar
2025

Semrush impersonation scam hits Google Ads

This blog post was co-authored with Elie Berreby, Senior SEO Strategist Criminals are highly interested in online marketing and advertising…

Outpost24
20
Mar
2025

Is it time to retire ‘one-off’ pen tests for continuous testing?

If your organization is like many, annual penetration testing may be a regular part of your security protocols. After completing…

North Korean IT Workers Exploiting GitHub to Attack Organizations Worldwide
20
Mar
2025

North Korean IT Workers Exploiting GitHub to Attack Organizations Worldwide

A sophisticated network of suspected North Korean IT workers has been discovered leveraging GitHub to create false identities and secure…

RansomHub Affiliate Deploys New Custom Backdoor “Betruger” for Persistent Access
20
Mar
2025

RansomHub Affiliate Deploys New Custom Backdoor “Betruger” for Persistent Access

Symantec’s Threat Hunter team has identified a sophisticated custom backdoor named “Betruger” linked to a RansomHub affiliate. This newly discovered…

Israeli Spyware Graphite Targeted WhatsApp with 0-Click Exploit
20
Mar
2025

Israeli Spyware Graphite Targeted WhatsApp with 0-Click Exploit

Cybersecurity researchers at the Citizen Lab at the University of Toronto have exposed the use of sophisticated spyware named Graphite,…