A widespread malicious cyber operation has hijacked thousands of websites aimed at East Asian audiences to redirect visitors to adult-themed content since early September 2022.
Government entities and large organizations have been targeted by an unknown threat actor by exploiting a security flaw in Fortinet FortiOS software to result in data loss and OS and file corruption.
The company, formerly CampusKudos, which provides and hosts a social platform for higher education institutions and alumni networks, left the server hosting an internal database exposed to the internet without a password, allowing anyone to access the data using only a web browser and knowing its IP address.
The vulnerabilities were discovered by researchers at industrial and IoT cybersecurity firm Claroty. The company — along with CISA and CERT/CC — has attempted to report the findings to the vendor over the past year, but without success, and the security holes remain unpatched.
In 2022, OpenSeahad over 1 million registered users and received more than 121 million monthly visitors to its website. This makes OpenSea not only the largest NFT marketplace but also a lucrative target for cybercriminals. Any vulnerability on the platform can turn into an opportunity for malicious actors and spell disaster for unsuspecting users.
A new Golang-based botnet named GoBruteforcer has been spotted scanning and infecting popular web servers, including FTP and MySQL. The botnet, hosted on a legitimate website, deploys an Internet Relay Chat (IRC) bot on compromised servers and leverages it to communicate with the attacker's C2 server to obtain further instructions.
Google search results have become a hotbed of malicious ads pushing malware. Recently, threat actors have been discovered abusing Google Ads to distribute BatLoader malware. The campaign operators use software impersonation tactics for malware delivery and add two more payloads upon infection.
he videos lure users by pretending to be tutorials on how to download cracked versions of software such as Photoshop, Premiere Pro, Autodesk 3ds Max, AutoCAD, and other products that are licensed products available only to paid users," CloudSEK researcher Pavan Karthick M said.
Investment fraud leapfrogged business email compromise (BEC) last year to become the top-earning cybercrime category, costing victims over $3.3bn in 2022, according to the FBI.
With governments around the world increasingly turning to a hybrid work environment, personnel are simultaneously becoming less prepared to deal with new cyber risks and vulnerabilities that threaten the virtual office, according to the findings of a government cybersecurity survey released by IT company Ivanti on Thursday.