Cyber Defense Advisors

News

  • by
  • July 5, 2024

New Golang-Based Zergeca Botnet Capable of Powerful DDoS Attacks

Cybersecurity researchers have uncovered a new botnet called Zergeca that’s capable of conducting distributed denial-of-service (DDoS) attacks. Written in Golang, the botnet is so named for its reference to a string named “ootheca” present in the command-and-control (C2) servers (“ootheca[.]pw” and “ootheca[.]top”). “Functionally, Zergeca is not just a typical DDoS botnet; besides supporting six different […]

Cyber News
  • by
  • July 4, 2024

Volcano Demon ransomware group rings its victims to extort money

What’s happening? Security researchers have warned that a new ransomware group has taken an unusual twist on the traditional method of extorting money from its corporate victims. So what’s different this time? Whereas many ransomware attacks see a company’s company’s data exfiltrated by attackers, and the threat made that stolen data will be sold to […]

Cyber News
  • by
  • July 4, 2024

Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus

Microsoft has revealed two security flaws in Rockwell Automation PanelView Plus that could be weaponized by remote, unauthenticated attackers to execute arbitrary code and trigger a denial-of-service (DoS) condition. “The [remote code execution] vulnerability in PanelView Plus involves two custom classes that can be abused to upload and load a malicious DLL into the device,” […]

Cyber News
  • by
  • July 4, 2024

Brazil Halts Meta’s AI Data Processing Amid Privacy Concerns

Brazil’s data protection authority, Autoridade Nacional de Proteção de Dados (ANPD), has temporarily banned Meta from processing users’ personal data to train the company’s artificial intelligence (AI) algorithms. The ANPD said it found “evidence of processing of personal data based on inadequate legal hypothesis, lack of transparency, limitation of the rights of data subjects, and […]

Cyber News
  • by
  • July 4, 2024

Global Police Operation Shuts Down 600 Cybercrime Servers Linked to Cobalt Strike

A coordinated law enforcement operation codenamed MORPHEUS has felled close to 600 servers that were used by cybercriminal groups and were part of an attack infrastructure associated with the Cobalt Strike tool. The crackdown targeted older, unlicensed versions of the Cobalt Strike red teaming framework between June 24 and 28, according to Europol. Of the […]

Cyber News
  • by
  • July 4, 2024

Twilio’s Authy App Attack Exposes Millions of Phone Numbers

Cloud communications provider Twilio has revealed that unidentified threat actors took advantage of an unauthenticated endpoint in Authy to identify data associated with Authy accounts, including users’ cell phone numbers. The company said it took steps to secure the endpoint to no longer accept unauthenticated requests. The development comes days after an online persona named […]

Cyber News
  • by
  • July 3, 2024

Smashing Security podcast #379: Private nights, evil twins, and crypto home invasions

Apps can let you spy on strangers in bars, a gang of cryptocurrency thieves turns to kidnap and assault, and have you joined the mile-high evil twin club? All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this […]

Cyber News

Cybersecurity Alert: Brace for July 4th Weekend Threats

Cybersecurity Alert: Brace for July 4th Weekend Threats Stay Secure While You Celebrate – Apple ID Users Beware of Malicious SMS Attacks As we gear up for the Fourth of July festivities, it’s crucial to ramp up our cybersecurity efforts to protect against the heightened risk of cyberattacks during this holiday weekend. A Peek At […]

Cyber Thoughts
  • by
  • July 3, 2024

The Not-So-Secret Network Access Broker x999xx

Most accomplished cybercriminals go out of their way to separate their real names from their hacker handles. But among certain old-school Russian hackers it is not uncommon to find major players who have done little to prevent people from figuring out who they are in real life. A case study in this phenomenon is “x999xx,” […]

Cyber News