Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking – OfficialSarkar

Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking – OfficialSarkar

Sep 12, 2024Ravie LakshmananCryptocurrency / Network Security Internet-exposed Selenium Grid instances are being targeted by bad actors for illicit cryptocurrency mining and proxyjacking campaigns. “Selenium Grid is a server that facilitates running test cases in parallel across different browsers and versions,” Cado Security researchers Tara Gould and Nate Bill said in an analysis published today….

Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware Attack – OfficialSarkar

Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware Attack – OfficialSarkar

Iraqi government networks have emerged as the target of an “elaborate” cyber attack campaign orchestrated by an Iran state-sponsored threat actor called OilRig. The attacks singled out Iraqi organizations such as the Prime Minister’s Office and the Ministry of Foreign Affairs, cybersecurity company Check Point said in a new analysis. OilRig, also called APT34, Crambus,…

Top 3 Threat Report Insights for Q2 2024 – OfficialSarkar

Top 3 Threat Report Insights for Q2 2024 – OfficialSarkar

Sep 12, 2024The Hacker NewsThreat Intelligence / Cybercrime Cato CTRL (Cyber Threats Research Lab) has released its Q2 2024 Cato CTRL SASE Threat Report. The report highlights critical findings based on the analysis of a staggering 1.38 trillion network flows from more than 2,500 of Cato’s global customers, between April and June 2024. Key Insights…

WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers – OfficialSarkar

WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers – OfficialSarkar

Sep 12, 2024Ravie LakshmananWeb Security / Content Management WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate two-factor authentication (2FA) mandatorily. The enforcement is expected to come into effect starting October 1, 2024. “Accounts with commit access can push updates and changes to…

Quad7 Botnet Expands to Target SOHO Routers and VPN Appliances – OfficialSarkar

Quad7 Botnet Expands to Target SOHO Routers and VPN Appliances – OfficialSarkar

Sep 11, 2024Ravie LakshmananNetwork Security / Hacking The operators of the mysterious Quad7 botnet are actively evolving by compromising several brands of SOHO routers and VPN appliances by leveraging a combination of both known and unknown security flaws. Targets include devices from TP-LINK, Zyxel, Asus, Axentra, D-Link, and NETGEAR, according to a new report by…

DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe – OfficialSarkar

DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe – OfficialSarkar

A “simplified Chinese-speaking actor” has been linked to a new campaign that has targeted multiple countries in Asia and Europe with the end goal of performing search engine optimization (SEO) rank manipulation. The black hat SEO cluster has been codenamed DragonRank by Cisco Talos, with victimology footprint scattered across Thailand, India, Korea, Belgium, the Netherlands,…

Singapore Police Arrest Six Hackers Linked to Global Cybercrime Syndicate – OfficialSarkar

Singapore Police Arrest Six Hackers Linked to Global Cybercrime Syndicate – OfficialSarkar

Sep 11, 2024Ravie LakshmananCyber Crime / Hacking The Singapore Police Force (SPF) has announced the arrest of five Chinese nationals and one Singaporean man for their alleged involvement in illicit cyber activities in the country. The development comes after a group of about 160 law enforcement officials conducted a series of raids on September 9,…

Lazarus Group Uses Fake Coding Tests to Spread Malware – OfficialSarkar

Lazarus Group Uses Fake Coding Tests to Spread Malware – OfficialSarkar

Sep 11, 2024Ravie LakshmananMalware / Software Development Cybersecurity researchers have uncovered a new set of malicious Python packages that target software developers under the guise of coding assessments. “The new samples were tracked to GitHub projects that have been linked to previous, targeted attacks in which developers are lured using fake job interviews,” ReversingLabs researcher…

Ivanti Releases Urgent Security Updates for Endpoint Manager Vulnerabilities – OfficialSarkar

Ivanti Releases Urgent Security Updates for Endpoint Manager Vulnerabilities – OfficialSarkar

Sep 11, 2024Ravie LakshmananEnterprise Security / Vulnerability Ivanti has released software updates to address multiple security flaws impacting Endpoint Manager (EPM), including 10 critical vulnerabilities that could result in remote code execution. A brief description of the issues is as follows – CVE-2024-29847 (CVSS score: 10.0) – A deserialization of untrusted data vulnerability that allows…