Cybersecurity

Make API Management Less Scary for Your Organization

While application development has evolved rapidly, the API management suites used to access these services remain a spooky reminder of a different era. Introducing new API management infrastructure with these legacy models still poses challenges for organizations as they modernize. Transitioning from monolithic architectures to agile microservices empowers developers to make quick changes. Using serverless […]

Cybersecurity

Operation Triangulation: Experts Uncover Deeper Insights into iOS Zero-Day Attacks

Oct 24, 2023NewsroomZero Day / Mobile Security The TriangleDB implant used to target Apple iOS devices packs in at least four different modules to record microphone, extract iCloud Keychain, steal data from SQLite databases used by various apps, and estimate the victim’s location. The findings come from Kaspersky, which detailed the great lengths the adversary […]

Cybersecurity

Another InfoStealer Enters the Field, ExelaStealer

Affected Platforms: WindowsImpacted Users: Windows usersImpact: The information collected can be used for future attacksSeverity Level: Medium In 2023, the InfoStealer market is a reasonably crowded affair. The likes of RedLine, Raccoon, and Vidar own a significant market share, with new entrants such as SaphireStealer appearing frequently. The latest entry, ExelaStealer has now taken the […]

Cybersecurity

ClearFake Enters the Fake Browser Update Arena to Deliver Malware | Cyware Hacker News

Researchers have shared details of a new fake browser update threat that used a new malware called ClearFake to deliver malicious payloads onto victims’ devices. The malware is similar to SocGholish and FakeSG campaigns that use social engineering tactics to trick users into installing a bogus web browser update. Modus operandi The operators behind ClearFake […]

Cybersecurity

Void Rabisu Targets Women Political Leaders with New RomCom 4.0 Variant | Cyware Hacker News

Researchers came across a new, lightweight variant of the RomCom backdoor that has been used in a cyberespionage campaign targeting the participants of the Women Political Leaders (WPL) Summit held in Brussels from June 7–8. The new iteration (tracked as RomCom 4.0) was first observed in early August and has been attributed to Void Rabisu, […]

Cybersecurity

Chinese APT Actors Target WeChat Users

Endpoint Security APT 41 Used Android, iOS Surveillance Malware to Target APAC Victims Since 2018 Jayant Chakravarti (@JayJay_Tech) • October 3, 2023     A WeChat Pay payment services sign at Cafe De Coral in Hong Kong (Image; Shutterstock) Security researchers linked a surveillance toolkit called LightSpy to Chinese cyberespionage group APT41. The group used […]