Water Sigbin Hackers Exploit Oracle WebLogic Vulnerabilities

Cybersecurity researchers uncovered a sophisticated attack campaign by the Water Sigbin (aka 8220 Gang) threat actor that exploited vulnerabilities in the Oracle WebLogic Server, notably CVE-2017-3506 and CVE-2023-21839, to deploy the XMRig cryptocurrency miner on compromised systems.   The attack begins with the threat actor exploiting the WebLogic vulnerabilities to execute a malicious PowerShell script on the victim…

Read More

Hackers Backdoored Courtroom Video Recording Software With System Hijacking Malware

Hackers Backdoored Courtroom Video Recording Software With System Hijacking Malware Courtroom software hijacked discovered by researchers of Rapid7 A vulnerability (CVE-2024-4978) has been identified in JAVS Viewer v8.3.7, a critical component for managing digital recordings in legal and government environments.  The installer for this version is backdoored, allowing attackers to remotely seize control of infected…

Read More

Have you Noticed Job’s Adds Roaming Around Facebook; Beaware of Ov3r_Stealer’ Malware

Recently as I was going through my Facebook , I noticed that lot of job advertisement for various position mainly account manager. As I applied they send back queries asking for mobile number and What’s Up messages. Researchers first discovered the stealer in early December. It was being spread via a Facebook job advertisement for…

Read More

No, 3 million Electric Toothbrushes were not used in a DDoS Attack; Hypothetical Attack

3 million electric toothbrushes were hacked with malware to conduct distributed denial of service (DDoS) attacks is likely a hypothetical scenario instead of an actual attack, said a publication. The published a story stated that an employee of cyber security firm Fortinet said 3 million electric toothbrushes had been infected with Java malware to conduct DDoS…

Read More

Zscaler ThreatLabz Finds Most Cyberattacks Hide In Encrypted Traffic

Zscaler finds malware, which includes malicious web content and malware payloads, continued to dominate over other types of encrypted attacks, with ad spyware sites and cross-site scripting accounting for 78% of all blocked attacks. Research analyzed nearly 30 billion blocked threats from October 2022 to September 2023 by the Zscaler Zero Trust Exchange platform, the…

Read More