Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA warns of a significant rise in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. These attacks pose serious risks to critical infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack began with a phishing email containing a link to an encrypted archive holding a malicious Windows Shortcut (LNK) file disguised as "Case Documents." When executed, the LNK triggered a multi-stage attack chain involving privilege escalation, disabling Microsoft Defender, and downloading additional payloads.
Researchers uncovered HollowFrame, a Go-based loader, and Matryoshka, a Rust-based backdoor, used in spear-phishing attacks on a law firm. The attack chain begins with a link to an encrypted archive containing a malicious Windows Shortcut file.
This article details a spear-phishing campaign targeting a law firm that uses a Go-based loader called HollowFrame and a Rust-based backdoor named Matryoshka. The attack begins with a malicious LNK file disguised as case documents, leading to privilege escalation and payload delivery.
This article warns about scam websites offering fake Fortnite rewards, such as V-Bucks or locker value calculators, that redirect users to fake Epic Games login pages. These sites steal usernames and passwords, which criminals use to hijack accounts, make purchases, or sell them.