Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The China-nexus threat actor UAT-7810 is expanding its Operational Relay Box (ORB) networks by exploiting vulnerabilities in unpatched Ruckus and ASUS routers to deploy custom malware, including upgraded backdoors like "LONGLEASH" and "DOGLEASH." These ORB networks serve as covert infrastructure for other APT groups, allowing them to mask their origins and route malicious traffic through compromised edge devices, bypassing traditional defenses. The group's investment in multi-platform tools highlights their focus on resilience and evasion, posing a significant blind spot for defenders.
AhnLab ASEC identified phishing emails posing as payment confirmations from Korean companies. These emails contain malicious XLS files that infect systems upon opening.
AhnLab ASEC identified phishing emails disguised as payment confirmation notices. The emails impersonate employees of a Korean company and trick recipients into opening a malicious XLS file.
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as payment confirmation notices.
A multi-stage attack leveraging malicious LNK files and the TON blockchain was discovered by LevelBlue SpiderLabs. The attack begins with a ZIP file containing a Windows shortcut (LNK) that executes a hidden PowerShell command to download a legitimate Node.js binary, which then deploys a backdoor.
The LevelBlue Managed Threat Research team investigated a security alert in a customer environment involving a malicious ZIP file containing a Windows shortcut (.lnk) used for initial execution.