An Israeli government investigation into the use of powerful eavesdropping technology by the police found that they only used it after securing a judicial warrant but that the flood of information exceeded the limits of their authority.
LockBit Ransomware Abuses Windows Defender for Payload Loading
A LockBit ransomware operator or affiliate has been abusing Windows Defender to decrypt and load Cobalt Strike payloads during attacks, according to endpoint security firm SentinelOne.
Australian Man Charged for Developing Imminent Monitor RAT
The Australian Federal Police announced over the weekend that a 24-year-old man has been charged for allegedly creating and selling a piece of spyware named Imminent Monitor (IM).
Organizations Warned of Critical Confluence Flaw as Exploitation Continues
The US Cybersecurity and Infrastructure Security Agency (CISA) has instructed government organizations — and advised private sector companies — to address a recently disclosed Confluence vulnerability that has been exploited in attacks.
Austria Probes Claim Spyware Targeted Law Firms, Banks
Austria said Friday that it was investigating a report that an Austrian company developed spyware targeting law firms, banks and consultancies in at least three countries.
Morocco Detains Frenchman Wanted in US Over Cybercrime: Police Source
Morocco has detained a 21-year-old French national wanted by the United States for alleged involvement in cybercrime, a police source in the kingdom told AFP on Friday, confirming media reports.
Microsoft Connects USB Worm Attacks to ‘EvilCorp’ Ransomware Gang
Cybersleuths at Microsoft have found a link between the recent ‘Raspberry Robin’ USB-based worm attacks and EvilCorp, a notorious Russian ransomware operation sanctioned by the U.S. government.
Malicious Macro-Enabled Docs Delivered via Container Files to Bypass Microsoft Protections
Threat actors are embedding macro-enabled Office documents in container files such as archives and disk images to circumvent a recently rolled-out macro-blocking feature in Microsoft Office.
Governments Ramp Up Demands for User Info, Twitter Warns
Twitter warned Thursday that governments around the globe are asking the company to remove content or snoop on private details of user accounts at an alarming rate.
N Korean APT Uses Browser Extension to Steal Emails From Foreign Policy, Nuclear Targets
Over the past year, North Korean advanced persistent threat (APT) actor Kimsuky has been observed using a browser extension to steal content from victims’ webmail accounts, threat intelligence and incident response company Volexity reports.

