A cybersecurity company based in Vietnam has reported seeing attacks exploiting a new Microsoft Exchange zero-day vulnerability, but it may just be a variation of the old ProxyShell exploit.
Hackers Possibly From China Using New Method to Deploy Persistent ESXi Backdoors
Hackers possibly from China have been using a new technique to install persistent backdoors in VMware ESXi hypervisors, giving them significant capabilities while making detection more difficult.
Kaiji Botnet Successor ‘Chaos’ Targeting Linux, Windows Systems
Black Lotus Labs, Lumen Technologies’ threat intelligence team, has issued a warning on Chaos, the new variant of the Kaiji distributed denial-of-service (DDoS) botnet, targeting enterprises and large organizations.
High-Profile Hacks Show Effectiveness of MFA Fatigue Attacks
New Infostealer Malware ‘Erbium’ Offered as MaaS for Thousands of Dollars
Security researchers are warning of a new information stealer named Erbium being distributed under the Malware-as-a-Service (MaaS) model.
The threat made its initial appearance in late July, when a Russian speaking threat actor started advertising it on a dark web forum.
Hacktivist Attacks Show Ease of Hacking Industrial Control Systems
Hacktivists might not know a lot about industrial control systems (ICS), but they’re well aware of the potential implications of these devices getting compromised. That is why some groups have been targeting these systems — which are often unprotected and easy to hack — to draw attention to their cause.
Sophos Firewall Zero-Day Exploited in Attacks on South Asian Organizations
UK-based cybersecurity company Sophos has warned customers that a new zero-day vulnerability affecting some of its firewall products has been exploited in attacks.
NSA, CISA Explain How Threat Actors Plan and Execute Attacks on ICS/OT
US government agencies have shared a new cybersecurity resource that can help organizations defend critical control systems against threat actors.
VMware Warns of ‘ChromeLoader’ Delivering Ransomware, Destructive Malware
VMware’s Carbon Black team warns that the ChromeLoader malware is now delivering malware such as ZipBomb and the Enigma ransomware to business services and government organizations.
Free Decryptor Available for LockerGoga Ransomware Victims
Victims of the LockerGoga ransomware can now recover their files for free using a new decryption tool available via the NoMoreRansom project.













