Short Summary:

Head Mare is a hacktivist group that emerged in 2023, targeting organizations in Russia and Belarus. They utilize phishing campaigns exploiting vulnerabilities in WinRAR to gain initial access and employ ransomware like LockBit and Babuk to encrypt victims’ data. The group is known for its custom malware, PhantomDL and PhantomCore, and aims to cause significant damage while also demanding ransom for data decryption.…

Read More
Short Summary: Trend Micro discovered a new attack exploiting CVE-2023-22527 in older Atlassian Confluence versions, deploying an in-memory fileless backdoor known as the Godzilla webshell. This vulnerability allows remote code execution, and the Godzilla webshell uses AES encryption for communication, making it difficult for traditional antivirus solutions to detect.…
Read More
Short Summary: The critical vulnerability CVE-2023-22527 is being exploited for cryptojacking, allowing attackers to turn affected systems into cryptomining networks. Methods include deploying shell scripts, targeting SSH endpoints, and maintaining persistence via cron jobs. Organizations are urged to update their Confluence instances and adopt security best practices.…
Read More

Short Summary:

The article discusses the rapid exploitation of critical vulnerabilities, particularly focusing on CVE-2024-27198 in TeamCity On-Premises. Following its disclosure, threat actors quickly attempted to exploit this vulnerability, leading to significant security concerns for organizations using TeamCity. Darktrace’s AI capabilities were instrumental in detecting and responding to these exploitation attempts, highlighting the need for faster detection and response mechanisms in cybersecurity.…

Read More

Threat Actor: ProtonMail | ProtonMail Victim: Users of ProtonMail | Users of ProtonMail Price: Free Exfiltrated Data Type: Email address validity, creation date, public key

Key Points :

ProtonMail provides an API to verify email addresses and retrieve their creation dates. Users can convert Unix timestamps into standard date formats using online converters.…
Read More

Short Summary:

The article discusses the rapid exploitation of critical vulnerabilities, particularly focusing on CVE-2024-27198, a severe authentication bypass vulnerability in TeamCity On-Premises. Following its disclosure, threat actors quickly began exploiting this vulnerability, leading to significant security concerns for organizations using TeamCity. Darktrace’s Cyber AI Analyst detected various malicious activities linked to this vulnerability, including command-and-control (C2) connections and cryptocurrency mining attempts.…

Read More

Short Summary:

Darktrace reported the swift exploitation of a critical vulnerability (CVE-2024-27198) in JetBrains TeamCity, highlighting the urgent need for rapid detection and response to prevent supply chain attacks. Following its public disclosure, threat actors quickly attempted to exploit the vulnerability, leading to malicious activities such as unauthorized access and cryptocurrency mining on affected systems.…

Read More
Short Summary

Server-Side Template Injection (SSTI) vulnerabilities allow attackers to inject malicious code into server-side templates, leading to arbitrary code execution, data theft, and potential server compromise. Recent trends show an increase in critical CVEs affecting various web applications, particularly in sectors like Retail/Wholesale and Finance/Banking.…

Read More

Summary: Wiz Research has uncovered a cryptomining campaign named “SeleniumGreed” that exploits exposed Selenium Grid services due to their lack of default authentication, allowing threat actors to deploy malicious miners. This campaign highlights significant security risks associated with misconfigured Selenium instances in cloud environments, which are prevalent and often overlooked by users.…

Read More

On May 23, 2023, the U.S., Australia, New Zealand, Canada and the U.K. issued a joint advisory about a suspected Chinese state-sponsored threat actor group that infiltrates firewalls, routers and virtual private networks (VPNs) belonging to critical infrastructure organizations. The group is primarily referred to as Volt Typhoon aka BRONZE SILHOUETTE, Dev-0391, Insidious Taurus, Storm-0391, UNC3236, VANGUARD PANDA, VOLTZITE.…

Read More