Technology

Dec 23, 2022Ravie LakshmananCyber Espionage / Pakistani Hackers A new targeted phishing campaign has zoomed in on a two-factor authentication solution called Kavach that’s used by Indian government officials. Cybersecurity firm Securonix dubbed the activity STEPPY#KAVACH, attributing it to a threat actor known as SideCopy based on tactical overlaps with prior attacks. “.LNK files are
0 Comments
Google is reportedly working on making Android’s root store updatable via Google Play Store on Android 14. The search giant’s current mechanism updates root certificates only as part of full system updates, which could potentially render devices running on older Android versions unable to connect to the internet when the expired root certificates not being
0 Comments
Samsung Galaxy S23 series has leaked multiple times in the past. The upcoming flagship smartphone lineup from the South Korean tech brand is believed to include the vanilla Samsung Galaxy S23, Galaxy S23+, and Galaxy S23 Ultra. Now, a new report has surfaced suggesting signature shades of the upcoming Samsung Galaxy S23 series phones. The vanilla
0 Comments
Dec 23, 2022Ravie LakshmananRansomware / Endpoint Security The Vice Society ransomware actors have switched to yet another custom ransomware payload in their recent attacks aimed at a variety of sectors. “This ransomware variant, dubbed ‘PolyVice,’ implements a robust encryption scheme, using NTRUEncrypt and ChaCha20-Poly1305 algorithms,” SentinelOne researcher Antonio Cocomazzi said in an analysis. Vice Society,
0 Comments
An exhaustive analysis of FIN7 has unmasked the cybercrime syndicate’s organizational hierarchy, alongside unraveling its role as an affiliate for mounting ransomware attacks. It has also exposed deeper associations between the group and the larger threat ecosystem comprising the now-defunct ransomware DarkSide, REvil, and LockBit families. The highly active threat group, also known as Carbanak,
0 Comments
Dec 22, 2022Ravie LakshmananInternet of Things / Patch Management The Zerobot DDoS botnet has received substantial updates that expand on its ability to target more internet-connected devices and scale its network. Microsoft Threat Intelligence Center (MSTIC) is tracking the ongoing threat under the moniker DEV-1061, its designation for unknown, emerging, or developing activity clusters. Zerobot,
0 Comments
Redmi K60 series will launch soon in China, Lu Weibing, Redmi’s General Manager, confirmed on Thursday after some initial speculations. The Xiaomi executive did not announce the exact launch date and specifications of the models, but a fresh leak suggests that the latest Redmi K-series phones will go official in China on December 27. The
0 Comments
Dec 21, 2022Ravie Lakshmanan The Raspberry Robin worm has been used in attacks against telecommunications and government office systems across Latin America, Australia, and Europe since at least September 2022. “The main payload itself is packed with more than 10 layers for obfuscation and is capable of delivering a fake payload once it detects sandboxing
0 Comments
Dec 21, 2022Ravie LakshmananMobile Security / Banking Trojan An Android banking trojan known as GodFather is being used to target users of more than 400 banking and cryptocurrency apps spanning across 16 countries. This includes 215 banks, 94 crypto wallet providers, and 110 crypto exchange platforms serving users in the U.S., Turkey, Spain, Italy, Canada,
0 Comments
Microsoft has reportedly started testing Windows Subsystem for Android (WSA) on Windows 11 with support for running Android 13 through a beta release. The American conglomerate made the announcement through an official GitHub discussion thread that stated that the Windows Subsystem for Android 13 on Windows 11 is being made available to members who have
0 Comments
Dec 20, 2022Ravie LakshmananBanking Malware / Mobile Security The threat actors behind the Windows banking malware known as Casbaneiro has been attributed as behind a novel Android trojan called BrasDex that has been observed targeting Brazilian users as part of an ongoing multi-platform campaign. BrasDex features a “complex keylogging system designed to abuse Accessibility Services
0 Comments
Dec 20, 2022Ravie LakshmananPrivacy / Data Security Epic Games has reached a $520 million settlement with the U.S. Federal Trade Commission (FTC) over allegations that the Fortnite creator violated online privacy laws for children and tricked users into making unintended purchases in the video game. To that end, the company will pay a record $275
0 Comments
Dec 19, 2022Ravie LakshmananSoftware Security / Supply Chain Cybersecurity researchers have discovered a new malicious package on the Python Package Index (PyPI) repository that impersonates a software development kit (SDK) for SentinelOne, a major cybersecurity company, as part of a campaign dubbed SentinelSneak. The package, named SentinelOne and now taken down, is said to have
0 Comments