Menu

Blog

Archive for the ‘cybercrime/malcode’ category: Page 2

Nov 11, 2024

Hackers now use ZIP file concatenation to evade detection

Posted by in category: cybercrime/malcode

Hackers are targeting Windows machines using the ZIP file concatenation technique to deliver malicious payloads in compressed archives without security solutions detecting them.

The technique exploits the different methods ZIP parsers and archive managers handle concatenated ZIP files.

This new trend was spotted by Perception Point, who discovered a a concatentated ZIP archive hiding a trojan while analyzing a phishing attack that lured users with a fake shipping notice.

Nov 11, 2024

Quantum cyber threats are likely years away. Why — and how — we’re working today to stop them

Posted by in categories: cybercrime/malcode, mobile phones, quantum physics

This was Mastercard in March: You probably do it every day without a second thought — shop online with your credit card, or install an update on your phone, or send a confidential file to a co-worker.


Mastercard’s efforts include a pilot to test whether quantum key distribution would work on its complex global network.

Nov 10, 2024

This robot mimics humans, cleans washbasins, completes multiple tasks

Posted by in categories: cybercrime/malcode, robotics/AI

By using sensor-embedded sponges and data, Vienna researchers quickly trained robots to clean washbasins.


Thanks to researchers at TU Wein in Vienna, the promise of housecleaning robots is one step closer. The team has developed a self-learning robot to mimic humans to complete simple tasks like cleaning washbasins.

Continue reading “This robot mimics humans, cleans washbasins, completes multiple tasks” »

Nov 9, 2024

Mysterious Mastercard Data Breach Triggers Bank Warning As Customers Urged To ‘Pay Close Attention’ To Money Movements

Posted by in categories: cybercrime/malcode, economics, finance, government

A US bank is warning customers of a security “intrusion” that may have compromised Mastercard account numbers and other financial data.

Maryland-based Eagle Bank says it has received a notice from Mastercard, stating an unnamed US merchant allowed unauthorized access to account information between August 15th, 2023, and May 25th, 2024.

The bank revealed the breach in a filing with the Massachusetts state government.

Nov 9, 2024

US ‘false flag’ operations pollute global cyberspace

Posted by in categories: cybercrime/malcode, governance, internet

Illustration: Liu Rui/GT

China on Monday released its third report on the “Volt Typhoon” investigation. The report not only provides critical new information but also delivers a clearer message to responsible stakeholders concerned with global cyberspace security and governance: A previously underappreciated threat must be taken seriously. This threat originates from US intelligence agencies and security bodies, which, possessing superior technological capabilities, engage in “false flag” operations — activities carried out to deliberately conceal the true origin of cyberattacks while falsely attributing responsibility to someone else, particularly an opponent. To serve their own interests, these organizations openly or tacitly collaborate with high-tech companies.

The Marble Framework mentioned in the latest investigative report was first exposed in 2017 when WikiLeaks claimed to have obtained information from inside the CIA’s Center for Cyber Intelligence. Developed by the CIA as an anti-forensics tool, the primary function of the Marble Framework is to obscure and disguise the true origins of cyberattacks, making it difficult to trace these attacks back to the actual perpetrators. The Marble Framework employs string obfuscation to hide textual information within the malware, as this text often provides forensic experts with clues to identify the developer or country of origin behind the malicious software.

Nov 9, 2024

U.S. Government Issues New TLP Guidance for Cross-Sector Threat Intelligence Sharing

Posted by in categories: cybercrime/malcode, government

U.S. government updates Traffic Light Protocol guidance to enhance cybersecurity information sharing and collaboration.

Nov 9, 2024

New tool bypasses Google Chrome’s new cookie encryption system

Posted by in categories: cybercrime/malcode, encryption

A researcher has released a tool to bypass Google’s new App-Bound encryption cookie-theft defenses and extract saved credentials from the Chrome web browser.

The tool, named ‘Chrome-App-Bound-Encryption-Decryption,’ was released by cybersecurity researcher Alexander Hagenah after he noticed that others were already figuring out similar bypasses.

Although the tool achieves what multiple infostealer operations have already added to their malware, its public availability raises the risk for Chrome users who continue to store sensitive data in their browsers.

Nov 9, 2024

Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft

Posted by in category: cybercrime/malcode

Chinese botnet Storm-0940 exploits routers, targets Microsoft users with covert password spray attacks.

Nov 9, 2024

New Phishing Kit Xiū gǒu Targets Users Across Five Countries With 2,000 Fake Sites

Posted by in category: cybercrime/malcode

Discover how the new Xiū gǒu phishing kit threatens users in multiple countries since September 2024.

Nov 9, 2024

DDoS site Dstat.cc seized and two suspects arrested in Germany

Posted by in categories: cybercrime/malcode, economics, energy, law enforcement

The Dstat.cc DDoS review platform has been seized by law enforcement, and two suspects have been arrested after the service helped fuel distributed denial-of-service attacks for years.

The seizure and arrests were conducted as part of “Operation PowerOFF,” an ongoing international law enforcement operation that targets DDoS-for-hire platforms, aka “booters” or “stressers,” to seize infrastructure and arrest the operators.

These platforms are responsible for service disruptions to online services and can cause significant economic damages, as well as impact to the operation of critical services, such as healthcare.

Page 2 of 21912345678Last