Tag: Cyberattack

Detecting QakBot Malware Campaign Leading to Black Basta Ransomware Infections 3 min read Latest Threats Detecting QakBot Malware Campaign Leading to Black Basta Ransomware Infections by Daryna Olyniychuk Earth Preta aka Mustang Panda Attack Detection: Abused Fake Google Accounts in Spear-Phishing Campaigns Targeting Governments Worldwide  4 min read Latest Threats Earth Preta aka Mustang Panda Attack Detection: Abused Fake Google Accounts in Spear-Phishing Campaigns Targeting Governments Worldwide  by Veronika Telychko Somnia Malware Detection: UAC-0118 aka FRwL Launches Cyber Attacks Against Organizations in Ukraine Using Enhanced Malware Strains 4 min read Latest Threats Somnia Malware Detection: UAC-0118 aka FRwL Launches Cyber Attacks Against Organizations in Ukraine Using Enhanced Malware Strains by Veronika Telychko Armageddon APT Hacker Group aka UAC-0010 Spreads Phishing Emails Masquerading as the State Special Communications Service of Ukraine 3 min read Latest Threats Armageddon APT Hacker Group aka UAC-0010 Spreads Phishing Emails Masquerading as the State Special Communications Service of Ukraine by Veronika Telychko PURPLEURCHIN Campaign Detection: A New Crypto Mining Operation Massively Abuses GitHub Actions and Other Popular Free CI/CD Service Accounts   3 min read Latest Threats PURPLEURCHIN Campaign Detection: A New Crypto Mining Operation Massively Abuses GitHub Actions and Other Popular Free CI/CD Service Accounts   by Veronika Telychko RomCom Backdoor Detection: Cyber Attack on Ukrainian State Bodies Attributed to Cuba Ransomware Operators aka Tropical Scorpius (UNC2596) Group 4 min read Latest Threats RomCom Backdoor Detection: Cyber Attack on Ukrainian State Bodies Attributed to Cuba Ransomware Operators aka Tropical Scorpius (UNC2596) Group by Veronika Telychko On Demand Subscription: Drive Immediate Value From SOC Prime Platform 4 min read SOC Prime Platform On Demand Subscription: Drive Immediate Value From SOC Prime Platform by Veronika Telychko BlackByte Ransomware Detection: Threat Actors Exploit CVE-2019-16098 Vulnerability in RTCore64.sys Driver to Bypass EDR Protection 3 min read Latest Threats BlackByte Ransomware Detection: Threat Actors Exploit CVE-2019-16098 Vulnerability in RTCore64.sys Driver to Bypass EDR Protection by Veronika Telychko ProxyNotShell: Detecting CVE-2022-41040 and CVE-2022-41082, Novel Microsoft Exchange Zero-Day Vulnerabilities Actively Exploited in the Wild 3 min read Latest Threats ProxyNotShell: Detecting CVE-2022-41040 and CVE-2022-41082, Novel Microsoft Exchange Zero-Day Vulnerabilities Actively Exploited in the Wild by Veronika Telychko Top Challenges for MSSPs and MDRs and How to Overcome Them 8 min read SIEM & EDR Top Challenges for MSSPs and MDRs and How to Overcome Them by Oleksandra Rumiantseva