Month: October 2024


  • Investigating FortiManager ZeroDay Exploitation (CVE202447575)

    A new threat cluster, UNC5820, has been observed exploiting a zero-day vulnerability in FortiManager appliances across multiple industries. The vulnerability…


  • Understanding the Initial Stages of Web Shell and VPN Threats: An MXDR Analysis

    This analysis examines two cybersecurity incidents: a web shell attack and a VPN compromise. The web shell attack involved uploading…


  • New Bumblebee Loader Infection Chain Signals Possible Resurgence

    A new infection chain for the Bumblebee loader malware has been discovered, potentially indicating its resurgence after Operation Endgame. The…


  • Inside the Latrodectus Malware Campaign

    The Latrodectus malware campaign employs a combination of traditional phishing techniques and innovative payload delivery methods to target financial, automotive,…


  • Analyzing the familiar tools used by the Crypt Ghouls hacktivists

    The Crypt Ghouls group is targeting Russian businesses and government agencies with ransomware attacks. They utilize a toolkit including utilities…


  • Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login Credentials

    ![Roundcube Webmail XSS Vulnerability](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoZuKNtFMMlMGAzijsvtVIkOReCPQTeJQlNx_ouQDXZPe1bFEDX3lEkVxauO40AhwqKaYCLIVYDBZumIsW5ERKfUQ9CvB-OVg10Dr0keC8ojAJ_jK6KTwQtKd8fblcO0FuXgMTWXotoCd9KgWPdsesmLTufSCkRLVNrWAv-25SZravKdgDF6jCNuNc6X0T/s728-rw-e365/roundcube.png ‘Roundcube Webmail XSS Vulnerability’)Unknown threat actors have been observed attempting to exploit a now-patched security flaw…


  • North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data

    ![North Korean IT Workers](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilleKZkFdelhDoVbNhtZtk-Ocl5bfbSbxUpCYLe3LmMAR6nFV6UNyetmh2-KEP4fcVCTvOH8l_2iP5ihfoI2SUyCd6Zd6r4rr-bVmhhXnnE8Pa8MnNjp9QqxU1dFVrFIhrVLuSK06XVj1hLL-7fPh6fttYL-BQb553fYZzN2SXkR930MaLhyphenhyphen1MPBTNHZW4/s728-rw-e365/server.png ‘North Korean IT Workers’)North Korean information technology (IT) workers who obtain employment under false identities in…


  • Cobalt Strike Beacon Detected – 122[.]51[.]105[.]65:8085

    * [Cobalt Strike](https://www.redpacketsecurity.com/category/cobalt-strike/)Cobalt Strike Beacon Detected — 122-[.-]51-[.-]105-[.-]65:8085===============================================================[October 20, 2024](https://www.redpacketsecurity.com/2024/10/) Cobalt Strike Beacon Detection Alerts > The Information provided at…


  • Cobalt Strike Beacon Detected – 124[.]71[.]192[.]162:443

    * [Cobalt Strike](https://www.redpacketsecurity.com/category/cobalt-strike/)Cobalt Strike Beacon Detected — 124-[.-]71-[.-]192-[.-]162:443===============================================================[October 20, 2024](https://www.redpacketsecurity.com/2024/10/) Cobalt Strike Beacon Detection Alerts > The Information provided at…


  • Cobalt Strike Beacon Detected – 116[.]198[.]229[.]197:6666

    * [Cobalt Strike](https://www.redpacketsecurity.com/category/cobalt-strike/)Cobalt Strike Beacon Detected — 116-[.-]198-[.-]229-[.-]197:6666=================================================================[October 20, 2024](https://www.redpacketsecurity.com/2024/10/) Cobalt Strike Beacon Detection Alerts > The Information provided at…