Author: Tekno Phreak
-
Vulnerability & Patch Roundup – November 2024
* [Security Advisory](https://blog.sucuri.net/category/security-advisory)* [Security Education](https://blog.sucuri.net/category/security-education)* [WordPress Security](https://blog.sucuri.net/category/wordpress-security)Vulnerability -& Patch Roundup — November 2024================================================![](https://blog.sucuri.net/wp-content/uploads/2024/07/avatar_user_112_1721420180-60×60.png) [Sucuri Malware Research Team](https://blog.sucuri.net/author/malware-research)* December 20, 2024…
-
Judge rules NSO Group is liable for spyware hacks targeting 1,400 WhatsApp user devices
![NSO Group](https://cms.therecord.media/uploads/small_NSO_GROUP_9c245ee01a.webp?w=3840) [Suzanne Smalley](/author/suzanne-smalley)December 21st, 2024 Judge rules NSO Group is liable for spyware hacks targeting 1,400 WhatsApp user devices=======================================================================================The…
-
Authorities Arrested LockBit Ransomware Developer & Team Core Member
U.S. authorities have unveiled charges against Rostislav Panev, a dual Russian-Israeli national, for his alleged role as a key developer…
-
OSS in the crosshairs: Cryptomining hacks highlight key new threat
![cryptomining-growing-threat-watch](https://www.reversinglabs.com/hs-fs/hubfs/cryptomining-growing-threat-watch.jpg?width=1400&height=732&name=cryptomining-growing-threat-watch.jpg)A dozen packages associated with the popular, open source projects *rspack* and *vant* were compromised this week by threat actors…
-
Holiday Bonus-Themed QR Code-Based Credential Phishing
Author: Kahng AnCofense Intelligence has recently identified a series of end-of-year and holiday bonus-themed credential phishing emails. These are notable…
-
Now You See Me, Now You Dont: Using LLMs to Obfuscate Malicious JavaScript
This article discusses an adversarial machine learning algorithm that uses large language models (LLMs) to generate novel variants of malicious…
-
BellaCPP: Discovering a new BellaCiao variant written in C++
A new C++ variant of the BellaCiao malware, dubbed BellaCPP, has been discovered by researchers. This variant shares similarities with…
-
Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack
Two npm packages, @rspack/core and @rspack/cli, were compromised in a supply chain attack, allowing the publication of malicious versions containing…
-
Recent Cases of Watering Hole Attacks, Part 1
This analysis focuses on a watering hole attack targeting a Japanese university research laboratory website in 2023. The attack used…
-
Threat Actors Hijack Misconfigured Servers for Live Sports Streaming
Aqua Nautilus researchers uncovered a new attack vector where threat actors exploit misconfigured JupyterLab and Jupyter Notebook applications to hijack…