Tag Cloudflare

Iranian Threat Actors Emulate North Korean Job Scam Tactics

Cyberwarfare / Nation-State Attacks , Fraud Management & Cybercrime , Social Engineering Tehran Lures Aerospace Sector with Malicious Job Offers Prajeet Nair (@prajeetspeaks) • November 14, 2024     Image: Shutterstock In a disturbing development, Iranian state-sponsored hackers are reportedly adopting tactics used by their North Korean counterparts to infiltrate…

Read MoreIranian Threat Actors Emulate North Korean Job Scam Tactics

New Cuttlefish Malware Compromises Router Connections to Steal Cloud Credentials

A new cyber threat has emerged, identified as “Cuttlefish,” specifically targeting small office and home office (SOHO) routers. This sophisticated malware aims to covertly monitor all traffic traversing these devices while collecting authentication data from HTTP GET and POST requests. According to a recent report from the Black Lotus Labs…

Read MoreNew Cuttlefish Malware Compromises Router Connections to Steal Cloud Credentials

FlyingYeti Leverages WinRAR Vulnerability to Deploy COOKBOX Malware in Ukraine

Cloudflare Disrupts Phishing Campaign Targeting Ukrainian Entities On Thursday, Cloudflare announced that it has taken measures to disrupt an extensive phishing campaign that has been ongoing for a month. This operation is attributed to a Russia-aligned threat actor known as FlyingYeti, which has specifically targeted Ukraine amidst ongoing tensions in…

Read MoreFlyingYeti Leverages WinRAR Vulnerability to Deploy COOKBOX Malware in Ukraine

New Xiū gǒu Phishing Kit Targets Key Sectors in the UK, US, Japan, and Australia

Cybersecurity experts at Netcraft have identified a sophisticated phishing kit named “Xiū gǒu,” which has been active since September 2024 and is specifically targeting users in multiple countries, including the UK, US, Spain, Australia, and Japan. This malicious toolkit exploits a range of public and private sector services, such as…

Read MoreNew Xiū gǒu Phishing Kit Targets Key Sectors in the UK, US, Japan, and Australia

2024 Permiso State of Identity Security: Major Changes on the Horizon

Identity security has emerged as a pressing concern following a series of significant breaches, with numerous high-profile organizations such as Microsoft, Okta, Cloudflare, and Snowflake experiencing security incidents. This situation has prompted stakeholders to reassess their approaches to identity security from both strategic and technological perspectives. Traditionally, identity security has…

Read More2024 Permiso State of Identity Security: Major Changes on the Horizon

Okta’s Latest Customer Support Data Breach Affected 134 Clients

Identity and authentication management provider Okta has reported a security breach affecting 134 of its 18,400 customers, following a compromise of its support case management system. The breach occurred between September 28 and October 17, 2023. During this period, an unauthorized actor accessed sensitive HAR files that contained session tokens,…

Read MoreOkta’s Latest Customer Support Data Breach Affected 134 Clients

Singapore Banks to Eliminate OTPs for Online Logins in the Next 3 Months

Singapore’s Banking Sector Moves Away from One-Time Passwords Amid Increased Phishing Risks In a significant shift aimed at enhancing cybersecurity, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) announced that retail banks will discontinue the use of one-time passwords (OTPs) for online account authentication…

Read MoreSingapore Banks to Eliminate OTPs for Online Logins in the Next 3 Months

2023 Sees a Remarkable 61,839% Increase in DDoS Attacks Targeting the Environmental Services Sector

Surge in DDoS Attacks Targeting Environmental Services Amid Global Climate Summit The environmental services sector has recently experienced an unprecedented increase in HTTP-based distributed denial-of-service (DDoS) attacks, which accounted for a staggering 50% of all HTTP traffic directed at this industry. This sharp rise, reported by Cloudflare in its fourth-quarter…

Read More2023 Sees a Remarkable 61,839% Increase in DDoS Attacks Targeting the Environmental Services Sector

Over 110,000 Websites Compromised in Polyfill Supply Chain Attack

Polyfill.io Supply Chain Attack Compromises Over 110,000 Websites In a concerning development for e-commerce and web developers, Google has responded to a supply chain attack targeting the widely used Polyfill.io service. The attack follows the acquisition of the domain by a Chinese company, which has modified the JavaScript library "polyfill.js"…

Read MoreOver 110,000 Websites Compromised in Polyfill Supply Chain Attack