Tag Trend Micro

Kinsing Hackers Use Apache ActiveMQ Flaw to Deploy Linux Rootkits

A significant cybersecurity threat has emerged as the Kinsing group exploits a severe vulnerability in Apache ActiveMQ servers, leading to infections of Linux systems with cryptocurrency miners and rootkits. This critical flaw is identified as CVE-2023-46604, categorized as having a maximum CVSS score of 10.0, which allows remote code execution.…

Read MoreKinsing Hackers Use Apache ActiveMQ Flaw to Deploy Linux Rootkits

AI-Powered Attacks and the Future of Cybersecurity

Artificial intelligence is significantly transforming the landscape of cybercrime. According to David Sancho, a senior threat researcher at Trend Micro, autonomous AI agents are on the verge of conducting entire cyber attacks independently. These advanced algorithms can scan servers, identify vulnerabilities, refine exploit techniques, and even execute phishing campaigns from…

Read MoreAI-Powered Attacks and the Future of Cybersecurity

New Critical RCE Vulnerability Identified in Apache Struts 2 – Update Immediately

Apache Software Foundation has issued a security advisory regarding a critical vulnerability within the Struts 2 open-source web application framework, posing a significant risk for remote code execution (RCE). This vulnerability, designated as CVE-2023-50164, stems from inadequate “file upload logic” that permits unauthorized path traversal. If exploited, attackers can upload…

Read MoreNew Critical RCE Vulnerability Identified in Apache Struts 2 – Update Immediately

US Government Issues Warning About New Strain of Chinese ‘Taidoor’ Virus

Recent disclosures from US intelligence agencies reveal an alarming resurgence of a 12-year-old strain of malware, known as “Taidoor.” This variant is believed to be employed by state-sponsored actors from China, targeting a wide array of institutions, including government bodies, corporations, and think tanks. The malware, which has been active…

Read MoreUS Government Issues Warning About New Strain of Chinese ‘Taidoor’ Virus

Hackers Impersonate Recruiters to Target Employees of Defense Contractors

The Cybersecurity and Infrastructure Security Agency (CISA) in the United States has issued an alert regarding a sophisticated malware campaign attributed to North Korean hackers targeting government contracting firms. This new threat, identified as “BLINDINGCAN,” utilizes an advanced remote access Trojan designed to create a backdoor into compromised systems. The…

Read MoreHackers Impersonate Recruiters to Target Employees of Defense Contractors

Microsoft’s January 2024 Windows Update Addresses 48 New Vulnerabilities

In a significant update released for January 2024, Microsoft has patched a total of 48 security vulnerabilities across its software ecosystem. This month’s Patch Tuesday includes two flaws classified as Critical and 46 as Important. Notably, there are no indications that any of these vulnerabilities are being actively exploited or…

Read MoreMicrosoft’s January 2024 Windows Update Addresses 48 New Vulnerabilities

Microsoft Releases Fixes for 73 Vulnerabilities, Including Two Windows Zero-Day Exploits

In its February 2024 Patch Tuesday updates, Microsoft has issued fixes for 73 security vulnerabilities across its software ecosystem, including two zero-day flaws currently under active exploitation. Among these vulnerabilities, five have been categorized as Critical and 65 as Important, while three have a Moderate severity rating. This release also…

Read MoreMicrosoft Releases Fixes for 73 Vulnerabilities, Including Two Windows Zero-Day Exploits

Targeted Phishing Attacks Hit Senior Executives at Major Companies

A sophisticated phishing campaign observed since May 2020 has been increasingly targeting corporate leaders across various sectors, including manufacturing, real estate, finance, government, and technology. The primary objective is to extract sensitive information from these high-ranking individuals. This campaign employs social engineering techniques, specifically by sending emails that falsely notify…

Read MoreTargeted Phishing Attacks Hit Senior Executives at Major Companies

DarkGate Malware Targets Recently Patched Microsoft Vulnerability in Zero-Day Attack

A recently identified malware campaign, dubbed DarkGate, has raised alarms in the cybersecurity community. It exploits a now-patched security vulnerability in Microsoft Windows, known as CVE-2024-21412, which was used as a zero-day attack vector through fraudulent software installers. This incident was first observed in mid-January 2024, wherein attackers deceived users…

Read MoreDarkGate Malware Targets Recently Patched Microsoft Vulnerability in Zero-Day Attack