- BellaCPP: Discovering a new BellaCiao variant written in C++by Mert Degirmenci on December 20, 2024 at 10:00 am
While investigating an incident involving the BellaCiao .NET malware, Kaspersky researchers discovered a C++ version they dubbed “BellaCPP”.
- Attackers exploiting a patched FortiClient EMS vulnerability in the wildby Ashley Muñoz, Francesco Figurelli, Cristian Souza, Eduardo Ovalle, Areg Baghinyan on December 19, 2024 at 12:00 pm
Kaspersky’s GERT experts describe an incident with initial access to enterprise infrastructures through a FortiClient EMS vulnerability that allowed SQL injections.
- Lazarus group evolves its infection chain with old and new malwareby Vasily Berdnikov, Sojun Ryu on December 19, 2024 at 10:00 am
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
- Analysis of Cyber Anarchy Squad attacks targeting Russian and Belarusian organizationsby Kaspersky on December 18, 2024 at 10:00 am
Kaspersky experts analyze attacks by C.A.S, a cybergang that uses uncommon remote access Trojans and posts data about victims in public Telegram channels.
- Download a banker to track your parcelby Dmitry Kalinin on December 17, 2024 at 8:21 am
The Mamont banking trojan is spreading under the guise of a parcel-tracking app for fake stores claiming to offer goods at wholesale prices.
- Dark web threats and dark market predictions for 2025by Alexander Zabrovsky, Sergey Lozhkin on December 16, 2024 at 10:00 am
Kaspersky experts review dark market trends in 2024, such as popularity of cryptors, loaders and crypto drainers on the dark web, and discuss what to expect in 2025.
- Careto is back: what’s new after 10 years of silence?by Georgy Kucherin, Marc Rivero on December 12, 2024 at 10:00 am
Kaspersky researchers analyze 2019, 2022 and 2024 attacks attributed to Careto APT with medium to high confidence.
- Story of the Year: global IT outages and supply chain attacksby Alexander Liskin, Vladimir Kuskov, Igor Kuznetsov, Vitaly Kamluk on December 9, 2024 at 10:00 am
While the CrowdStrike incident is still fresh in our minds, Kaspersky experts look back on similar IT outages that happened in 2024 and predict potential threats for 2025.
- Exploits and vulnerabilities in Q3 2024by Alexander Kolesnikov on December 6, 2024 at 10:00 am
The report contains statistics on vulnerabilities and exploits, with an analysis of interesting vulnerabilities found in Q3 2024, such as regreSSHion
- Our secret ingredient for reverse engineeringby Georgy Kucherin on December 5, 2024 at 10:00 am
Kaspersky researchers demonstrate capabilities of hrtng plugin for IDA Pro, share tips on working with IDA and reverse engineer FinSpy malware with these tools.
Securelist
Online Security
The Dark Side of Romance Scams
Microsoft Flags Iranian Cyber Ops
Anomali Threat Intelligence
Cybercrime Hackers Target Australia
The Threat of Cyber Attacks
$50m Fines Cyber Data Breaches
Dallas Ransomware Attack
Hackers Show Mental Health Data
AI is Creating a New Attack Surface
Secure the Cloud
Penetration Testing