Alerts List
AL2024_43 New Rockstar 2FA Phishing Service Targets Microsoft 365 Accounts (4th December 2024)
Description Rockstar 2FA is a new phishing-as-a-service (PhaaS) platform facilitating adversary-in-the-middle (AiTM) attacks to compromise Microsoft 3 . . . Read more

Date Publish: Dec 4th 24
AL2024_42 BootKitty UEFI Malware Exploits LogoFAIL to Infect Linux Systems (3rd December 2024)
Description BootKitty is a newly identified UEFI (Unified Extensible Firmware Interface) bootkit targeting Linux systems, exploiting a firmware vulner . . . Read more

Date Publish: Dec 3rd 24
AL2024_41 Hackers Exploit Godot Game Engine to Deploy GodLoader Malware (29th November 2024)
Description Cybercriminals have leveraged the popular open-source Godot game engine to distribute malware through a new tool called GodLoader. This ma . . . Read more

Date Publish: Nov 29th 24
AL2024_40 GhostSpider Malware Analysis (29th November 2024)
Description GhostSpider is a sophisticated backdoor malware employed by the Salt Typhoon hacking group, also known as Earth Estries or UNC2286. This g . . . Read more

Date Publish: Nov 29th 24
AL2024_39 Over 2,000 Palo Alto Firewalls Compromised Using Recently Patched Zero-Day Vulnerabilities (29th No
Description Hackers have exploited two recently patched zero-day vulnerabilities in Palo Alto Networks PAN-OS software, compromising over 2,000 firewa . . . Read more

Date Publish: Nov 29th 24
AL2024_38 MITRE Shares 2024’s Top 25 Most Dangerous Software Weaknesses (22nd November 2024)
Description MITRE has released the 2024 list of the 25 most dangerous and commonly exploited software weaknesses, based on a review of over 31,000 vul . . . Read more

Date Publish: Nov 22nd 24
AL2024_37 Malicious WordPress Plugins: ClickFix and ClearFake Campaigns Compromise Thousands of Sites (24th O
Description WordPress websites are increasingly being targeted by threat actors who install malicious plugins that push information-stealing malware t . . . Read more

Date Publish: Oct 24th 24
AL2024_36 D-Link DIR-846W Routers: Four Critical RCE Flaws Unfixed (03rd September 2024) 
Description   D-Link has issued a warning regarding four Remote Code Execution (RCE) vulnerabilities affecting all hardware and firmware versions of i . . . Read more

Date Publish: Sep 3rd 24
AL2024_35 A New Threat Targeting Windows, Linux, and VMware ESXi Systems (02nd September 2024) 
Description  Cicada3301 is a new ransomware group that targets Windows and Linux systems, especially VMware ESXi environments. They use double-extorti . . . Read more

Date Publish: Sep 2nd 24
AL2024_34 Hackers Exploit AppDomain Manager Injection to Deploy CobaltStrike Beacons (02nd September 2024) 
Description  A new type of cyberattack using a less common technique called AppDomain Manager Injection has been targeting government agencies in Taiw . . . Read more

Date Publish: Sep 2nd 24
AL2024_33 Critical Vulnerability Exploited in LiteSpeed Cache Plugin (23rd August 2024)
Description Hackers have begun exploiting a critical vulnerability in the LiteSpeed Cache plugin, a popular tool used by WordPress websites to enhance . . . Read more

Date Publish: Aug 23rd 24
AL2024_32 Hackers Steal Banking Credentials from iOS, Android Users via PWA Apps (22nd August 2024)
Description Threat actors have started leveraging progressive web applications (PWAs) to impersonate banking apps and steal credentials from both Andr . . . Read more

Date Publish: Aug 22nd 24