RedCurl Corporate Espionage Hackers Return With Updated Hacking Tools

A corporate cyber-espionage hacker group has resurfaced after a seven-month hiatus with new intrusions targeting four companies this year, including one of the largest wholesale stores in Russia, while simultaneously making tactical improvements to its toolset in an attempt to thwart analysis. “In every attack, the threat actor demonstrates extensive red teaming skills and the […]

Ukraine Identifies Russian FSB Officers Hacking As Gamaredon Group

Ukraine’s premier law enforcement and counterintelligence agency on Thursday disclosed the real identities of five individuals allegedly involved in digital intrusions attributed to a cyber-espionage group named Gamaredon, linking the members to Russia’s Federal Security Service (FSB). Calling the hacker group “an FSB special project, which specifically targeted Ukraine,” the Security Service of Ukraine (SSU) […]

Hitler, Mickey Mouse and SpongeBob got COVID-19 vaccination? Valid vaccination certificates generated by hacking the European vaccination passport system

Law enforcement agencies in the European Union are investigating the theft of a private key used by health authorities to issue and sign digital COVID-19 vaccination certificates, which has been distributed in private messaging apps and hacking forums. It should be remembered that this vaccination certificate allows the inhabitants of the European community to demonstrate […]

Apple AirTags can be used as trojan for credential hacking

According to security researcher Bobby Raunch, the attack exploits the way Lost Mode of AirTags is set up. Although Apple’s Bluetooth-enabled item trackers called AirTags are pretty helpful as you can attach important objects like wallets or keys to prevent them from going missing, they are still vulnerable to hacking and not entirely trustworthy. According […]

2 WordPress Nija forms plugins allow hacking millions wordpress websites

Cybersecurity specialists notified WordPress of the detection of two vulnerabilities in the popular Ninja Forms plugin. According to the report, successful exploitation of the flaws could allow malicious hackers to extract sensitive information and send phishing emails from compromised websites. The report, presented by Wordfence, mentions that the flaw in this plugin with more than […]

CVE-2021-36260: Remotely hacking and spying on Hikvision CCTV systems with this zero-click vulnerability

Cybersecurity specialists report the detection of a dangerous “zero-click” vulnerability in a popular security camera model whose exploitation would allow threat actors to gain full access to an affected device and even to the home networks of millions of homes. Tracked as CVE-2021-36260, the vulnerability was described as a remote code execution bug residing in […]

This hacking group infected the largest grain and meat supplier in the U.S. with ransomware; way more dangerous than Colonial Pipeline attack

A representative of the U.S. farmers’ cooperative NEW Cooperative has confirmed that the organization became victim of a BlackMatter ransomware infection. Reportedly, threat actors are reportedly demanding a $5.9 million USD ransom in exchange for handing over the decryption keys and not revealing the compromised information. In addition, hackers have threatened to increase the ransom […]

Israeli spyware used in hacking phones of activists, journalists globally

In groundbreaking research, it has been revealed that governments and regimes around the world used NSO Group’s Pegasus spyware, a company based in Herzliya, Israel. Around 17 media outlets participated in a sweeping investigation on the nefarious activities of Israeli spyware maker NSO Group’s Pegasus spyware. Washington Post reports that investigation revealed the software was […]

Indian call center seized over Amazon hacking scam against US citizens

The call center ran a fake Amazon technical support call center in South Delhi – Now, 26 of its “employees” have been arrested. The Delhi Police have shut down a fake call center alleged to have been operational for the past seven months and scamming US citizens. Allegedly, the call center employees duped US citizens […]

How Russia is hacking German elections using Psychological warfare – PSYOP – Ideological subversion

The German government, through its Foreign Ministry, has filed a complaint against Russian authorities over an alleged attempt to steal confidential information belonging to its lawmakers as part of a potential disinformation campaign leading up to the upcoming election. Andrea Sasse, a foreign ministry spokeswoman, said a hacking group identified as Ghostwriter deployed a “sophisticated […]

SEC Sanctions Several Companies over Email Account Hacking

Earlier this week the SEC (Securities and Exchange Commission) in the USA penalized various companies due to cyber security breakdowns. Hackers took advantage of the mishap to gain unauthorized access to email accounts and lots of customer’s data was exposed. A statement from the SEC read as follows: “According to SEC, it has penalized eight […]

Tetris, Chinese government’s favorite hacking & spying tool. How it works and how to get it?

Cybersecurity specialists report the detection of a web attack structure implemented by an alleged group of Chinese state-sponsored hackers and designed to exploit security flaws in dozens of popular websites in order to gather information about dissidents and opponents of china’s government. Apparently, hackers are attacking at least 57 Chinese websites and the official platforms […]

Unpatched Remote Hacking Flaw Disclosed in Fortinet’s FortiWeb WAF

Details have emerged about a new unpatched security vulnerability in Fortinet’s web application firewall (WAF) appliances that could be abused by a remote, authenticated attacker to execute malicious commands on the system. “An OS command injection vulnerability in FortiWeb’s management interface (version 6.3.11 and prior) can allow a remote, authenticated attacker to execute arbitrary commands […]

Critical vulnerability in SEOPress WordPress plugin allows hacking 100,000 WordPress websites

Cybersecurity specialists report the detection of a cross-site scripting (XSS) vulnerability in SEOPress, a popular WordPress plugin for search engine optimization (SEO), allowing webmasters to manage SEO metadata, social media cards, Google Ads settings and other useful features. Currently this plugin has more than 100 thousand active installations, so this report should be taken seriously. […]