Browsing tag

Digital Forensics

Hackers Using Sneaky HTML Smuggling to Deliver Malware via Fake Google Sites

Cybersecurity researchers have discovered a new malware campaign that leverages bogus Google Sites pages and HTML smuggling to distribute a commercial malware called AZORult in order to facilitate information theft. “It uses an unorthodox HTML smuggling technique where the malicious payload is embedded in a separate JSON file hosted on an external website,” Netskope Threat […]

DarkGate Malware Exploited Recently Patched Microsoft Flaw in Zero-Day Attack

A DarkGate malware campaign observed in mid-January 2024 leveraged a recently patched security flaw in Microsoft Windows as a zero-day using bogus software installers. “During this campaign, users were lured using PDFs that contained Google DoubleClick Digital Marketing (DDM) open redirects that led unsuspecting victims to compromised sites hosting the Microsoft Windows SmartScreen bypass CVE-2024-21412 […]

NYPD loses fingerprint database due to malware infection

According to digital forensics specialists, a company that provides IT services to the New York Police Department (NYPD) accidentally disconnected the database of fingerprints for hours, all due to the use of a mini computer infected with a malware variant. One of the employees of this company was installing a digital screen on the facilities […]

TrendMicro antivirus customers’ information was leaked and sold to online scammers

We must not forget that even specialized companies can suffer cybersecurity incidents. According to digital forensics experts, an employee of Japan-based security firm TrendMicro was discovered stealing information from the company’s customers and selling it to third parties aiming to deploy sophisticated tech support scam campaigns. The targets of this campaign were the company’s customers […]

2000 companies hacked in Georgia. TV channels, government institutions and banks shut down

In an unprecedented event, nearly 2,000 websites in Georgia were hit by a massive cyberattack. According to digital forensics specialists, the organizations most affected include government institutions, digital media platforms and broadcasting companies and even some financial institutions. It all started this Monday morning, with reports of some service failures from some Georgian government websites. […]

London metro, bus & train ticket payment system hacked

Today, any online service or application is exposed to some extent to cyberattacks that, depending on the capabilities of hackers, could lead to information theft or disruption of activities and economic losses. This time, digital forensics specialists report a security incident related to the London public transport system. Transport for London (TFL), the public transport […]

Will other countries follow Kazakhstan in forcing users to install certificates for HTTPS interception?

Experts from multiple digital forensics firms report that the Kazakhstan government has begun intercepting all HTTPS traffic detected within its territory. Internet service providers companies operating in the country have already been warned by the government; from now on, they will have to force their respective customers to install certificates released by the Kazakh authorities […]

5k Bitcoin ATMs worldwide allow money laundering for drug trafficking

The Spanish authorities have stated that the legislation currently in existence in the European community is inadequate and insufficient to prevent the use of Bitcoin ATMs in order to launder money, as mentioned by digital forensics specialists. Various media report that the Spanish government has reached this conclusion after investigating the legal status of cryptocurrency […]

Cyber warfare between the US and Iran has begun

Digital forensics specialists report that the U.S. government has begun a cyberattack campaign against military systems and a cyber espionage network from Iran, after an American military drone was shot down by Iranian agents. President Trump’s administration ordered the attack on Iran in retaliation for the incident with the drone, however, shortly after the U.S. […]

Plurox, the all-in-one malware infecting computers around the world

A few months ago, specialists in digital forensics analysis of security firm Kaspersky analyzed Plurox, a backdoor detected in some attacks that occurred in early 2019, discovering that this malware has some features with high harmful potential. In their research, experts discovered that malware can spread across a local network via an exploit, access the […]

New vulnerabilities found on Linux and FreeBSD devices

Digital forensics services researchers warn that Linux and FreeBSD operating systems contain vulnerabilities that allow hackers to remotely lock servers and disrupt admins’ communications. Operating system distributors have recommended that users install update patches as soon as they are released or otherwise modify the necessary settings to reduce the risk of exploitation. According to digital […]

Multiple vulnerabilities affecting Sierra Wireless AirLink routers

Sierra has launched a security alert mentioning that its AirLink router model, thought for Internet of Things (IoT) applications, are exposed to the exploitation of some known vulnerabilities, reported cyber forensics course specialists. Vulnerabilities affecting AirLink devices are part of a list of 11 critical security flaws in Sierra Wireless routers, published a few days […]

Denial of service condition interrupted power company operations in the U.S.

A denial-of-service condition arose in an electric company supplying energy to various states in the west of the United States; according to cybersecurity specialists, the incident was serious enough for the American energy authority to be notified. The cybersecurity incident generated disruptions in the operation of some electrical systems for more than 10 hours during […]

Hackers steal source code from hundreds of GitHub repositories and demand ransom

According to cyber forensics course specialists, GitHub, open source software development platform, has been the target of a campaign of aggressive cyberattacks. During the attacks, the threat actors removed code repositories and demanded the developers a ransom in exchange for restoring the deleted code. The first reports indicate that the attack would have occurred during […]

Mozilla digital signature verification flaw causes browser extensions fails

Cyber forensics course experts reported a security flaw related to digital signatures in Mozilla that is mainly affecting users of the Tor browser; so far, the company has only mentioned problems with intermediate certificates that have expired. In recent days, Tor users encountered a popup window in the browser mentioning that one of the extensions […]

D-Link WiFi camera vulnerabilities allow access to user recordings

A WiFi camera (model DCS-2123L) designed by the manufacturer D-Link contains critical vulnerabilities that would allow a hacker to intercept and visualize the recordings stored on the device, in addition to altering the firmware, as mentioned by cyber forensics course specialists. The company has not completely corrected the flaws in this camera, which is one […]

SAP vulnerabilities put thousands of companies worldwide at risk

A recent investigation by cyber forensics course specialists has revealed that around 50k companies running SAP company software are more likely to suffer cyberattacks due to the discovery of new methods of exploitation for some old vulnerabilities in these systems that have not been properly corrected. SAP, a leading German software company, mentions that between […]

Vulnerability found in preinstalled tool on Dell computers allows remote access

Cyber forensics course specialists report the presence of a new vulnerability in the SupportAssist tool, of the computer equipment manufacturer Dell; the reported flaw could allow threat actors to execute code with administrator privileges on exposed computers executing non-updated versions of this tool to take control of the victims’ systems. Although the company released a […]

Hackers steal Microsoft Outlook login credentials to steal Bitcoin

Cyber forensics course specialists report that a group of hackers have infiltrated some email accounts from Outlook users to steal several virtual assets, including Bitcoin. The total stolen amount is still unknown, although it is speculated that it could be a considerable sum. One of the victims, a Dutch engineer, claims that a threat actor […]