North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign https://firewall.firm.in/wp-content/uploads/2024/12/hacking.png Dec 27, 2024Ravie LakshmananCryptocurrency / Cyber Espionage North Korean threat actors behind the ongoing Contagious Interview campaign have been observed dropping a new JavaScript malware called OtterCookie. Contagious Interview (aka DeceptiveDevelopment) refers to a persistent attack campaign that employs social engineering lures, with the hacking crew often posing as ...
Read More »Vulnerabilities & Exploits
Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately
Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately https://firewall.firm.in/wp-content/uploads/2024/12/palo.png Dec 27, 2024Ravie LakshmananFirewall Security / Vulnerability Palo Alto Networks has disclosed a high-severity vulnerability impacting PAN-OS software that could cause a denial-of-service (DoS) condition on susceptible devices. The flaw, tracked as CVE-2024-3393 (CVSS score: 8.7), impacts PAN-OS versions 10.X and 11.X, as well as Prisma Access running ...
Read More »Brazilian Hacker Charged for Extorting $3.2M in Bitcoin After Breaching 300,000 Accounts
Brazilian Hacker Charged for Extorting $3.2M in Bitcoin After Breaching 300,000 Accounts https://firewall.firm.in/wp-content/uploads/2024/12/brazil.png Dec 26, 2024Ravie LakshmananCybercrime / Ransomware A Brazilian citizen has been charged in the United States for allegedly threatening to release data stolen by hacking into a company’s network in March 2020. Junior Barros De Oliveira, 29, of Curitiba, Brazil has been charged with four counts of ...
Read More »Iran’s Charming Kitten Deploys BellaCPP: A New C++ Variant of BellaCiao Malware
Iran’s Charming Kitten Deploys BellaCPP: A New C++ Variant of BellaCiao Malware https://firewall.firm.in/wp-content/uploads/2024/12/malware.png Dec 25, 2024Ravie LakshmananCyber Attack / Malware The Iranian nation-state hacking group known as Charming Kitten has been observed deploying a C++ variant of a known malware called BellaCiao. Russian cybersecurity company Kaspersky, which dubbed the new version BellaCPP, said it discovered the artifact as part of ...
Read More »CISA Adds Acclaim USAHERDS Vulnerability to KEV Catalog Amid Active Exploitation
CISA Adds Acclaim USAHERDS Vulnerability to KEV Catalog Amid Active Exploitation https://firewall.firm.in/wp-content/uploads/2024/12/software.png Dec 24, 2024Ravie LakshmananVulnerability / Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched high-severity security flaw impacting Acclaim Systems USAHERDS to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild. The vulnerability in question is ...
Read More »Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts
Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts https://firewall.firm.in/wp-content/uploads/2024/12/python.png Dec 24, 2024Ravie LakshmananMalware / Data Exfiltration Cybersecurity researchers have flagged two malicious packages that were uploaded to the Python Package Index (PyPI) repository and came fitted with capabilities to exfiltrate sensitive information from compromised hosts, according to new findings from Fortinet FortiGuard Labs. The packages, named zebo and ...
Read More »North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin
North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin https://firewall.firm.in/wp-content/uploads/2024/12/bitcoin.png Dec 24, 2024Ravie LakshmananCybercrime / Malware Japanese and U.S. authorities have formerly attributed the theft of cryptocurrency worth $308 million from cryptocurrency company DMM Bitcoin in May 2024 to North Korean cyber actors. “The theft is affiliated with TraderTraitor threat activity, which is also tracked as ...
Read More »AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of Case
AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of Case https://firewall.firm.in/wp-content/uploads/2024/12/malware-ai.png Dec 23, 2024Ravie LakshmananMachine Learning / Threat Analysis Cybersecurity researchers have found that it’s possible to use large language models (LLMs) to generate new variants of malicious JavaScript code at scale in a manner that can better evade detection. “Although LLMs struggle to create malware from scratch, ...
Read More »CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List
CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List https://firewall.firm.in/wp-content/uploads/2024/12/cisa.jpg Dec 20, 2024Ravie LakshmananCISA / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The ...
Read More »Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation
Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation https://firewall.firm.in/wp-content/uploads/2024/12/firewall.png Dec 20, 2024Ravie LakshmananFirewall Security / Vulnerability Sophos has released hotfixes to address three security flaws in Sophos Firewall products that could be exploited to achieve remote code execution and allow privileged system access under certain conditions. Of the three, two are rated Critical in severity. There is ...
Read More »
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India











