Cyber Threat Intelligence Unit of BGD e-GOV CIRT has detected a suspicious ongoing phishing campaign by APT group named as SideWinder targeted at Bangladeshi entities such as Bangladesh Armed Forces Division (AFD) and Law Enforcement Agencies. The group is known as a highly active hacker group who has shown the …
Read More »BD CIRT REPORT
2024 strong start
Google’s Mandiant recover its x (twitter) account after hacked
Google’s cybersecurity firm Mandiant get back its x (twitter) account after being taken over by someone sharing links to a cryptocurrency platform. On Wednesday afternoon around 3:30 pm EST, the scammar took the control over mandiant’s x account, renamed it as phantom and tweeted out links to a company called …
Read More »
Shadowserver report
Nearly 11 million SSH servers vulnerable to Terrapin attacks
Around 11 million SSH servers are at risk from the Terrapin attack, which can compromise the security of certain SSH connections. This constitutes roughly 52% of all scanned samples in the IPv4 and IPv6 space monitored by Shadoserver. The Terrapin attack, created by researchers from Ruhr University Bochum in Germany, …
Read More »
Have a quick check
X (twitter) gold accounts flood dark web to sell
Cybercriminals have increased the sale of new or stolen Gold checkmarked accounts from the X/Twitter platform. These accounts are being used by threat actors to share links to malware on the social media site, making it appear as a post from a trusted source. Researchers at CloudSEK in Singapore have …
Read More »
Across 61 countries
29 malware families target 1,800 banking apps worldwide
The research uncovered that 29 malware families targeted 1,800 banking applications across 61 countries last year. In comparison, the 2022 report uncovered 10 prolific malware families targeting 600 banking apps. Traditional banking apps are the main target, with 1,103 compromised apps, accounting for 61% of the total. FinTech and Trading …
Read More »
To sell over 160 million records
Mysterious hacker strikes Iran with 23 organizations: Hudson Rock
Hudson Researchers reported that on December 20th, ‘irleaks’ claimed to have 160 million records from 23 top insurance companies in Iran for sale. The hacker says they have stolen data like names, birth dates, phone numbers, national codes, and more. They have shared a sample of the data and want …
Read More »
Anonymous Collective claim
Anonymous Collective claim attack on Bahrain’s E Visa Service
Hacktivist group, Anonymous Collective claim to cyber attack the E Visa service of the Bahrain government. The cyberattack on Bahrain government has raised concerns about the cyber security arena of sensitive data protection. The hacktivist group shared a screen shot of attack of the E Visa services on their social …
Read More »
“Leaksmas” Event
Dark Web Expose Massive Volumes Of Leaked PII And Compromised Data
On Christmas Eve, Resecurity protecting Fortune 100 and government agencies worldwide, noticed that multiple actors on the Dark Web were leaking a large amount of data. More than 50 million records containing personal information about consumers from different countries were leaked. The damage caused by this could potentially be worth …
Read More »
Microsoft warn
New ‘FalseFont’ Backdoor Target Defense Sector
Microsoft warn Iranian threat actor has targeted organizations in the Defense Industrial Base (DIB) sector with a campaign involving a new type of backdoor called FalseFont. Microsoft found the activity related to Peach Sandstorm (previously known as Holmium), also called APT33, Elfin, and Refined Kitten. FalseFont is a type of …
Read More »
ReversingLabs report
Hackers Abusing GitHub Platform Hosting Malware
Researchers found two new techniques on GitHub. One uses GitHub Gists, and the other uses Git commit messages to send commands. Malware creators sometimes upload their malware to Dropbox, Google Drive, OneDrive, and Discord to hide it and avoid being detected. ALSO READ: Fake security researchers push malware files on …
Read More »