Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers – Go Health Pro

Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers – Go Health Pro

Feb 18, 2025Ravie LakshmananMalware / Website Hacking Cybersecurity researchers have flagged a credit card stealing malware campaign that has been observed targeting e-commerce sites running Magento by disguising the malicious content within image tags in HTML code in order to stay under the radar. MageCart is the name given to a malware that’s capable of … Read more

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet – Go Health Pro

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet – Go Health Pro

Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed denial-of-service (DDoS) attacks. According to QiAnXin XLab, the attacks have leveraged the security flaw since June 2024. Additional details about the shortcomings have been withheld to prevent further … Read more

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners – Go Health Pro

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners – Go Health Pro

Jan 13, 2025Ravie LakshmananVulnerability / Cloud Security A recently disclosed critical security flaw impacting the Aviatrix Controller cloud networking platform has come under active exploitation in the wild to deploy backdoors and cryptocurrency miners. Cloud security firm Wiz said it’s currently responding to “multiple incidents” involving the weaponization of CVE-2024-50603 (CVSS score: 10.0), a maximum … Read more

North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign – Go Health Pro

North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign – Go Health Pro

Dec 27, 2024Ravie LakshmananCryptocurrency / Cyber Espionage North Korean threat actors behind the ongoing Contagious Interview campaign have been observed dropping a new JavaScript malware called OtterCookie. Contagious Interview (aka DeceptiveDevelopment) refers to a persistent attack campaign that employs social engineering lures, with the hacking crew often posing as recruiters to trick individuals looking for … Read more

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware – Go Health Pro

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware – Go Health Pro

Dec 17, 2024Ravie LakshmananMalware / Credential Theft A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate. “An attacker used social engineering via a Microsoft Teams call to impersonate a user’s client and gain remote access to their system,” Trend Micro researchers Catherine … Read more

x