Skip to content

Newsletter

All published 'Cyber Threat Weekly' newsletter issues can be found here.

Members Public

Cyber Threat Weekly – #12

The evolving threat landscape simply doesn’t slow down, although this is a relatively light week.  Let’s start with Ivanti and yet another vulnerability.  Researchers share 2023 Ransomware leak site analysis.  JetBrains critical bug allows an unauthenticated attacker to bypass authentication checks. Volt Typhoon uses small office home office

Members Public

Cyber Threat Weekly – #11

A busy week in threat news.  Let’s start with a new ZLoader variant emerges.  An exploration of Telegram’s dark markets and a phishing expedition.  Criminals actively target network operator’s credentials.  Scanning attempts of Atlassian Confluence RCE Bug. Discovery and analysis of a new DLL Loader.  GitLab releases

Members Public

Cyber Threat Weekly – #10

This week’s newsletter is a bit lighter than earlier this month, although news volumes continue to increase.  Let’s start with exploit attempts on the critical Atlassian Confluence bug disclosed last week.  First zero-day flaw of the year for Apple.  Digging deeper into a pair of malicious traffic direction

Members Public

Cyber Threat Weekly – #9

Another busy news cycle last week.  Let’s start with potential remote code execution in over 178,000 SonicWall firewalls.  This is not good, Ivanti Connect Secure VPN now under mass exploitation.  CISA releases advisory on Androxgh0st malware.  Critical flaw in older versions of Atlassian Confluence Datacenter and Server.  First

Members Public

Cyber Threat Weekly - #8

It got busy last week, a bunch of news to cover.  Let’s start with a new extortion tactic by ransomware clown posse threat actors, cyber criminals suck.  A great piece on bullet proof hosting by Krebs.  Yet another means of extortion for ransomware victims, fake data deletion scam. Honey

Members Public

Cyber Threat Weekly - #7

Kicking off a new week, last week we saw several interesting threats.  Let’s start with a new variation of dynamic link library (DLL) search order hijacking technique.  Next, social engineering through LinkedIn, this is a notable trend.  Black Basta ransomware decryption tool released. Possible Cisco ASA vulnerability for sale

Members Public

Cyber Threat Weekly - #6

First off, Happy New Year, and so it begins…  a new start to another year.  Got to remember to use 2024 instead of 2023.  Let’s begin with Carbanak is back and has been observed in ransomware attacks.  Poorly secured Linux SSH servers actively attacked.  A new version of Medusa

Members Public

Cyber Threat Weekly - #5

Wishing you Happy Holidays, a Merry Christmas, a Happy New Year, all the things.  Kicking it off, over a 3-month period, Blackberry found there was a 70% increase in unique malware hashes from the previous reporting period, about 2.9 unique samples per minute.  A Smishing gang has recently changed

Members Public

Cyber Threat Weekly - #4

As the Threat Landscape continues to evolve…  We continue to track the latest threat trends and adversary behavioral patterns.  Kicking off this week, researchers uncover links between the Sandman threat group and the Chinese government.  Next, Lazarus Group (North Korea) is exploiting vulnerable Internet facing servers using Log4Shell (CVE-2021-44228) and

Members Public

Cyber Threat Weekly - #3

We got quite a bit to cover this week…  Let’s start with malvertising to deploy DanaBot leading to CACTUS ransomware.  A botnet uncovered by Palo Alto is upping its game.  A Russian APT abusing CVE-2023-23397 and other vulnerabilities.  Proofpoint tracking similar behavior from nation state threat actor.  To keep