October 2021

Millions of Android Users are Currently Targets of Premium Scam Apps

Attackers are leveraging on 151 malicious Android apps with 10.5 million downloads in order to rope users into premium subscription service without consent and knowledge. This attack has been dubbed “UltimaSMS” and is believed to have commenced in May 2021. This attacker took advantage of apps covering wide range of categories including keyboards, QR code […]

Millions of Android Users are Currently Targets of Premium Scam Apps Read More »

Google Releases Emergency Update Patching Exploited Bugs

An emergency update for Chrome web browser fixing two zero-day vulnerabilities has been released. The vulnerability is tracked as CVE-2021-38000 and CVE-2021-38003 and relates to insufficient validaton of untrusted input in a feature called Intents and inappropriate implentation in V8 JavaScript and WebAssembly engine. This flaw was discovered and reported by Threat Analysis Group (TAG)

Google Releases Emergency Update Patching Exploited Bugs Read More »

Microsoft Cautions on TodayZoo Phishing Kit Used in Credential Stealing Attacks

An extensive series of credential phishing campaigns has been discovered and disclosed by Microsoft on Thursday. This campaign is taking advantage of custom phishing kit that stitched together components from at least five different circulated ones with the aim of siphoning user login information. This discovery was first made in December 2020 and dubbed the

Microsoft Cautions on TodayZoo Phishing Kit Used in Credential Stealing Attacks Read More »

Afghanistan and India are the new Targets of Hacker Group with Commodity RATs

A hacker group is now targeting Afghanistan and India as they exploit a now-patched, 20-year-old flaw affecting Microsoft Office to deploy remote access trojans (RATs) that allow the adversary gain complete control over the compromised endpoints. This has been attributed to a “lone wolf” threat actor operating a Lahore-based fake IT company called Bunse Technologies

Afghanistan and India are the new Targets of Hacker Group with Commodity RATs Read More »

OSINT: All You Need To Know

OSINT is intelligence “drawn from publicly available material”, according to the CIA. Most intelligence experts extend that definition to mean information intended for public consumption. The CIA says that OSINT includes information gathered from the internet, mass media, specialist journals and research, photos, and geospatial information. Most of these sources were used in the Bellingcat

OSINT: All You Need To Know Read More »