Cybercrime Group Deploys EDRKillShifter Tool to Disable EDR Software on Compromised Hosts
RansomHub ransomware group utilizes EDRKillShifter tool to exploit vulnerabilities and disable endpoint detection and response software on targeted computers.
RansomHub ransomware group utilizes EDRKillShifter tool to exploit vulnerabilities and disable endpoint detection and response software on targeted computers.
Researchers at Palo Alto Networks’ Unit 42 uncover ArtiPACKED vulnerability in GitHub Actions artifacts, posing a significant threat to repository security for major companies like Google, Microsoft, and Amazon Web Services.
A new variant of the Gafgyt botnet is exploiting weak SSH passwords on cloud servers for cryptocurrency mining using GPU computing power.
Russian-aligned cyber espionage squads Coldriver and Coldwastrel have been conducting a sophisticated spear phishing campaign against Western and Russian civil society entities for two years.
COLDRIVER and COLDWASTREL, Russian-aligned cyber espionage squads, have been targeting non-profit organizations, independent media, and international NGOs in Eastern Europe, Russia, Europe, and the US through a sophisticated spear-phishing campaign.
ValleyRAT malware poses a significant threat to Chinese-speaking individuals and industries, utilizing shellcode, sleep obfuscation, XOR encoding, AES-256 decryption, reflective DLL loading, API hashing, and callback procedures to evade detection and control victims.