A Chinese cyber threat actor takes advantage of a Cisco zero-day vulnerability.

A Chinese cyber threat actor takes advantage of a Cisco zero-day vulnerability.

A cyberespionage group called “Velvet Ant,” believed to be aligned with China, recently exploited a zero-day vulnerability in Cisco Nexus devices. This flaw, identified as CVE-2024-20399, allows an attacker to execute arbitrary commands as root on the affected device. According to Sygnia researchers, this exploit led to the deployment of custom malware that enabled remote … Read more

LilacSquid Threat Actor, Backed by Cisco Talos, Launches Worldwide Attack Using PurpleInk Malware against Multiple Sectors

LilacSquid Threat Actor, Backed by Cisco Talos, Launches Worldwide Attack Using PurpleInk Malware against Multiple Sectors

A recent report by Cisco Talos revealed the activities of a cyber espionage threat actor known as LilacSquid, or UAT-4820. LilacSquid targets organizations in various sectors across the US, Europe, and Asia by exploiting vulnerable web applications or using compromised Remote Desktop Protection credentials to infect systems with custom PurpleInk malware. The threat actor has … Read more

Threat Actor Allegedly in Possession of AWS, Azure, MongoDB, and Github API Keys

Threat Actor Allegedly in Possession of AWS, Azure, MongoDB, and Github API Keys

A threat actor claimed to have obtained unauthorized access to API keys for major cloud service providers like Amazon Web Services (AWS), Microsoft Azure, MongoDB, and GitHub. This announcement was made on social media platform X by the DarkWebInformer account. The news has sparked concern within the cybersecurity community, leading affected companies and experts to … Read more