A post on a cybercrime forum is advertising ready-made phishing projects targeting LastPass and Evernote users for USD 2,500 on monthly rental subscription
Chinese hacker groups and APT groups adhere to phishing, spear-phishing attack vectors against Indian companies, to carry out large volumes of scanning.
Internal ticketing tool Atlassian JIRA's unsecured service desks were publicly exposed, allowing attackers to raise internal tickets for multiple departments.
CloudSEK’s Threat Intelligence team discovered a post, on a cybercrime forum, advertising a scanning tool for the path traversal and file disclosure vulnerability, CVE-2021-41773, in Apache HTTP Server.
We have identified an increase in dark web discussions among threat actors, regarding CRM exploitation tactics and exposure of CRM credentials across code repositories such as Github and Bitbucket
CloudSEK researchers’ investigation discovered that the CoinEgg Scam/cryptocurrency scam was conducted by threat actors. We discovered an on-going malicious scheme involving multiple payment gateway domains and Android-based applications, used to lure unsuspecting individuals into a mass gambling scam.