News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Hackers find ways into Google accounts
B2B Cyber ​​Security ShortNews

According to researchers at Cloudsek.com, hackers are abusing an undocumented Google OAuth endpoint called “MultiLogin.” The experts are currently observing that other groups of cyber attackers are copying the technology and using it in their infostealers. Is a bigger wave coming now? Several information-stealing malware families exploit an undocumented Google OAuth endpoint called “MultiLogin” to recover expired authentication cookies and log in to user accounts. Even for accounts where the account password has been reset. Infostealer groups want to exploit the vulnerability The experts at Cloudsek.com report: The Lumma Infostealer, which contains the discovered exploit, was implemented on November 14th...

Read more

NodeStealer 2.0 hijacks Facebook business accounts
B2B Cyber ​​Security ShortNews

Unit 42 researchers recently uncovered a previously unreported phishing campaign that distributed an infostealer capable of completely taking over Facebook business accounts. Facebook business accounts were attacked with a phishing lure that offered tools such as business spreadsheet templates. This is part of a growing trend of attacks targeting Facebook business accounts for ad fraud and other purposes. The trend started in July 2022 with the discovery of the info-stealer Ducktail. Phishing targets Facebook business accounts About eight months later, in March 2023, FakeGPT, a new variant of a fake…

Read more

Malware: Emotet and FormBook at the top
Checkpoint News

Check Point Research (CPR), the research arm of Check Point Software Technologies Ltd., a global leader in cyber security solutions, has released its latest Global Threat Index for August 2022. CPR reports that FormBook is now the most prevalent malware, replacing Emotet, which has held that position since its January resurgence. FormBook is an infostealer that targets Windows operating systems. Once installed, it can intercept credentials, collect screenshots, monitor and log keystrokes, and download and execute (C&C) files according to its commands. Since its initial discovery in...

Read more

Germany affected: espionage with stealer agent Tesla
Kaspersky_news

As Kaspersky has noted, there is a recent campaign by cybercriminals using malware stealer Agent Tesla for espionage. The malware is distributed via well-crafted spam emails. Almost 15.000 users in Germany are already affected. Kaspersky experts have discovered a spam email campaign targeting companies worldwide using the notorious stealer Agent Tesla. For the spam campaign, the cyber criminals imitated e-mails from providers or contractors in detail in order to obtain the login data of the organizations concerned - the cyber criminals only revealed the wrong sender address. These credentials are shared on Darkweb forums...

Read more

Infostealer malware DUCKTAIL targets businesses
Infostealer malware DUCKTAIL targets businesses

WithSecure - formerly F-Secure Business - has detected a new infostealer malware: DUCKTAIL. The malware is delivered via LinkedIn spear phishing and then targets Facebook business accounts. DUCKTAIL targets professionals via LinkedIn spear phishing campaigns to hijack business Facebook accounts. Security researchers from WithSecure™ (formerly F-Secure Business) have discovered an attack campaign dubbed DUCKTAIL targeting individuals and businesses with a Business or Ads account on Facebook. The campaign consists of a malware component that enables information theft and hijacking of Facebook Business. Based on analysis and data collected, WithSecure™ has found that…

Read more