News & Updates

Spyware Maker QuaDream Closes Shop after Researchers Blow the Lid off Its Operations

Israel-based QuaDream has closed its office after a piercing analysis of its
operation developing and selling mercenary spyware tools.

Last week, researchers at Citizen Lab and Microsoft jointly blew the lid off
QuaDream’s Reign malware
[https://www.bitdefender.com/blog/hotforsecurity/quadream-reign-spyware-used-to-hack-iphones-of-high-profile-targets/]
infecting the iPhones of at least five civil society members during the
vulnerable days of iOS 14, dating back to 2021.

State-of-the-art spyw

News & Updates

New QBot Campaign Spreads Malware through PDF and Windows Script Files

A new malicious QBot campaign was recently discovered spreading on Windows
devices through PDF and Windows Script Files. The former banking Trojan is
notorious for facilitating initial access to compromised networks for threat
actors.

Perpetrators are historically known to use QBot to deploy additional malware,
such as Cobalt Strike beacons
[https://www.bitdefender.com/blog/hotforsecurity/emotet-deploys-cobalt-strike-beacons-directly-onto-targets-with-new-technique/]
and backdoors, to move lat

News & Updates

The Netherlands: Nearly 2.5 million victims of cyberattacks. The aftermath for your personal data

Cybercrime is no longer something that just happens to “other people” – it’s now
commonplace.

In 2021, nearly 2.5 million people in the Netherlands aged 15 or older (17
percent of the population) said they had fallen victim to cybercrime, according
to a Statistics Netherlands (CBS) report
[https://www.cbs.nl/en-gb/news/2022/09/nearly-2-5-million-people-victims-of-cybercrime-in-2021]
based on the Safety Monitor 2021.

Ten percent – over 1.5 million people – fell victim to online scams and fraud

News & Updates

Iowa Medicaid informs over 20,000 members of data breach

The personal and medical information of 20,800 Iowa Medicaid members was exposed
in a data breach at a third-party vendor managing the state’s health insurance
program.

The breach occurred at a Florida-based company called Independent Living Systems
(ILS). According to a March 14, 2023 notice
[https://ilshealth.com/supplemental-data-notice/], the company learned of
unauthorized access to its systems on July 5, 2022.

“Through our response efforts, we learned that an unauthorized actor obtained

News & Updates

DFIR via XDR: How to expedite your investigations with a DFIRent approach

Rapid technological evolution requires security that is resilient, up to date and adaptable.
In this article, we will cover the transformation in the field of DFIR (digital forensics and incident response) in the last couple years, focusing on the digital forensics’ aspect and how XDR fits into the picture.
Before we dive into the details, let’s first break down the main components of DFIR and
News & Updates

New Qbot campaign delivers malware by hijacking business emails

Cyberattacks that use banking trojans of the Qbot family have been targeting companies in Germany, Argentina, and Italy since April 4 by hijacking business emails, according to a research by cybersecurity firm Kaspersky.

In the latest campaign, the malware is delivered through emails written in English, German, Italian, and French. The messages are based on real business emails that the attackers have gained access to. This gives the attackers the opportunity to join the correspondence thread with messages of their own, Kaspersky said in its report.

To read this article in full, please click here

Cybersecurity Tools

Casino Etiquette And Proper Behavior

Here, I will talk about casino etiquette And proper behavior… Movies have been romanticizing casinos for viewers for a long time. While many of these movies were set in Las Vegas, the casinos that they show are anything but accurate. Not every casino requires players to wear a perfectly tailored tuxedo. Not every player has […]

The post Casino Etiquette And Proper Behavior appeared first on SecureBlitz Cybersecurity.

News & Updates

Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access

The Iranian threat actor known as MuddyWater is continuing its time-tested tradition of relying on legitimate remote administration tools to commandeer targeted systems.
While the nation-state group has previously employed ScreenConnect, RemoteUtilities, and Syncro, a new analysis from Group-IB has revealed the adversary’s use of the SimpleHelp remote support software in June 2022.
MuddyWater,
Exit mobile version