A new threat actor, dubbed Tangerine Turkey by Red Canary’s intelligence team, is attracting attention thanks to its sophisticated use of a Visual Basic Script (VBScript) worm that delivers a crypto mining payload. First seen in November last year, Tangerine Turkey’s malicious activity is evolving, and by December 2024, it had cracked Red Canary’s top 10 threat rankings. The worm, which spreads via USB devices, is part of a much broader and growing crypto-mining campaign that has targeted victims worldwide. What is Tangerine Turkey? Tangerine Turkey uses a series of technical steps to execute its payload: Research into the execution…
Kirsten Doyle
Security leaders often have a narrow view of human-element breaches, thinking of them as either social engineering or human error, but there’s more to it than that. Breaches that start with a person can be divided into broader categories, including security culture, insider threats, and emerging attack methods such as phishing and data exfiltration. This was one of the findings in Forrester’s new research report, Deconstructing Human-Element Breaches, which takes a look at the multifaceted risks posed by and to humans in cybersecurity. It also highlights how these long-standing challenges continue to affect security teams, and offers a structured framework…
The US Department of Justice (DoJ) and the Dutch National Police have seized 39 domains linked to a Pakistan-based cybercrime network operated by a group known as Saim Raza, or HeartSender. The sites sold malicious tools to transnational organized crime groups. According to an affidavit supporting the seizures, the Saim Raza network had been active since at least 2020, peddling phishing toolkits and other fraudulent resources to malefactors who used them to target victims in the States. The DoJ estimates that these activities have resulted in more than $3 million in financial losses. The seized domains acted as dark marketplaces…
As artificial intelligence (AI) continues to transform industries, governments worldwide are racing to implement regulations that ensure its safe and ethical use. From the OECD AI Principles to the EU AI Act, new frameworks set new expectations for transparency, accountability, and risk management. However, when it comes to businesses integrating AI into their cybersecurity strategies, compliance is anything but straightforward. We spoke to industry experts to explore how organisations can align their AI-driven cybersecurity practices with evolving global regulations. We also asked what challenges businesses face when navigating compliance across multiple jurisdictions and how AI regulations can help mitigate the…
Chinese artificial intelligence (AI) startup DeepSeek, which has taken the market by storm, has temporarily limited new user registrations following a large-scale cyberattack that disrupted its services. According to Reuters, the attack coincided with the company’s AI assistant becoming the top-rated free application on Apple’s App Store in the United States. The attack affected the registration process for new users, although current users were able to carry on accessing the platform as usual. The company said that it had resolved issues related to its application programming interface (API) and user login problems, marking the longest service outage in around 90…
Salt Labs has discovered an account takeover vulnerability in a widely used online travel service that facilitates hotel and car rental bookings. This service is integrated into a slew of commercial airline platforms, allowing users to seamlessly add accommodations to their airline itineraries. By exploiting this flaw, malicious actors could gain unauthorized access to any user account within the system, enabling them to impersonate victims and carry out various actions on their behalf. This includes booking hotels and rental cars using the victim’s airline loyalty points, modifying or canceling reservations, and more. The vulnerability could be triggered through a malicious link that…
Every year, 28 January marks Data Privacy Day, a global event dedicated to championing the importance of data protection and privacy in our increasingly digital, connected world. Established by the Council of Europe in 2006, this day commemorates the anniversary of Convention 108, the first binding international treaty on data protection. The purpose of the Convention was: “To secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him.” Over the…
In a newly discovered phishing campaign, malicious actors are using malicious PDF files to target mobile device users in potentially more than 50 countries. Dubbed the “PDF Mishing Attack,” the campaign exploits the widespread trust in PDFs as a secure file format, revealing new vulnerabilities in mobile platforms. The phishing operation masquerades as the United States Postal Service (USPS) to gain the trust of users and fool recipients into downloading the malicious PDFs. Once opened, the hidden links redirect victims to phishing pages that are designed to steal credentials. Exploiting Humans According to Zimperium’s zLabs team, who discovered the campaign,…
Homebrew, the popular open-source macOS and Linux package manager has become the latest victim of a malvertising campaign to distribute information-stealing malware. Security researcher Ryan Chenkie uncovered the scheme, which leverages fake Google ads to deliver malware that compromises user credentials, browser data, and cryptocurrency wallets. The Malware Behind the Campaign AmosStealer (Atomic), a notorious information-stealing malware designed to target macOS systems, is the malicious software at the center of this campaign. Sold as a subscription service for only $1,000 per month, AmosStealer has become a popular tool among malefactors targeting Apple users. It has also been spotted in other…
In a new and ongoing large-scale cyber campaign, Qualys researchers have uncovered a variant of the infamous Mirai botnet called the Murdoc Botnet. This variant exploits vulnerabilities in widely used AVTECH Cameras and Huawei HG532 routers, allowing malicious actors to compromise devices and build vast botnet networks for additional malicious activities. “The Mirai botnet was first publicly identified in late August 2016, and its effects are still felt today,” says Jason Soroko, Senior Fellow at Sectigo. “The threat actors have identified widespread entry points into enterprise and consumer networks, demonstrating that a single outdated or unpatched device can compromise an…
