VTA

'V3G4' The New Variant of Mirai Botnet Targeting Linux Devices

‘V3G4’ The New Variant of Mirai Botnet Targeting Linux Devices

VTA-00435 – ‘V3G4’ The New Variant of Mirai Botnet Targeting Linux Devices A new variant of the Mirai botnet has been discovered that utilizes several security vulnerabilities to infect Linux and IoT devices. Palo Alto Networks Unit 42 identified the … Read More

New APT Group Found Targeting Government Organizations in APAC

VTA-00434 – New APT Group Found Targeting Government Organizations in APAC These threat actors are leveraging a new set of tactics, techniques, and procedures rarely utilized by previously known APT groups. They leverage a custom toolkit, featuring TelePowerBot, KamiKakaBot, and Cucky and Ctealer information … Read More

Microsoft Patch Tuesday – Patches for 3 Actively Exploited Windows Vulnerabilities

VTA-00433 – Microsoft Patch Tuesday – Patches for 3 Actively Exploited Windows Vulnerabilities Microsoft has released their monthly Tuesday patch which addresses 75 flaws spanning its product portfolio, three of which have come under active exploitation in the wild. These … Read More

The Royal Ransomware Linux Variant Targets VMware ESXi OpenSLP Vulnerability

VTA-00432 – The Royal Ransomware Linux Variant Targets VMware ESXi OpenSLP Vulnerability In targeted callback phishing attempts, the Royal Group poses as software and food delivery companies in emails that appear to be subscription renewals. These phishing emails contain phone … Read More

OpenSSH Releases Patch for New Pre-Auth Double Free Vulnerability

VTA-00431 – OpenSSH Releases Patch for New Pre-Auth Double Free Vulnerability OpenSSH has released version 9.2 to address security bugs, including a memory safety vulnerability in the OpenSSH server (sshd). The vulnerability, tracked as CVE-2023-25136, has been classified as a … Read More

New shc-based Linux Malware Targeting Systems with Cryptocurrency Miner

VTA-00430 – New shc-based Linux Malware Targeting Systems with Cryptocurrency Miner A new Linux malware developed using the shell script compiler (shc) has been observed deploying a cryptocurrency miner on compromised systems. It is presumed that after successful authentication through … Read More

Empowering the Cybersecurity and Cloud Security Industry Together

Empowering the Cybersecurity and Cloud Security Industry Together We are thrilled and humbled to have Cyber100 Cohort 3 committee members (NACSA, MDEC, MAMPU, MCMC, MyDigital EPU KKOMM) to visit our office yesterday. We did not see this visit as sales … Read More

APT Actor Spread AppleJeus Malware Disguised as Cryptocurrency Apps

VTA-00429 – APT Actor Spread AppleJeus Malware Disguised as Cryptocurrency Apps The Lazarus Group threat actor has been observed leveraging fake cryptocurrency apps as a lure to deliver a previously undocumented version of the AppleJeus malware, according to new findings … Read More

New Browser-in-the-Browser (BitB) Attack Steal User Credentials

New Chrome Browser Update to Patch Yet Another Zero-Day Vulnerability (CVE-2022-4262)

VTA-00428 – New Chrome Browser Update to Patch Yet Another Zero-Day Vulnerability (CVE-2022-4262) Recently, Google has released an out-of-band security update to fix a new actively exploited zero-day flaw in its Chrome web browser. The high-severity flaw, tracked as CVE-2022-4262, concerns … Read More