Decryptedtech Decryptedtech Decryptedtech Decryptedtech
  • Home
  • Articles
    • News
    • Security Talk
    • Game Thoughts
    • Editorials
    • Shows and Events
    • Leaks and Rumors
    • My Ramblings
    • In Other News
    • Bits, Bytes, and Bourbon
  • Consulting
    • Security Consulting
    • Why Us
    • Services
  • Privacy Policy
  • Archived Items
    • Reviews
      • Enthusiast Gear
        • Motherboards
        • CPUs
        • GPUs
        • Audio
        • Storage and Networking
        • Entusiast Peripherals
      • Pro Gear
        • Motherboards
        • Memory
        • Storage and Networking
      • Consumer Gear
        • Motherboards
        • Audio
        • Storage and Networking
        • Consumer Peripherals
      • Home Theater
      • Mobile Computing
      • Tech Unplugged
      • Gadgets
      • Systems
        • Pro Systems
      • Software and Games
        • Consumer Software
        • Games
      • Peripherals
      • Power and Cooling
  • Bits, Bytes, and Bourbon Store

News

News

Ransomware Group RA Group Is Open for Business in the US and South Korea

There is a new player in the ransomware space. Dubber RA group this new organization appears to have had their grand opening last month (April 2023). RA Group published a data leak site on the dark web as part of the now all too familiar double extortion scheme that most ransomware brings to the table. RA Group is also one of the organizations that has leveraged the Babuk source code links to get things going, as reported by Cisco Talos.

Details
By Sean Kalinich
Sean Kalinich
May 16
Hits: 873
  • Hacking
  • Security
  • Malware
  • Ransomware
  • babuk
  • ra group

Read more: Ransomware Group RA Group Is Open for Business...

No comments on “Ransomware Group RA Group Is Open for Business in the US and South Korea”
News

Attackers using Google’s Golang to Take a Bite Out of Apple

Two new variants of Cobalt Strike written in Ggoogle’s Golang have popped up on the wild internet. According to SentinelOne, this new flavor is set up to target macOS systems. They have also noted that this new beacon (called Geacon) has been popping up on malware review sites like Virus Total in the past few months. The new detections could be part of red-teaming exercises, but the increase seems to indicate that real-world malicious activity is also part of the surge in detections.

Details
By Sean Kalinich
Sean Kalinich
May 16
Hits: 1288
  • Apple
  • Malware
  • macos
  • golang
  • cobaltstrike
  • geacon

Read more: Attackers using Google’s Golang to Take a Bite...

No comments on “Attackers using Google’s Golang to Take a Bite Out of Apple”
News

Cloud Management Systems for Three Industrial Cellular Providers Put OT Environments at Risk

Cybersecurity firm OTORIO has announced several new vulnerabilities in cloud management platforms at Black Hat Asia 2023. The Israeli company named three industrial cellular providers with a total of eleven vulnerabilities which could allow for complete compromise of operational technology devices. These three providers represent a very large number of OT and IIoT (Industrial Internet of Things) devices, making them a serious concern.

Details
By Sean Kalinich
Sean Kalinich
May 15
Hits: 1025
  • Vulnerabilities
  • cloud systems
  • ot
  • iiot
  • otorio
  • sierra wireless
  • inhand networks
  • teltonika networks

Read more: Cloud Management Systems for Three Industrial...

No comments on “Cloud Management Systems for Three Industrial Cellular Providers Put OT Environments at Risk”
News

Discord Discloses Breach from 3rd Party Support Account

The popular socialization platform, Discord, is alerting users to a data breach that occurred due to the compromise of a support agent account. The breach appears to be limited in scope to the ticket queue that the third-party agent was responsible for. The ticket queue contained email addresses, attachments and all messages that might have been exchanged during ticket resolution with this agent.

Details
By Sean Kalinich
Sean Kalinich
May 15
Hits: 716
  • Fraud
  • Data Breach
  • Phishing
  • Messaging
  • discord
  • 3rd party risk

Read more: Discord Discloses Breach from 3rd Party Support...

No comments on “Discord Discloses Breach from 3rd Party Support Account”
News

Because Sharing is Caring Why Shouldn’t Leaked Ransomware Code Not Get Reused?

After a Leak of Babuk ransomware source code in late 2021 researchers have identified 9 separate new stains that are intended to target VMware ESXi. The new variants first started showing up in the 2cond half of 2022. As with ransomware as a service, having leaked source code allows less sophisticated attack groups to utilize the work of others to their advantage. In this case the targeting the Linux based ESXi. ESXi is a great target as it allows for the encryption of infrastructure and prevents the rapid restoration of systems since the infrastructure those servers run on is what has been affected.

Details
By Sean Kalinich
Sean Kalinich
May 11
Hits: 1290
  • Ransomware
  • conti
  • babuk
  • cylance ransomware
  • revil
  • royal

Read more: Because Sharing is Caring Why Shouldn’t Leaked...

No comments on “Because Sharing is Caring Why Shouldn’t Leaked Ransomware Code Not Get Reused?”

More Articles …

  1. When Patching is Not Enough: How Attackers are Looking at Patches to Find the Next Flaw
  2. The Greatness Phishing as a Service Platform Intended to Make Targeting MS365 Easier
  3. Intel Investigating MSI Data Breach and Private Code Signing Key Theft
  4. More Threat Groups Pile onto PaperCut Vulnerability Including State-Sponsored Ones
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19

Page 15 of 570

Follow Us

Follow DecryptedTech on Social Media

facebook twitter linkedin
Decryptedtech