• Skip to primary navigation
  • Skip to main content
GreyKeep Security logo

GreyKeep Security

Expert security for an evolving digital age

  • Services
  • Our Approach
  • Blog
  • About
  • Contact Us
  • Show Search
Hide Search

News

Weekly Malware Roundup – November 13, 2023

greykeep · November 13, 2023 ·

GreyKeep Security Malware Roundup - September 5, 2023

This is the GreyKeep Security Malware Roundup for November 13, 2023. Here’s a summary of what’s in this week’s edition:

Targets

Windows / PowerShell
Linux
MacOS
Android
Google Calendar / Cloud
Atlassian Confluence
Python / PyPI
MOVEit
WinRAR

Organizations

Boeing
Cogdell Memorial Hospital
Isreali Tech Sector
Indian Government
Ukranian Power Grid
Cambodian Government
Fashion Industry
DP World

Threat Actors

BlueNoroff / Lazarus
CIOp
LockBit
Lorenz
Imperial Kitten
Ryuk Ransomware Group
SideCopy
Sandworm
Farnetwork
Saphire Sleet
BulletProofLink
Royal
[Read more…] about Weekly Malware Roundup – November 13, 2023

Cybersecurity Daily: November 2, 2023

greykeep · November 2, 2023 ·

GreyKeep Security Cybersecurity Daily News

Your daily dose of relevant cybersecurity advisories, industry news, and product updates for November 2, 2023.

Alerts & Advisories

  • Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability
  • Urgent: New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes
  • Critical Atlassian Confluence flaw can lead to significant data loss
  • Microsoft Temporarily Disables SketchUp Support After Discovery of 117 Vulnerabilities
  • Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover
  • Cisco Patches 27 Vulnerabilities in Network Security Products
  • New malware campaign uses MSIX packages to infect Windows PCs
  • Safari Side-Channel Attack Enables Browser Theft
  • Hackers Weaponize HWP Documents to Attack Defense and Press Sectors
  • Google Dynamic Search Ads Abused to Unleash Malware ‘Deluge’
  • UAE Cyber Council Warns of Google Chrome Vulnerability
  • Elektra-Leak’ Attackers Harvest AWS Cloud Keys in GitHub Campaign
  • New macOS ‘KandyKorn’ malware targets cryptocurrency engineers
  • Critical Apache ActiveMQ Vulnerability Exploited to Deliver Ransomware
  • Cisco AnyConnect SSL VPN Flaw Let Remote Attacker Launch DoS Attack
  • Researchers Uncover Wiretapping of XMPP-Based Instant Messaging Service
[Read more…] about Cybersecurity Daily: November 2, 2023

Cybersecurity Daily: October 12, 2023

greykeep · October 12, 2023 ·

GreyKeep Security Cybersecurity Daily News

Your daily dose of relevant cybersecurity advisories, industry news, and product updates for October 12, 2023.

Alerts & Advisories

  • Apple fixes iOS Kernel zero-day vulnerability on older iPhones
  • Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin
  • HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks
  • Adobe Acrobat Reader Vuln Now Under Attack
  • Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability
  • Microsoft Patch Tuesday updates for October 2023 fixed three actively exploited zero-day flaws
  • Citrix Devices Under Attack: NetScaler Flaw Exploited to Capture User Credentials
  • Google Chrome Use-after-free Flaw Let Attackers Perform Heap Exploitation
  • LinkedIn Smart Links Abused in Phishing Campaign Targeting Microsoft Accounts
  • Malicious NuGet Package Targeting .NET Developers with SeroXen RAT
  • One-Click ‘Gnome’ Exploit Is a Supply Chain Risk for Linux OSes
  • Looney Tunables’ Linux Flaw Sees Snowballing Proof-of-Concept Exploits
  • High-Severity Flaws in ConnectedIO’s 3G/4G Routers Raise Concerns for IoT Security
  • Patch Now: Massive RCE Campaign Wrangles Routers Into Botnet
  • Ransomware attacks now target unpatched WS_FTP servers
  • A new Magecart campaign hides the malicious code in 404 error page
[Read more…] about Cybersecurity Daily: October 12, 2023

Google Issues Maximum-Severity libwebp Vulnerability

greykeep · September 26, 2023 ·

Neon Google logo on industrial wall
Photo by Mitchell Luo

Google has submitted a new CVE for a vulnerability identified in libwebp, an open-source library for handling images in WebP format. WebP allows for smaller image sizes, reducing download times and improving website performance, and is supported by popular web browsers.

Google initially reported the issue as a flaw in Google Chrome (CVE-2023-4863) with a severity rating of 8.8 (High), but the company subsequently issued the WebP vulnerability under CVE-2023-5129 assigning the maximum severity rating possible – 10/10 (Critical).

[Read more…] about Google Issues Maximum-Severity libwebp Vulnerability

Weekly Malware Roundup – September 25, 2023

greykeep · September 26, 2023 ·

GreyKeep Security Malware Roundup - September 5, 2023

This is the GreyKeep Security Malware Roundup for September 25, 2023. Here’s a summary of what’s in this week’s edition:

Targets

Android
WinRAR
GitHub
GitLab
Azure
Redis
Free Download Manager

Organizations

Azerbaijan
City of Dallas
Middle East telecom
U.S. banks
Latin American banks
Ukrainian Military
Israeli organizations
Political activists/journalists
(Middle East)

Threat Actors

Earth Lusca (China)
Transparent Tribe (Pakistan)
OilRig (Iran)
Stealth Falcon
[Read more…] about Weekly Malware Roundup – September 25, 2023
  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Interim pages omitted …
  • Page 8
  • Go to Next Page »

How can we help you become more secure? Contact Us

GreyKeep Security

© 2025 GreyKeep Security LLC · All Rights Reserved

  • Services
  • Our Approach
  • GreyKeep Security Blog
  • About Us
  • Contact Us