Remove 03
article thumbnail

EnemyBot malware adds new exploits to target CMS servers and Android devices

Security Affairs

The first version of the bot exploits tens of known vulnerabilities including: CVE-2020-17456 vulnerability affecting SEOWON INTECH SLC-130 and SLR-120S routers; CVE-2018-10823 flaw an older D-Link routers (DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, DWR-111 through 1.01).

CMS 141
article thumbnail

Apr 10 – Apr 16 Ukraine – Russia the silent cyber conflict

Security Affairs

Threat actors are targeting Ukrainian government organizations with exploits for XSS vulnerabilities in Zimbra Collaboration Suite (CVE-2018-6882). Apr 03 – Apr 09 Ukraine – Russia the silent cyber conflict. April 15 – Threat actors use Zimbra exploits to target Ukrainian organizations.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

[SI-LAB] EMOTET spread in Chile impacted hundreds of users and targeted financial and banking services

Security Affairs

The latter leverages the WinRar/Ace vulnerability ( CVE-2018-20250 ) dropping the malware itself into the Windows startup folder. The second malware phase ( denuncias.rar ) ; which used WinRar/Ace vulnerability ( CVE-2018-20250 ) to drop the malware itself was uploaded by criminals to the opendir C2 server on March 18th, 2019.

article thumbnail

The Evolution of Aggah: From Roma225 to the RG Campaign

Security Affairs

Few weeks ago, Unit42 discovered another active campaign , compatible with the Roma225 one we tracked on December 2018, pointing to some interesting changes into the attackers TTPs. Since December 2018, we are following the tracks of this ambiguous cyber criminal group, internally referenced as TH-173. Conclusion. Pierluigi Paganini.