$6 million heist targets video game skin trading site

Categories: Business

Tags: game

Tags: video game

Tags: trading

Tags: skins

Tags: CS: GO

Tags: compromised

Tags: website

Tags: steam

We take a look at reports of a huge raid on a popular video game skin trading site.

(Read more…)

The post $6 million heist targets video game skin trading site appeared first on Malwarebytes Labs.

Read more

Update Chrome now! Google issues patch for zero day spotted in the wild

Categories: Exploits and vulnerabilities

Categories: News

Tags: 104.0.5112.101

Tags: Google

Tags: Chrome

Tags: CVE-2022-2852

Tags: CVE-2022-2856

Tags: CVE-2022-2854

Tags: CVE-2022-2853

Tags: UAF

Tags: heap buffer overflow

Google issued an update that includes 11 security fixes. One of the vulnerabilities is labeled as “Critical” and one of the vulnerabilities that is labeled as “High” exists in the wild.

(Read more…)

The post Update Chrome now! Google issues patch for zero day spotted in the wild appeared first on Malwarebytes Labs.

Read more

Ransomwater confusion, does the criminal know who the victim is?

Categories: News

Categories: Ransomware

Tags: ransomware

Tags: Clop

Tags: Thames Water

Tags: hoax

Tags: South Staffs Water

Tags: vital infrastructure

The Clop ransomware gang made a mistake in identifying who exactly their victim was, but they got it right in the end

(Read more…)

The post Ransomwater confusion, does the criminal know who the victim is? appeared first on Malwarebytes Labs.

Read more

[updated] Thousands of Zimbra mail servers backdoored in large scale attack

Categories: Exploits and vulnerabilities

Categories: News

Tags: Zimbra

Tags: ZVS

Tags: cve-2022-27925

Tags: web shell

Tags: cve-2022-37042

Tags: authentication

Tags: RCE

Researchers found that a known RCE vulnerability in Zimbra Collaboration was chained with a new authentication vulnerability to drop backdoor web shells on thousands of servers

(Read more…)

The post [updated] Thousands of Zimbra mail servers backdoored in large scale attack appeared first on Malwarebytes Labs.

Read more

Analyzing the Hidden Danger of Environment Variables for Keeping Secrets

Credit to Author: David Fiser| Date: Wed, 17 Aug 2022 00:00:00 +0000

While DevOps practitioners use environment variables to regularly keep secrets in applications, these could be conveniently abused by cybercriminals for their malicious activities, as our analysis shows.

Read more

CISA and FBI issue alert about Zeppelin ransomware

Categories: News

Categories: Ransomware

Tags: Zeppelin

Tags: ransomware

Tags: RDP

Tags: Sonicwall

Tags: phishing

Tags: malvertising

Tags: backups

Tags: authentication

Tags: mfa

Tags: patching

Tags: EDR

The FBI and CISA have issued a joint Cybersecurity Advisory (CSA) to raise awareness about Zeppelin ransomware

(Read more…)

The post CISA and FBI issue alert about Zeppelin ransomware appeared first on Malwarebytes Labs.

Read more