Unveiling the Latest ICS Malware Threat: FrostyGoop Targeting Critical Infrastructure

Cybersecurity Researchers Uncover FrostyGoop Malware Targeting Energy Company in Ukraine Cybersecurity researchers recently uncovered the ninth Industrial Control Systems (ICS)-focused malware called FrostyGoop. This malicious software was used in a disruptive cyber attack targeting an energy company in Lviv, Ukraine, in January. The industrial cybersecurity firm Dragos identified FrostyGoop as the first malware strain to…

Read More

Uncovering the Latest Cyber Threats: HATVIBE and CHERRYSPY Malware Target Ukrainian Institutions

The Spear-Phishing Campaign The Computer Emergency Response Team of Ukraine (CERT-UA) recently issued a warning about a spear-phishing campaign aimed at a scientific research institution within the country. This malicious campaign involved the deployment of two types of malware – HATVIBE and CHERRYSPY. These malware entities were used to infiltrate the targeted institution’s systems and…

Read More

Securing New Hires: A Guide to Password-Less Employee Onboarding

The Risks of Sharing Temporary First-Day Passwords The initial onboarding stage is a crucial step for both employees and employers. However, this process often involves the risky practice of sharing temporary first-day passwords. This antiquated method can expose organizations to serious security risks, putting sensitive information at stake. The Traditional Dilemma for IT Departments Traditionally,…

Read More

Uncovering the Threat: How PINEAPPLE and FLUXROOT Hacker Groups Exploit Google Cloud for Credential Phishing

Financially Motivated Actor FLUXROOT Leverages Google Cloud for Credential Phishing A Latin America-based financially motivated actor known as FLUXROOT has recently caught the attention of security experts for its malicious activities. This actor has been seen exploiting Google Cloud serverless projects to carry out credential phishing campaigns, shedding light on the growing trend of abusing…

Read More

Boost Client Engagement: Elevate Your Cybersecurity Game with vCISO Reporting

The Comprehensive Playbook for vCISOs: Your First 100 Days As a vCISO (Virtual Chief Information Security Officer), your role involves spearheading your client’s cybersecurity strategy, risk governance, and overall information security initiatives. This multifaceted position requires a broad skill set encompassing research, strategy development, execution, and reporting. To help vCISOs navigate their crucial initial phase…

Read More