What’s New

SpyNote: Beware of This Android Trojan that Records Audio and Phone Calls

The Android banking trojan known as SpyNote has been dissected to reveal its diverse information-gathering features. Typically spread via SMS phishing campaigns, attack chains involving the spyware trick potential victims into installing the app by clicking on the embedded link, according to F-Secure. Besides requesting invasive permissions to access [...]

By |2023-10-16T12:33:39-05:00October 16th, 2023|Categories: BMT Announcement|

Free Tools for Cybersecurity Awareness Month

October is a great month for many reasons, but at BMT we especially like this time of the year as it celebrates something that should be an important part of any business culture, cybersecurity awareness.  While usually an afterthought until it happens, cyberattacks are increasing at a significant pace.  [...]

QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks

Despite the disruption to its infrastructure, the threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery of Ransom Knight (aka Cyclops) ransomware and Remcos RAT.This indicates that "the law enforcement operation may not have impacted Qakbot [...]

By |2023-10-09T07:57:30-05:00October 5th, 2023|Categories: BMT Announcement|

Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems

Cisco has released updates to address a critical security flaw impacting Emergency Responder that allows unauthenticated, remote attackers to sign into susceptible systems using hard-coded credentials. The vulnerability, tracked as CVE-2023-20101 (CVSS score: 9.8), is due to the presence of static user credentials for the root account that the [...]

By |2023-10-05T13:35:58-05:00October 5th, 2023|Categories: BMT Announcement|

Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware

New findings have identified connections between an Android spyware called DragonEgg and another sophisticated modular iOS surveillanceware tool named LightSpy. DragonEgg, alongside WyrmSpy (aka AndroidControl), was first disclosed by Lookout in July 2023 as a strain of malware capable of gathering sensitive data from Android devices. It was attributed [...]

By |2023-10-04T12:27:11-05:00October 4th, 2023|Categories: BMT Announcement|

Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorch

Cybersecurity researchers have disclosed multiple critical security flaws in the TorchServe tool for serving and scaling PyTorch models that could be chained to achieve remote code execution on affected systems. Israel-based runtime application security company Oligo, which made the discovery, has coined the vulnerabilities ShellTorch. "These vulnerabilities [...] can [...]

By |2023-10-04T10:36:28-05:00October 3rd, 2023|Categories: BMT Announcement|

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries

Introduction In today's interconnected digital ecosystem, Application Programming Interfaces (APIs) play a pivotal role in enabling seamless communication and data exchange between various software applications and systems. APIs act as bridges, facilitating the sharing of information and functionalities. However, as the use of APIs continues to rise, they have [...]

By |2023-10-02T12:21:21-05:00October 2nd, 2023|Categories: BMT Announcement|

LUCR-3: Scattered Spider Getting SaaS-y in the Cloud

LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property (IP) for extortion. LUCR-3 targets Fortune 2000 companies across various sectors, including [...]

By |2023-10-02T12:24:03-05:00October 2nd, 2023|Categories: BMT Announcement|Tags: |
Go to Top