Skip to content

Category: Beveiligingsnieuws

OctLurk en SilkLurk: cyberaanval op Centraal-Azië

Kaspersky meldt een golf aanvallen sinds januari 2025 op overheidsorganisaties in Centraal-Azië. Onderzoekers koppelen de activiteit aan OctLurk and SilkLurk, een multi-plugin backdoor-framework.

HollowFrame and Matryoshka: Spear-Phishing Toolkit

Researchers describe how HollowFrame Matryoshka operates as a multi-stage spear-phishing intrusion. It chains DLL side-loading, privilege escalation, and Rust-based backdoors for remote command execution and deeper domain activity.

Minnesota Water Cyberattacks: Iran Warning Update

Minnesota is investigating Minnesota water cyberattacks that affected over 30 water systems. Authorities say residents were largely not impacted, while federal agencies warn of Iranian activity.

Cheap Android TV boxes can turn your broadband proxy

Researchers traced a fraud operation (Fuyao) to certain cheap Android TV boxes that masquerade as phone devices and can relay traffic. The findings also describe how ad automation and remote control were orchestrated.

Chrome’s Latest Patches: 1,442 Bugs Fixed

Google has fixed 1,442 security bugs in recent Chrome releases, far exceeding the total of earlier updates combined. The company is also testing faster delivery, automation, and dynamic patching to reduce exposure time.

84 Flaws Found in 4G/5G Cores: DoS & Session Hijacking

A study from Nanyang Technological University reports 84 previously unknown vulnerabilities in 4G and 5G core networks. The issues stem from implicit trust between core functions and may enable DoS and session hijacking.

Device code phishing: 6 fast-growing warning signs

Device code phishing has shifted from a niche technique to an industrial-scale phishing-as-a-service threat. Here are six practical reasons security teams should treat it as an urgent 2026 priority.