Aggregator
NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities
Browser Guard gets even better with Access Control
Take control of pesky permission pop-ups and decide exactly which websites can access your camera, microphone, location, and send you notifications.
The post Browser Guard gets even better with Access Control appeared first on Security Boulevard.
Is Aquila (Dmitry) from WASM Forum Community the Author of the Carberp Banking Malware?
Dear blog readers,
I recently did something very interesting and I decided to share my results and findings.
What I did was the following. While doing a technical collection round for malicious software I came across to Carberp's source where I decided to take a peek and found out some pretty interesting and relevant personally attributable IoCs (Indicators of Compromise) which led me to further pursue an OSINT enrichment process which led me to believe and conclude that there's a high probability that Aquilla (Dmitry) from the WASM forum community could be one of the main authors of the Carberp banking trojan.
The most interesting part of this technical collection round which then turned into IoCs extraction and then OSINT enrichment based on the successfully found hardcoded IoCs in Carberp's publicly accessible and leaked source code is that I think I have managed to establish a direct connection between the hardcoded C&Cs and Is Aquila (Dmitry) from the WASM forum community.
Here's the interesting part and the actual hardcoded C&C IoCs I found in Carberp's publicly accessible source code:
hxxp://178.63.11.137 (Primary test C2)
hxxp://94.240.148.127 (Alt configuration node parsing `/cfg/passw.plug`)
Payload Drop Zones & Telemetry:
hxxp://apartman-adriana.com (http://.../temp/DrClient.dll) - Email: [email protected]
hxxp://56tgvr.info
We then have an interesting connection for one of the IoCs (hxxp://178.63.11.137) which appears to have been known to be responding to the email server for the WASM forum community which based on additional analysis appear to have been managed and operated and actually owned by Aquila also known as Dmitry (Email: [email protected]; [email protected]; hxxp://dimon.ru).
Related domain registrations for Aquila:
hxxp://symbolographia.com
hxxp://wasm.site
hxxp://posthumanism.info
Related screenshot:
The post Is Aquila (Dmitry) from WASM Forum Community the Author of the Carberp Banking Malware? appeared first on Security Boulevard.
Data Centers Are Feeling the Heat, and That’s OK
DragonForce
You must login to view this content
«Нет» значит «да». Кнопка отказа от Cookie оказалась лишь красивой болванкой
大疆 OSMO Pocket 4 深度体验:三年之后,大疆如何继续定义「手持云台相机」
HSCC Guide Targets Third-Party AI Risk in Healthcare
The Health Sector Coordinating Council released guidance to help the healthcare and public health sector better manage the explosion of third-party AI vendor cyber risk concerns they face, especially as the technology is embedded in all sorts of products.
US FCC Grants Netgear Temporary Exemption From Router Ban
Netgear obtained a temporary waiver from the Federal Communications Commission allowing it to continue importing consumer routers through most of 2027, making the networking hardware giant the first consumer brand to circumvent a ban on foreign-made hardware.
Artemis Gets $70M to Build AI Agents for Detection, Response
Artemis, a New York startup led by former Amazon GuardDuty product leader Shachar Hirshberg, emerged from stealth with $70 million to build an AI-driven SIEM alternative that correlates telemetry across enterprise environments, tailors detections and speeds investigations.
Federal Staffers Are Still Using Claude Despite Trump Orders
Federal agency staffers tell ISMG they are still using Anthropic's AI tools weeks after U.S. President Donald Trump ordered an immediate halt, as officials prioritize mapping dependencies and evaluating alternatives over enforcing a rapid shutdown.
Cisco says critical Webex Services flaw requires customer action
PhantomCore: ваши новые невидимые коллеги. Они уже две недели в сети, а вы их даже не заметили
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-34197 Apache ActiveMQ Improper Input Validation Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Supply chain dependencies: Have you checked your blind spot?
NIST Weighs In on the Mystery of the Gravitational Constant
Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware
伪造Zoom官网投递BlackSuit勒索软件:9天入侵全链路深度剖析
Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers
Two American nationals have been sentenced to federal prison for operating a sophisticated “laptop farm” scheme. The operation successfully infiltrated over 100 U.S. companies, generating more than $5 million in illicit revenue to fund the Democratic People’s Republic of Korea (DPRK) and its weapons programs. Kejia Wang, 42, received a 108-month prison sentence, while his […]
The post Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers appeared first on Cyber Security News.