Npav Lab
-
A newly discovered malware campaign, “FatBoyPanel,” is targeting Indian bank users, stealing Aadhaar numbers, PAN details, ATM PINs, and credit card information. Researchers from zLabs (Zimperium) have identified nearly 900 malware samples designed to trick users into revealing sensitive data.
-
North Korean hacking group Kimsuky is using a custom RDP Wrapper and proxy tools to gain persistent, stealthy access to infected computers. This marks a shift in their tactics, moving away from noisy malware to more covert remote access techniques.
-
Cybercriminals are using fake Microsoft Active Directory Federation Services (ADFS) login pages to steal usernames, passwords, and MFA codes from employees in education, healthcare, and government organizations. The stolen credentials allow hackers to access corporate email accounts, send phishing emails, and commit financial fraud.
-
The New York Blood Center Enterprises suffered a ransomware attack on January 26, 2025, forcing it to cancel blood donation drives despite an ongoing blood shortage. The organization is working with cybersecurity experts and law enforcement to restore its systems, but processing times are delayed, and the timeline for full recovery is unknown.
-
WhatsApp has confirmed a sophisticated cyberattack targeting around 90 journalists and activists across 20 countries. Hackers used zero-click spyware, which can infect phones without the user clicking on anything. Meta has taken action against the attackers and is notifying the victims.
-
The WantToCry ransomware group is targeting unsecured SMB services, encrypting shared files, and demanding ransom payments. Weak passwords and misconfigured networks allow these attacks to succeed. Organizations must secure their SMB settings to prevent data loss and ransomware infections.
-
Tata Technologies recently faced a ransomware attack that led to the temporary suspension of some IT services. The company has confirmed that all affected services have been restored, and an investigation is underway to strengthen cybersecurity and prevent future incidents.
-
We are proud to announce that NPAV Endpoint Security has been awarded the AV-Test Approved Corporate Endpoint Protection Certificate, recognizing its powerful AI-driven defense and real-time threat detection.
-
Hackers are actively targeting vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM) software to infiltrate networks. These flaws allow attackers to download/upload files and gain admin-level access. While patches are available, unpatched systems remain at risk.
-
Chinese AI startup DeepSeek faced a major cyberattack soon after its successful launch on Wall Street. The attack caused service disruptions, forcing the company to temporarily stop new user registrations. DeepSeek’s popular open-source AI model, DeepSeek-R1, is creating waves in the global market, shaking up the tech industry and affecting major tech stocks.