Senior Data Engineer, Cyber Analytics
Mastercard
Toronto, Canada
Apply now: https://totalcyber.io/jobs/mastercard/senior-data-engineer-cyber-analytics

Senior Data Engineer, Cyber Analytics
Mastercard
Toronto, Canada
Apply now: https://totalcyber.io/jobs/mastercard/senior-data-engineer-cyber-analytics
CIA has updated the KEV catalogue.
- CVE-2025-22457: Ivanti Connect Secure, Policy Secure and ZTA Gateways Stack-Based Buffer Overflow Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-22457 #CISA #cybersecurity #infosec #Ivanti
The Register: Australian Retirement funds reportedly raided after unexplained portal probes and data theft https://www.theregister.com/2025/04/04/australian_retirement_funds_attacked/ @theregister #cybersecurity #Infosec
Compliance & Operational Risk - Framework & Governance Senior Officer
Citi
Belfast, United Kingdom
Apply now: https://totalcyber.io/jobs/citi/compliance-operational-risk-framework-governance-senior-officer
Time: Social Media Platforms Shouldn’t Own Your Identity https://time.com/7274854/social-media-platforms-own-your-identity/ @time #socialmedia #privacy #cybersecurity #infosec
So Oracle only decided to come clean - barely - just days after it was slammed with a class action lawsuit.
This story is from yesterday:
CSO: https://www.csoonline.com/article/3953644/oracle-quietly-admits-data-breach-days-after-lawsuit-accused-it-of-cover-up.html @csoonline #Oracle #cybersecurity #infosec
New.
WatchTower: Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure (CVE-2025-22457) https://labs.watchtowr.com/is-the-sofistication-in-the-room-with-us-x-forwarded-for-and-ivanti-connect-secure-cve-2025-22457/ @watchtower #cybersecurity #infosec #Ivanti
Tenable Cybersecurity Snapshot https://www.tenable.com/blog/cybersecurity-snapshot-six-security-controls-for-ai-systems @tenable #cybersecurity #infosec
This is from yesterday. I've been getting a lot of these, lately. The latest "Adjust" presumptuous fool tells you to call 3477842468.
SpyCloud: Residential Proxies, North Korean IT Workers & Smishing https://spycloud.com/blog/spycloud-march-cybercrime-update/ @spycloud #cybersecurity #Infosec #phishing
Australian superannuation funds hit by coordinated cyberattack
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/australian-superannuation-funds-hit-by-coordinated-cyberattack-3-9-z-2-l/gD2P6Ple2L
GRC Specialist, AWS Security
Amazon Web Services Australia Pty Ltd
Melbourne, Australia
Apply now: https://totalcyber.io/jobs/amazon-web-services-australia-pty-ltd/grc-specialist-aws-security-3
Deobfuscating APT28's HTA Trojan: A Deep Dive into VBE Techniques & Multi-Layer Obfuscation
This analysis delves into APT28's cyber espionage campaign targeting Central Asia and Kazakhstan diplomatic relations, focusing on their HTA Trojan. The malware employs advanced obfuscation techniques, including VBE (VBScript Encoded) and multi-layer obfuscation. The investigation uses x32dbg debugging to decode the obfuscated code, revealing a custom map algorithm for character deobfuscation. The process involves decoding strings using embedded characters from Windows vbscript.dll. The analysis identifies the use of Microsoft's Windows Script Encoder (screnc.exe) to create VBE files. By employing various deobfuscation techniques, including a Python script, the final malware sample is extracted and analyzed, showcasing APT28's evolving tactics in cyber espionage.
Pulse ID: 67efc6e712b49d46c1423ca9
Pulse Link: https://otx.alienvault.com/pulse/67efc6e712b49d46c1423ca9
Pulse Author: AlienVault
Created: 2025-04-04 11:47:51
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Russian-Speaking Threat Actor Abuses Cloudflare & Telegram in Phishing Campaign
A Russian-speaking threat actor has launched a new phishing campaign using Cloudflare-branded pages themed around DMCA takedown notices. The attack abuses the ms-search protocol to deliver malicious LNK files disguised as PDFs. Once executed, the malware communicates with a Telegram bot to report the victim's IP address before connecting to Pyramid C2 servers. The campaign leverages Cloudflare Pages and Workers services to host phishing pages, and uses an open directory to store malicious files. The infection chain includes PowerShell and Python scripts, with incremental changes in tactics to evade detection. The actors' infrastructure spans multiple domains and IP addresses, primarily using Cloudflare's network.
Pulse ID: 67efc6ed5285702a3440969a
Pulse Link: https://otx.alienvault.com/pulse/67efc6ed5285702a3440969a
Pulse Author: AlienVault
Created: 2025-04-04 11:47:57
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
"the ProtectEU plan, launched on Monday, says the European Commission wants to develop a roadmap to allow "lawful and effective access to data for law enforcement in 2025" and a technology roadmap to do so by the following year."
https://www.theregister.com/2025/04/03/eu_backdoor_encryption/
The Digital Divide: A Barrier to Social, Economic and Political Equity https://www.ispionline.it/en/publication/the-digital-divide-a-barrier-to-social-economic-and-political-equity-204564 #cybersecurity #infosec
Security Week: Oracle Confirms Cloud Hack https://www.securityweek.com/oracle-confirms-cloud-hack/ @SecurityWeek #cybersecurity #Infosec #Oracle
Proofpoint: Call It What You Want: Threat Actor Delivers Highly Targeted Multistage Polyglot Malware https://www.proofpoint.com/us/blog/threat-insight/call-it-what-you-want-threat-actor-delivers-highly-targeted-multistage-polyglot @proofpoint #cybersecurity #Infosec #malware #phishing
Netskope: New Evasive Campaign Delivers LegionLoader via Fake CAPTCHA & CloudFlare Turnstile https://www.netskope.com/blog/new-evasive-campaign-delivers-legionloader-via-fake-captcha-cloudflare-turnstile #cybersecurity #infosec #Cloudflare #phishing #malware
Microsoft updated its security guide yesterday, with a long list of Chromium-based Edge vulnerabilities. Some of them are non-Microsoft CVEs and have no workarounds. Here are the release notes: https://msrc.microsoft.com/update-guide/releaseNote/2025-Apr @microsoftsec #Microsoft #cybersecurity #Infosec
Staff Threat Researcher
Zscalar
Uttar Pradesh, India
Apply now: https://totalcyber.io/jobs/zscalar/staff-threat-researcher