Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Spyware activities are on the rise, thanks to never-ending zero-day vulnerabilities

byKerem Gülen
August 8, 2022
in News, Cybersecurity
Home News
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Vulnerability exploitation and spyware activities picked up in July, with abnormally high amounts of activity observed in incursions connected to spyware, according to research conducted by Recorded Future. The creators of mercenary spyware appear to have been unusually active in weaponizing common vulnerabilities and exposures (CVEs). It is unknown, however, whether this is simply due to other threat actors being less active during the summer.

The CVE report details the latest spyware activities

Spyware is a sort of malicious software that is installed on a computer without the knowledge of the end user. Spyware infiltrates the device, obtains sensitive information and internet usage statistics, and then sends it to advertising, data firms, or other users.

Vulnerability exploitation and spyware activities picked up in July, with abnormally high amounts of activity observed in incursions connected to spyware, according to research conducted by Recorded Future.
Spyware is one of the most common online threats

The software that is downloaded without the user’s permission is called spyware. Spyware is contentious because, even when installed for seemingly innocuous reasons, it can breach the privacy of the end user and has the potential to be abused.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Spyware is one of the most common online threats. Once installed, it monitors internet traffic, tracks login passwords, and eavesdrops on sensitive information. Spyware’s primary purpose is to collect credit card numbers, banking information, and passwords.

Vulnerability exploitation and spyware activities picked up in July, with abnormally high amounts of activity observed in incursions connected to spyware, according to research conducted by Recorded Future.
This malicious software is one of the most common online threats

This is the third monthly vulnerability bulletin created by Recorded Future’s Insikt Group’s threat research team; the first was released in June to coincide with the launch of Microsoft’s automated patching service for organizations, which has helped many people feel less anxious about Patch Tuesday.

The CVE monthly report will now be released by Recorded Future on the first Tuesday of each month, with Patch Tuesday continuing to be released on the second Tuesday.

In its most recent report, the research team stated that it had observed the distribution of spyware using newly disclosed zero-day vulnerabilities that affected both Microsoft and Google. The team claimed this showed an often close relationship between top-tier spyware developers and new zero-days.


The Russo-Ukrainian War rewrites the laws of cyber-warfare


“On July 4, 2022, Google disclosed an actively exploited zero-day vulnerability, CVE-2022-2294, which affects Google Chrome. While the company did not disclose details about attacks involving this flaw, it was not long before others reported exploitation,” the team explained.

Vulnerability exploitation and spyware activities picked up in July, with abnormally high amounts of activity observed in incursions connected to spyware, according to research conducted by Recorded Future.
Spyware infiltrates the device, obtains sensitive information and internet usage statistics, and then sends it to advertising, data firms, or other users

On July 21, 2022, Avast threat researchers (who were the first to alert Google to the issue) published a report detailing a campaign in which Israeli spyware firm Candiru used CVE-2022-2294 to distribute DevilsTongue software.

Another zero-day vulnerability, this time for Microsoft, was linked to spyware. Microsoft announced a zero-day vulnerability, CVE-2022-22047, on July 12, 2022, affecting the most recent releases of Windows and Windows Server. The mercenary threat organization Knotweed, operating in Austria, used this vulnerability to spread its Subzero spyware.


Security as a service leaves cybersecurity to the experts, but it is a double-edged sword


“A second vulnerability, CVE-2022-30216, also affects current versions of Windows and Windows Server and has a very high CVSS score due to remote code execution, but we have not yet seen exploitation attempts,” the researchers said.

A remote code execution (RCE) vulnerability in Apache Spark, tracked as CVE-2022-33891, found by Databricks researcher Kostya Kortchinsky, whose exploitation was seen in the wild within 48 hours of disclosure, and a SQL injection vulnerability in the Django Python web framework, tracked as CVE-2022-34265, were among the other more serious vulnerabilities in July 2022.

Vulnerability exploitation and spyware activities picked up in July, with abnormally high amounts of activity observed in incursions connected to spyware, according to research conducted by Recorded Future.
Spyware’s primary purpose is typically to collect credit card numbers, banking information, and passwords

CVE-2022-30190, commonly known as Follina, is a risky zero-click vulnerability in Microsoft Office that, if left unchecked, enables a threat actor to execute PowerShell commands without requiring user input, continues to see high levels of exploitation in July. Although Follina was made public at the end of May and addressed in the June Patch Tuesday update, many people still do not apply the patch.


Rising cybersecurity risks threaten the healthcare industry


“If we could have predicted any vulnerability to see high-profile exploitation after initial disclosure, it would have been Follina. Sure enough, on July 6, 2022, Fortinet researchers released an analytic report on a phishing campaign using Follina to distribute the Rozena backdoor. This malware allows attackers to take over Windows systems completely. Fortinet researchers observed adversaries using Rozena to inject a remote shell connection back to the attacker’s machine,” the Recorded Future team stated.

Tags: CybersecurityMalwarespywarezero-day

Related Posts

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

June 3, 2026
Crypto investors are watching one date closely in 2026

Crypto investors are watching one date closely in 2026

June 3, 2026
How Telegram Creators test post visibility before running growth campaigns

How Telegram Creators test post visibility before running growth campaigns

June 3, 2026
Does your AI clock in without you?

Does your AI clock in without you?

June 3, 2026
Why secure software delivery depends on better release management

Why secure software delivery depends on better release management

June 3, 2026
Sony reveals God of War: Laufey for PS5

Sony reveals God of War: Laufey for PS5

June 3, 2026
Please login to join discussion

LATEST NEWS

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

Crypto investors are watching one date closely in 2026

How Telegram Creators test post visibility before running growth campaigns

Does your AI clock in without you?

Why secure software delivery depends on better release management

Sony reveals God of War: Laufey for PS5

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Veed.io

Paper Pilot

IsOn24

Magnific

DADABOTS

Rosebud AI

Prome

Pageon AI

Vyond

Centauri AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.