Elastic Security Labs stories
EDDIESTEALER Rust malware mimics CAPTCHA to steal credentials
Thu, 5th Jun 2025
#
elastic security labs
A new Rust-based malware, EDDIESTEALER, uses fake CAPTCHA pages to trick users into running code that steals browser credentials and crypto wallets.
Harrods cyber attack spotlights retailer risk amid cutbacks
Fri, 2nd May 2025
#
elastic security labs
The recent cyber attack on Harrods highlights rising cyber threats to retailers, linked to economic pressures potentially weakening security defences.
How new malware SHELBY targets telecom via phishing
Mon, 31st Mar 2025
#
elastic security labs
Elastic Security Labs has unveiled SHELBY, a sophisticated malware family linked to phishing attacks against an Iraqi telecom firm, raising security alarms.
Cybercriminals advance with MEDUSA ransomware campaign
Mon, 24th Mar 2025
#
elastic security labs
Elastic Security Labs has revealed a sophisticated campaign deploying MEDUSA ransomware via the ABYSSWORKER driver, undermining endpoint security measures.
Elastic Security Labs reveals new GOSAR backdoor threat
Wed, 18th Dec 2024
#
elastic security labs
Elastic Security Labs has unveiled GOSAR, a sophisticated new Golang-based malware family, targeting Chinese-speaking victims with advanced evasion techniques.
Elastic identifies stealthy malware toolkit named PUMAKIT
Wed, 18th Dec 2024
#
elastic security labs
Elastic Security Labs has unveiled PUMAKIT, an advanced malware toolkit featuring stealthy rootkit capabilities, raising alarms in cybersecurity.
Elastic Security's top three cybersecurity predictions for 2025
Tue, 17th Dec 2024
#
elastic security labs
In 2025, AI will be crucial in strengthening cybersecurity as threat actors become increasingly sophisticated, driving a surge in cyber incidents.
Elastic report: Azure outpaces AWS in 2024 cyber threats analysis
Wed, 2nd Oct 2024
#
elastic security labs
In a significant shift, Microsoft Azure has eclipsed AWS as the leading environment for cyber threats, accounting for 64% of anomalous signals, according to Elastic's new report.
Elastic report: misconfigurations & OSTs heighten cyber risk
Wed, 2nd Oct 2024
#
elastic security labs
Elastic's 2024 Global Threat Report reveals that misconfigurations and offensive security tools significantly elevate cyber risks, notably in cloud environments.
Elastic reports critical security flaws in Microsoft systems
Wed, 7th Aug 2024
#
elastic security labs
Elastic Security Labs has uncovered serious security vulnerabilities in Microsoft's Smart App Control and SmartScreen, posing risks of undetected cyber attacks.
New BITSLOTH backdoor uncovered, leverages BITS for C2 comms
Fri, 2nd Aug 2024
#
elastic security labs
Elastic Security Labs has uncovered BITSLOTH, a sophisticated Windows backdoor leveraging BITS for covert command-and-control, found in a South American Foreign Ministry breach.
Elastic discovers new attack vector in Microsoft Management Console
Wed, 26th Jun 2024
#
elastic security labs
Elastic Security Labs has unveiled GrimResource, a new attack technique exploiting the Microsoft Management Console, allowing full code execution with minimal security alerts.
Elastic unveils guide on securing large language models
Thu, 23rd May 2024
#
elastic security labs
Elastic's new LLM Safety Assessment report offers crucial guidelines for secure Large Language Model deployments, addressing rising cybersecurity risks.
Exclusive: Why Elastic continues to see positive momentum
Fri, 16th Feb 2024
#
elastic security labs
Gavin Jones, Area VP for ANZ at Elastic, the leading search analytics firm, shares insights on its strategic direction and technological advancements.
New threat report reveals true dominance of ransomware
Fri, 20th Oct 2023
#
elastic security labs
Increases in ransomware, commercial off-the-shelf malware, and attacks against cloud service providers create new challenges for cybersecurity teams.
A third of cyberattacks in the cloud leverage credential access
Tue, 22nd Nov 2022
#
elastic security labs
A new report has revealed adversary success in identity theft indicates default cloud security controls are ineffective at preventing attacks.