Tag: cyber
-
New Advanced Phishing Attack Exploits Discord to Target Crypto Users
Check Point Research has uncovered a sophisticated phishing campaign that leverages Discord to target cryptocurrency users. The attack redirects victims from legitimate Web3 websites to a fake Collab.Land bot and then to a phishing site, ultimately tricking them into signing malicious transactions. This campaign has been directly linked to the notorious Inferno Drainer, which has…
-
DragonForce: Symbol einer neuen Generation hybrider Cyber-Bedrohungen
Nach dem plötzlichen Verschwinden von RansomHub im April 2025 übernahm DragonForce dessen Partnernetzwerk und etablierte sich als flexible Alternative zu den ehemals führenden Ransomware-as-a-Service-Anbietern. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/dragonforce-symbol-einer-neuen-generation-hybrider-cyber-bedrohungen/a40712/
-
Researchers Uncover Remote Code Execution Flaw in macOS CVE-2024-44236
Security researchers Nikolai Skliarenko and Yazhi Wang of Trend Micro’s Research Team have disclosed critical details about CVE-2024-44236, a memory corruption vulnerability in Apple’s macOS Scriptable Image Processing System (sips). Discovered by Hossein Lotfi through Trend Micro’s Zero Day Initiative, this flaw allows arbitrary code execution via maliciously crafted ICC profile files. Patched in October…
-
Apache ActiveMQ Vulnerability Allows Attackers to Induce DoS Condition
Tags: apache, attack, cyber, dos, flaw, malicious, mitigation, open-source, service, software, vulnerabilityCritical vulnerability in Apache ActiveMQ (CVE-2024-XXXX) exposes brokers to denial-of-service (DoS) attacks by allowing malicious actors to exhaust system memory through specially crafted OpenWire commands. The flaw, tracked as AMQ-6596, affects multiple legacy versions of the widely used open-source messaging platform and has prompted urgent mitigation directives from the Apache Software Foundation. The vulnerability stems…
-
Kaspersky Alerts on AI-Driven Slopsquatting as Emerging Supply Chain Threat
Tags: ai, cyber, cybersecurity, kaspersky, microsoft, programming, risk, software, supply-chain, threat, vulnerabilityCybersecurity researchers at Kaspersky have identified a new supply chain vulnerability emerging from the widespread adoption of AI-generated code. As AI assistants increasingly participate in software development-with Microsoft CTO Kevin Scott predicting AI will write 95% of code within five years-a phenomenon called >>slopsquatting
-
UK Government to Shift Away from Passwords in New Security Move
UK government has unveiled plans to implement passkey technology across its digital services later this year, marking a significant shift away from traditional password and SMS-based verification methods. Announced at the government’s flagship cyber security event CYBERUK, this transition aims to enhance security while providing a more streamlined user experience for citizens accessing GOV.UK services.…
-
Fedora Linux Joins the Windows Subsystem for Linux Officially
Fedora Project has announced the official availability of Fedora Linux on the Windows Subsystem for Linux (WSL), marking a significant expansion of Fedora’s ecosystem. Starting with Fedora 42, users can now seamlessly integrate Fedora’s cutting-edge tools and development environment directly into Windows via WSL’s tar-based architecture. This integration empowers developers and enthusiasts to leverage Fedora’s…
-
Microsoft Launches >>Copilot+ PC<< for an Upgraded Windows Experience
Microsoft has announced a significant wave of new Windows experiences designed for Copilot+ PCs, which the company describes as >>the fastest, most intelligent and most secure Windows PCs ever built.
-
Nomad Bridge Hacker Apprehended in Connection with $190 Million Heist
Alexander Gurevich, a 47-year-old dual Russian-Israeli citizen, was arrested last Thursday at Ben-Gurion Airport while attempting to flee to Russia under a new identity. Gurevich is the primary suspect in the 2022 Nomad Bridge hack that resulted in approximately $190 million in stolen cryptocurrency, marking one of the largest blockchain security breaches that year. Israeli…
-
160-Year-Old Haulage Firm Falls After Cyber-Attack: Director Issues Urgent Warning
The 160-year-old haulage giant Knights of Old, once a stalwart of the UK’s logistics sector, was forced into administration in 2023 following a devastating cyber-attack that crippled its financial systems. Paul Abbott, a board director at the Kettering-based firm, has issued a stark warning to businesses of all sizes: no organization is immune to cyber…
-
SonicWall Unveils New Firewalls and Comprehensive Managed Cybersecurity Service
SonicWall has unveiled a new line of advanced firewalls and a comprehensive managed cybersecurity service designed to combat the evolving threat landscape, with particular emphasis on attacks targeting non-standard ports. The announcement comes on the heels of concerning findings in SonicWall’s 2019 Cyber Threat Report, which highlighted a growing trend of cybercriminals exploiting vulnerabilities across…
-
China-Backed Hackers Target Exiled Uyghur Community with Malicious Software
Senior members of the World Uyghur Congress (WUC) living in exile were targeted with a sophisticated spearphishing campaign delivering malware through a seemingly legitimate Uyghur language text editor. The attack, which began preparation nearly a year ago, represents another chapter in China’s ongoing digital transnational repression campaign against the Uyghur diaspora. While the malware itself…
-
FBI Warns Hackers Are Using EndLife Routers to Mask Their Tracks
The Federal Bureau of Investigation (FBI) has issued a stark warning to businesses and home users: cybercriminals are actively exploiting outdated, unsupported routers to hide their tracks and launch attacks, making them a favored tool for masking malicious operations. According to a new security advisory released May 7, FBI investigators have observed a troubling spike…
-
Cyberangriff auf einen Personaldienstleister in Virginia, USA
Cyber Security Incident Involving PDRI First seen on plc.pearson.com Jump to article: plc.pearson.com/en-GB/news-and-insights/news/cyber-security-incident-involving-pdri
-
Azure Storage Utility Vulnerability Allows Privilege Escalation to Root Access
A critical vulnerability discovered by Varonis Threat Labs has exposed users of Microsoft Azure’s AI and High-Performance Computing (HPC) workloads to a potential privilege escalation attack. The flaw, found in a utility pre-installed on select Azure Linux virtual machines, made it possible for an unprivileged local user to gain root access-a severe breach of the…
-
New infosec products of the week: May 9, 2025
Here’s a look at the most interesting products from the past week, featuring releases from ProcessUnity, Searchlight Cyber, ServiceNow, and Verosint. ServiceNow unveils AI … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/05/09/new-infosec-products-of-the-week-may-9-2025/
-
Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures
Threat actors with ties to the Qilin ransomware family have leveraged malware known as SmokeLoader along with a previously undocumented .NET compiled loader codenamed NETXLOADER as part of a campaign observed in November 2024.”NETXLOADER is a new .NET-based loader that plays a critical role in cyber attacks,” Trend Micro researchers Jacob Santos, Raymart Yambot, John…
-
US tells CNI orgs to stop connecting OT kit to the web
The US authorities have released new guidance for owners of critical national infrastructure in the face of an undisclosed number of cyber incidents. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366623645/US-tells-CNI-orgs-to-stop-connecting-OT-kit-to-the-web
-
How China’s Admission Reinforces the Urgency for AI-Powered, Preemptive Cybersecurity
In December, a senior Chinese cyber official offered what U.S. representatives took as tacit admission: China was behind a series of cyber intrusions targeting U.S. critical infrastructure. As reported by The Wall Street Journal, this extraordinary moment came during a closed-door meeting in Geneva”, one that has since confirmed what many cybersecurity professionals have long…
-
Shaping tomorrow’s cyber defenders: Why the Hacking Games gives me hope for Generations Z, A and beyond
First seen on scworld.com Jump to article: www.scworld.com/perspective/shaping-tomorrows-cyber-defenders-why-the-hacking-games-gives-me-hope-for-generations-z-a-and-beyond
-
Most cyber insurance claims stem from BEC, fraud, report says
First seen on scworld.com Jump to article: www.scworld.com/news/most-cyber-insurance-claims-stem-from-bec-fraud-report-says
-
Trump’s Defense Department cyber policy nominee pledges to bolster cyber threat deterrence
First seen on scworld.com Jump to article: www.scworld.com/brief/trumps-defense-department-cyber-policy-nominee-pledges-to-bolster-cyber-threat-deterrence
-
Report: Most firms not ready for AI-powered cyber threats
First seen on scworld.com Jump to article: www.scworld.com/brief/report-most-firms-not-ready-for-ai-powered-cyber-threats
-
Cyber intel sharing unaffected by federal cuts
Tags: cyberFirst seen on scworld.com Jump to article: www.scworld.com/brief/cyber-intel-sharing-unaffected-by-federal-cuts
-
Email-Based Attacks Top Cyber-Insurance Claims
Cyber-insurance carrier Coalition said business email compromise and funds transfer fraud accounted for 60% of claims in 2024. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/email-based-attacks-cyber-insurance-claims
-
SMBs Know They’re At Risk, but Most Aren’t Embracing AI
A survey by CrowdStrike finds the gap between SMB awareness of cyber threats and efforts by them to protect themselves is widening, with not enough of them spending the money needed on AI and other tools to defend against ransomware and other attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/smbs-know-theyre-at-risk-but-most-arent-embracing-ai/
-
Leading Through Uncertainty: AI, Risk, and Real Talk from RSAC’s Women in Cyber
Recapping Synack’s Women in Cyber panel: Inside the hard conversations about AI risk, hiring struggles, and why resilience First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/leading-through-uncertainty-ai-risk-and-real-talk-from-rsacs-women-in-cyber/
-
Exclusive: Top FBI cyber official Bryan Vorndran expected to leave the bureau
Tags: cyberThe head of the FBI’s Cyber Division, Bryan Vorndran, is expected to retire from the bureau soon, according to two people with direct knowledge. First seen on therecord.media Jump to article: therecord.media/bryan-vorndran-leaving-fbi
-
CISA’s Acting Director Defends Cuts Amid Growing Turmoil
Top Cyber Official Says CISA Wants to Eliminate Duplication and Increase Efficiency. The acting director of the Cybersecurity and Infrastructure Security Agency told a House appropriations subcommittee Thursday the nation’s cyber defense agency was continuing to improve its ability to respond to growing threats from China despite budget cuts and looming workforce reductions. First seen…
-
Wiz, Kaseya Investor Warns Security Incident May Have Impacted ‘Portfolio Company Information’
Insight Partners, the venture capital and private equity giant whose portfolio includes Wiz, Kaseya and Veeam, has an update on a January cyber incident. First seen on crn.com Jump to article: www.crn.com/news/security/2025/wiz-kaseya-investor-warns-of-potential-portfolio-company-information

