Tag: cyber
-
Krisenkommunikation – Warum ein Kommunikationsprofi in jede Cyber-Taskforce gehört
Tags: cyberFirst seen on security-insider.de Jump to article: www.security-insider.de/krisenkommunikation-reputationsschutz-unternehmen-a-54ec77d002444561970768948b6615d3/
-
Astaroth 2FA Phishing Kit Targets Gmail, Yahoo, Office 365, and Third-Party Logins
Tags: 2fa, authentication, credentials, cyber, cybercrime, cybersecurity, login, mfa, network, office, phishing, threatA new phishing kit named Astaroth has emerged as a significant threat in the cybersecurity landscape by bypassing two-factor authentication (2FA) mechanisms. First advertised on cybercrime networks in January 2025, Astaroth employs advanced techniques such as session hijacking and real-time credential interception to compromise accounts on platforms like Gmail, Yahoo, Office 365, and other third-party…
-
Device Code Phishing Attack Exploits Authentication Flow to Hijack Tokens
Tags: attack, authentication, cyber, defense, exploit, government, intelligence, microsoft, phishing, service, threatA sophisticated phishing campaign leveraging the device code authentication flow has been identified by Microsoft Threat Intelligence, targeting a wide range of sectors, including government, NGOs, IT services, and critical industries such as defense and energy. The campaign, attributed to a threat actor known as Storm-2372, has been active since August 2024 and is assessed…
-
CISA Publishes 20 Advisories on ICS Security Flaws and Exploits
Tags: cisa, control, cyber, cybersecurity, exploit, flaw, infrastructure, risk, technology, threat, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) has issued 20 security advisories on February 13, 2025, warning about critical vulnerabilities in Industrial Control Systems (ICS) and medical devices. These disclosures are part of ongoing efforts to address the growing risks posed by cyber threats targeting critical infrastructure and operational technology (OT). The advisories span vulnerabilities…
-
Dutch Authorities Dismantle Network of 127 CommandControl Servers
Dutch police and the Public Prosecution Service have taken down a network of 127 command-and-control servers. This network was operated by ZServers/XHost, a so-called bulletproof hosting provider offering cybercriminals a safe haven to facilitate illegal activities, such as spreading malware and carrying out cyberattacks. A bulletproof hoster is a hosting company that protects criminals by…
-
Apache Fineract SQL Injection Vulnerability Allows Malicious Data Injection
The Apache Software Foundation has disclosed a critical SQL injection vulnerability in its widely utilized financial platform, Apache Fineract. The flaw, tracked as CVE-2024-32838, affects multiple API endpoints and poses a significant risk to applications built on this platform. This vulnerability allows authenticated attackers to inject malicious SQL data, potentially compromising sensitive information and the overall…
-
AMD Ryzen Flaw Enables Code Execution Through DLL Hijacking
A security vulnerability hasbeen identified inthe AMD Ryzen Master Utility, a performance-tuningtool for AMDRyzen processors. This flaw, discovered by a security researcher, allows for privilege escalation and arbitrary code execution via DLL hijacking. AMD has confirmed the issue and issued a patch to mitigate the risk. The Vulnerability The AMDRyzen Master Utility provides users with a streamlined interface for overclocking, monitoring system performance,…
-
What is anomaly detection? Behavior-based analysis for cyber threats
a priori the bad thing that you’re looking for,” Bruce Potter, CEO and founder of Turngate, tells CSO. “It’ll just show up because it doesn’t look like anything else or doesn’t look like it’s supposed to. People have been tilting at that windmill for a long time, since the 1980s, trying to figure out what…
-
WinZip Vulnerability Allows Remote Attackers to Execute Arbitrary Code
A newly discovered vulnerability in WinZip, a popular file compression and archiving utility, has raised alarms among cybersecurity experts. Identified as CVE-2025-1240, this critical flaw allows remote attackers to execute arbitrary code on a victim’s system under specific conditions. Users are strongly advised to update their software to mitigate the risk. Key Details of the…
-
From Reactive to Predictive: Building Cyber Resilience for 2025
When you’re resilient to something, you don’t just endure; you adapt, recover, and emerge stronger. This idea is what should motivate companies to focus more on cyber resilience. It’s not enough to simply weather the storm of a cyberattack; true resilience means predicting the storm’s arrival, minimizing its impact, and ensuring business operations bounce back…
-
Senate Confirms Trump Pick RFK Jr. to Lead HHS
Expert: ‘Predictions are Cloudy’ on How Kennedy Will Handle Cyber, Privacy Issues. The U.S. Senate confirmed controversial nominee Robert F. Kennedy to lead the U.S. Department of Health and Human Services. But despite many hours of recent scrutiny by lawmaker not much – if anything – is publicly known about Kennedy’s stance on health data…
-
How Public & Private Sectors Can Better Align Cyber Defense
With investment in cybersecurity capabilities and proactive measures to address emerging challenges, we can work together to navigate the complexities of combating cybercrime. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/how-public-private-sectors-better-align-cyber-defense
-
Intelligence agencies must explain what they do, says UK’s former cyber spy chief
Speaking at the Munich Cyber Security Conference on Thursday, Sir Jeremy Fleming, who headed the cyber and signals intelligence agency GCHQ from 2017 to 2023, said he felt “really strongly” the agency’s “license to operate” had to be based on public understanding and trust. First seen on therecord.media Jump to article: therecord.media/intel-agencies-must-explain-what-they-do-fleming-gchq
-
New Microsoft Windows GUI 0-Day Vulnerability Actively Exploited in the Wild
A newly discovered vulnerability in Microsoft Windows, identified by ClearSky Cyber Security, is reportedly being actively exploited by the Chinese state-sponsored Advanced Persistent Threat (APT) group Mustang Panda. The vulnerability, which affects the Windows Explorer graphical user interface (GUI), has been classified as low-severity by Microsoft but poses significant risks due to its exploitation in…
-
Chinese APT ‘Emperor Dragonfly’ Moonlights With Ransomware
Pivoting from prior cyber espionage, the threat group deployed its backdoor tool set to ultimately push out RA World malware, demanding $2 million from its victim. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/chinese-apt-emperor-dragonfly-ransomware-attack
-
What the EU Cyber Solidarity Act Means for UK MSPs and MSSPs
First seen on scworld.com Jump to article: www.scworld.com/perspective/what-the-eu-cyber-solidarity-act-means-for-uk-msps-and-mssps
-
The blueprint for cyber resilience: How businesses can adapt and thrive
First seen on scworld.com Jump to article: www.scworld.com/resource/the-blueprint-for-cyber-resilience-how-businesses-can-adapt-and-thrive
-
Cyber resilience: A C-suite game plan for balancing innovation, compliance and risk
First seen on scworld.com Jump to article: www.scworld.com/resource/cyber-resilience-a-c-suite-game-plan-for-balancing-innovation-compliance-and-risk
-
Burp Suite Professional / Community 2025.2 Released With New Built-in AI Integration
PortSwigger has announced the release of Burp Suite Professional and Community Edition 2025.2, introducing significant updates that include AI integration into the Montoya API, enhancing the capabilities for building smarter, AI-powered extensions. Bug Fixes and Browser Updates: A notable bug fix corrects the display of source IP addresses for DNS requests over IPv6 in the…
-
The Rise of Cyber Espionage: UAV and C-UAV Technologies as Targets
Researchers at cybersecurity firm Resecurity detected a rise in cyberattacks targeting UAV and counter-UAV technologies. Resecurity identified an increase in malicious cyber activity targeting UAV and counter-UAV (C-UAV/C-UAS) technologies. That was especially notable during active periods of local conflicts, including the escalation of the Russia-Ukraine war and the Israel-Hamas confrontation. The trend of malicious targeting…
-
Unusual attack linked to Chinese APT group combines espionage and ransomware
Tags: apt, attack, breach, china, cloud, country, credentials, crime, crimes, crypto, cyber, cybercrime, cyberespionage, data, encryption, espionage, exploit, finance, firewall, government, group, hacker, infection, insurance, intelligence, korea, microsoft, network, north-korea, ransom, ransomware, russia, software, tactics, technology, threat, veeam, vulnerabilityThe attacker demanded a $2-million ransom: The attack that resulted in the deployment of the RA World ransomware program, as well as data exfiltration, had the same chain: the toshdpdb.exe loading toshdpapi.dll then decrypting toshdp.dat which resulted in the PlugX variant being deployed. The difference is the attacker then chose to deploy the RA World…
-
Unpatched Cisco Devices Still Getting Popped by Salt Typhoon
Telecoms Still Falling to Chinese Nation-State Hacking Group, Researchers Warn. A Chinese cyber espionage group tracked as Salt Typhoon and tied to the mass hacking of telecommunications networks in the U.S. and dozens of other countries has been continuing to seek and hack unpatched equipment, including exploiting two long-patched vulnerabilities in Cisco gear. First seen…
-
Japan Goes on Offense With New ‘Active Cyber Defense’ Bill
Japan is on a mission to catch up to the US standard of national cyber preparedness, and its new legislation is a measure intended to stop escalating Chinese cyber-espionage efforts, experts say. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/japan-offense-new-cyber-defense-bill
-
Consortium Acquires Cyber Risk Quantification Startup To Become ‘Next-Gen VAR’
Consortium’s acquisition of Metrics That Matter is aimed at providing customers with a more-accurate, continuously updated picture of their cyber risk, CEO Nate Ungerott tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2025/consortium-networks-acquires-cyber-risk-quantification-startup-to-become-next-gen-var
-
Munich Cyber Security and Security Conferences 2025 [Live Updates]
Live updates from the Munich Security and Cyber Security Conference from reporters Alexander Martin, Daryna Antoniuk and Dina Temple-Raston. First seen on therecord.media Jump to article: therecord.media/munich-cyber-security-and-security-conference-2025
-
Check Point ‘State of Global Cyber Security 2025″ Report – Zahl der Cyber-Angriffe steigt um 44 Prozent
First seen on security-insider.de Jump to article: www.security-insider.de/bericht-global-cyber-security-2025-zunahme-cyber-angriffe-a-b78634bf546fa4835f6ab35520946e3e/
-
Consortium Networks Acquires Cyber Risk Quantification Startup To Become ‘Next-Gen VAR’
Consortium Networks’ acquisition of Metrics That Matter is aimed at providing customers with a more-accurate, continuously updated picture of their cyber risk, CEO Nate Ungerott tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2025/consortium-networks-acquires-cyber-risk-quantification-startup-to-become-next-gen-var
-
UK government sanctions target Russian cyber crime network Zservers
The UK government has imposed sanctions on a Russian cyber crime syndicate responsible for aiding ransomware attacks, targeting the group and individual members First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366619219/UK-government-sanctions-target-Russian-cyber-crime-network-ZSERVERS
-
Arbitrary File Upload Vulnerability in WordPress Plugin Let Attackers Hack 30,000 Website
A subgroup of the Russian state-sponsored hacking group Seashell Blizzard, also known as Sandworm, has intensified its cyber operations through a campaign dubbed BadPilot. This multi-year initiative has targeted critical infrastructure worldwide, expanding the group’s reach beyond its traditional focus on Ukraine and Eastern Europe to include North America, Europe, and Asia-Pacific regions. Exploiting Vulnerabilities…

