Exploitation of the flaw, tracked as CVE-2025-10035, is highly dependent on whether systems are exposed to the Internet, according to Fortra.
0
Patch Now: Max-Severity Fortra GoAnywhere Bug Allows Command Injection
Thứ Sáu, 19 tháng 9, 2025
Việt Nam Hacker
0
'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails
Việt Nam Hacker
The loophole allows cyberattackers to exfiltrate company data via OpenAI's infrastructure, leaving no trace at all on enterprise systems.
0
Critical Azure Entra ID Flaw Highlights Microsoft IAM Issues
Việt Nam Hacker
While the cloud vulnerability was fixed prior to disclosure, the researcher who discovered it says it could have led to catastrophic attacks.
0
7 Lessons for Securing AI Transformation From Former CIA Digital Guru
Việt Nam Hacker
Jennifer Ewbank, former CIA deputy director of digital innovation, discusses resilience, cultural shifts, and cyber fundamentals in the AI era.
0
TikTok Deal Won't End Enterprise Risks
Thứ Năm, 18 tháng 9, 2025
Việt Nam Hacker
The proposed restructuring plan would address many concerns related to the social media platform, but risks remain for security teams.
0
SonicWall Breached, Firewall Backup Data Exposed
Việt Nam Hacker
Threat actors breached the MySonicWall service and accessed backup firewall configuration files belonging to "fewer than 5%" of its install base, according to the company.
0
Mastering Digital Breadcrumbs to Stay Ahead of Evolving Threats
Việt Nam Hacker
Digital forensics offers a challenging but rewarding career path for cybersecurity professionals willing to invest in specialized knowledge and continuous learning.
0
The Cloud Edge Is The New Attack Surface
Việt Nam Hacker
The cloud now acts as the connecting infrastructure for many companies' assets — from IoT devices to workstations to applications and workloads — exposing the edge to threats.
0
Microsoft Disrupts 'RaccoonO365' Phishing Service
Thứ Tư, 17 tháng 9, 2025
Việt Nam Hacker
Phishing-as-a-service (PhaaS) kits have become an increasingly popular way for lower-skill individuals who want to get into cybercrime.
0
'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree
Việt Nam Hacker
Though the groups have shared their decision to go dark, threat researchers say there are signs that it's business as usual.
0
North Korean Group Targets South With Military ID Deepfakes
Thứ Ba, 16 tháng 9, 2025
Việt Nam Hacker
The North Korea-linked group Kimsuky used ChatGPT to create deepfakes of military ID documents in an attempt to compromise South Korean targets.
0
Critical Bugs in Chaos Mesh Enable Cluster Takeover
Việt Nam Hacker
"Chaotic Deputy" is a set of four vulnerabilities in the chaos engineering platform that many organizations use to test the resilience of their Kubernetes environments.
0
'Vane Viper' Threat Group Tied to PropellerAds, Commercial Entities
Việt Nam Hacker
Researchers say the commercial adtech platform and several other companies form the infrastructure of a massive cybercrime operation.
0
'HybridPetya' Ransomware Bypasses Secure Boot
Việt Nam Hacker
The malware, which has traits of Petya ransomware and the infamous NotPetya wiper, is designed to target UEFI-based systems, according to researchers.
0
SecurityScorecard Buys AI Automation Capabilities, Boosts Vendor Risk Management
Việt Nam Hacker
The company acquired HyperComply to help enterprises automate vendor security reviews and gain a real-time picture of the security of their entire supply chain.
0
FBI Warns of Threat Actors Hitting Salesforce Customers
Thứ Hai, 15 tháng 9, 2025
Việt Nam Hacker
The FBI's IC3 recently warned of two threat actors, UNC6040 and UNC6395, targeting Salesforce customers, separately and in tandem.
0
'Lies-in-the-Loop' Attack Defeats AI Coding Agents
Việt Nam Hacker
Researchers convince Anthropic's AI-assisted coding tool to engage in dangerous behavior by lying to it, paving the way for a supply chain attack.
0
French Advisory Sheds Light on Apple Spyware Activity
Thứ Sáu, 12 tháng 9, 2025
Việt Nam Hacker
CERT-FR's advisory follows last month's disclosure of a zero-day flaw Apple said was used in "sophisticated" attacks against targeted individuals.
0
'Gentlemen' Ransomware Abuses Vulnerable Driver to Kill Security Gear
Thứ Năm, 11 tháng 9, 2025
Việt Nam Hacker
By weaponizing the ThrottleStop.sys driver, attackers are disrupting antivirus and endpoint detection and response (EDR) systems.
0
AI-Enhanced Malware Sports Super-Stealthy Tactics
Việt Nam Hacker
With legit sounding names, EvilAI's "productivity" apps are reviving classic threats like Trojans while adding new evasion capabilities against modern antivirus defenses.
0
Vidar Infostealer Back with a Vengeance
Việt Nam Hacker
The pervasive Vidar infostealer has evolved with a suite of new evasion techniques and covert data exfiltration methods, according to researchers.
0
'K2 Think' AI Model Jailbroken Mere Hours After Release
Việt Nam Hacker
Researchers discovered that measures designed to make AI more transparent to users and regulators can also make it easier for bad actors to abuse.
0
Russian APT Attacks Kazakhstan's Largest Oil Company
Việt Nam Hacker
Researchers say a likely Russian APT used a compromised employee email account to attack Kazakhstan's biggest company, though the oil and gas firm claims it was a pen test.
0
Students Pose Inside Threat to Education Sector
Thứ Tư, 10 tháng 9, 2025
Việt Nam Hacker
0
Chinese Hackers Allegedly Pose as US Lawmaker
Việt Nam Hacker
Chinese state-backed threat actors are suspected of posing as Michigan congressman John Moolenaar in a series of spearphishing attacks.
0
EoP Flaws Again Lead Microsoft Patch Day
Thứ Ba, 9 tháng 9, 2025
Việt Nam Hacker
Nearly half the CVEs Microsoft disclosed in its September security update, including one publicly known bug, enable escalation of privileges.
0
Qantas Reduces Executive Pay Following Cyberattack
Việt Nam Hacker
The data breach, which occurred earlier this year, saw threat actors compromise a third-party platform to obtain Qantas customers' personal information.
0
Huge NPM Supply-Chain Attack Goes Out With Whimper
Việt Nam Hacker
Threat actors phished Qix's NPM account, then used their access to publish poisoned versions of 18 popular open-source packages accounting for more than 2 billion weekly downloads.
0
Salty2FA Takes Phishing Kits to Enterprise Level
Việt Nam Hacker
Cybercriminal operations use the same strategy and planning as legitimate organizations as they arm adversarial phishing kits with advanced features.
0
SentinelOne Announces Plans to Acquire Observo AI
Việt Nam Hacker
The combined company will help customers separate data ingestion from SIEM, to improve detection and performance.
0
'MostereRAT' Malware Blends In, Blocks Security Tools
Thứ Hai, 8 tháng 9, 2025
Việt Nam Hacker
A threat actor is using a sophisticated EDR-killing malware tool in a campaign to maintain long-term, persistent access on Windows systems.
0
Salesloft Breached via GitHub Account Compromise
Việt Nam Hacker
The breach kickstarted a massive supply chain attack that led to the compromise of hundreds of Salesforce instances through stolen OAuth tokens.
0
45 New Domains Linked to Salt Typhoon, UNC4841
Việt Nam Hacker
The China-backed threat actors have used the previously undiscovered infrastructure to obtain long-term, stealthy access to targeted organizations.
0
Scammers Are Using Grok to Spread Malicious Links on X
Thứ Sáu, 5 tháng 9, 2025
Việt Nam Hacker
It's called "grokking," and gives spammers a way to skirt X's ban on links in promoted posts and reach larger audiences than ever before.
0
Anyone Using Agentic AI Needs to Understand Toxic Flows
Việt Nam Hacker
The biggest vulnerabilities may lie at the boundaries of where the AI agent connects with the enterprise system.
0
ISC2 Aims to Bridge DFIR Skill Gap with New Certificate
Thứ Năm, 4 tháng 9, 2025
Việt Nam Hacker
The Nonprofit organization launched the Threat Handling Foundations Certificate amid mounting incident and breach disclosures.
0
Czech Warning Highlights China Stealing User Data
Việt Nam Hacker
Czech cyber agency NÚKIB warned of the risks of using products and software that send data back to China.
0
Blast Radius of Salesloft Drift Attacks Remains Uncertain
Việt Nam Hacker
Many high-profile Salesloft Drift customers have disclosed data breaches as a result of a recent supply-chain attack, but the extent and severity of this campaign are unclear.
0
Japan, South Korea Take Aim at North Korean IT Worker Scam
Thứ Tư, 3 tháng 9, 2025
Việt Nam Hacker
With the continued success of North Korea's IT worker scams, Asia-Pacific nations are working with private firms to blunt the scheme's effectiveness.
0
Cloudflare Holds Back the Tide on 11.5Tbps DDoS Attack
Việt Nam Hacker
It's the equivalent of watching more than 9,350 full-length HD movies or streaming 7,480 hours of high-def video nonstop in less than a minute.
0
Hacked Routers Linger on the Internet for Years, Data Shows
Việt Nam Hacker
While trawling Internet scan data for signs of compromised infrastructure, researchers found that asset owners may not know for years their devices had been hacked.
0
Amazon Stymies APT29 Credential Theft Campaign
Thứ Ba, 2 tháng 9, 2025
Việt Nam Hacker
A group linked to Russian intelligence services redirected victims to fake Cloudflare verification pages and exploited Microsoft's device code authentication flow.
0
Zscaler, Palo Alto Networks Breached via Salesloft Drift
Việt Nam Hacker
Two major security firms suffered downstream compromises as part of a large-scale supply chain attack involving Salesloft Drift, a marketing SaaS application from Salesforce.
0
Jaguar Land Rover Shuts Down in Scramble to Secure 'Cyber Incident'
Việt Nam Hacker
0
JSON Config File Leaks Azure ActiveDirectory Credentials
Việt Nam Hacker
In this type of misconfiguration, cyberattackers could use exposed secrets to authenticate directly via Microsoft’s OAuth 2.0 endpoints and infiltrate Azure cloud environments.
0
Hackers Are Sophisticated & Impatient — That Can Be Good
Việt Nam Hacker
You can't negotiate with hackers from a place of fear — but you can turn their urgency against them with the right playbook, people, and preparation.
0
NIST Enhances Security Controls for Improved Patching
Việt Nam Hacker
The U.S. National Institute of Standards and Technology released Security and Privacy Control version 5.2.0 to help organizations be more proactive regarding patching.
0
Akira, Cl0p Top List of 5 Most Active Ransomware-as-a-Service Groups
Thứ Năm, 28 tháng 8, 2025
Việt Nam Hacker
Flashpoint published its 2025 midyear ransomware report that highlighted the top five most prolific groups currently in operation.
0
1,000+ Devs Lose Their Secrets to an AI-Powered Stealer
Việt Nam Hacker
One of the most sophisticated supply chain attacks to date caused immense amounts of data to leak to the Web in a matter of hours.
0
Dark Reading Confidential: A Guided Tour of Today's Dark Web
Việt Nam Hacker
Dark Reading Confidential Episode 9: Join us for a look around today's Dark Web, and find out how law enforcement, AI, nation-state activities, and more are reshaping the way cybercriminals conduct their dirty business online. Keith Jarvis, senior security researcher at Sophos' Counter Threat Unit joins Dark Reading's Alex Culafi for a conversation you don't want to miss.
0
'ZipLine' Phishers Flip Script as Victims Email First
Thứ Tư, 27 tháng 8, 2025
Việt Nam Hacker
"ZipLine" appears to be a sophisticated and carefully planned campaign that has already affected dozens of small, medium, and large organizations across multiple industry sectors.
0
China Hijacks Captive Portals to Spy on Asian Diplomats
Việt Nam Hacker
The Mustang Panda APT is hijacking Google Chrome browsers when they attempt to connect to new networks and redirecting them to phishing sites.
0
Google: Salesforce Attacks Stemmed From Third-Party App
Việt Nam Hacker
A group tracked as UNC6395 engaged in "widespread data theft" via compromised OAuth tokens from a third-party app called Salesloft Drift.
0
Malicious Scanning Waves Slam Remote Desktop Services
Thứ Ba, 26 tháng 8, 2025
Việt Nam Hacker
Researchers say the huge spike of coordinated scanning for Microsoft RDP services could indicate the existence of a new, as-yet-undisclosed vulnerability.
0
Data I/O Becomes Latest Ransomware Attack Victim
Việt Nam Hacker
The "incident" led to outages affecting a variety of the tech company's operations, though the full scope of the breach is unknown.
0
Hook Android Trojan Now Delivers Ransomware-Style Attacks
Việt Nam Hacker
New features to take over smartphones and monitor user activity demonstrate the continued evolution of the malware, which is now being spread on GitHub.
0
Hackers Lay In Wait, Then Knocked Out Iran Ship Comms
Thứ Hai, 25 tháng 8, 2025
Việt Nam Hacker
Lab-Dookhtegen claims major attack on more than 60 cargo ships and oil tankers belonging to two Iranian companies on US sanctions list.
0
ClickFix Attack Tricks AI Summaries Into Pushing Malware
Việt Nam Hacker
Because instructions appear to come from AI-generated content summaries and not an external source, the victim is more likely to follow them without suspicion.
0
Fast-Spreading, Complex Phishing Campaign Installs RATs
Việt Nam Hacker
Attackers not only steal credentials but also can maintain long-term, persistent access to corporate networks through the global campaign.
0
Securing the Cloud in an Age of Escalating Cyber Threats
Việt Nam Hacker
As threats intensify and cloud adoption expands, organizations must leave outdated security models behind.
0
Silk Typhoon Attacks North American Orgs in the Cloud
Thứ Sáu, 22 tháng 8, 2025
Việt Nam Hacker
A Chinese APT is going where most APTs don't: deep into the cloud, compromising supply chains and deploying uncommon malware.
0
Apple Intelligence Is Picking Up More User Data Than Expected, Researcher Finds
Việt Nam Hacker
Music tastes, location information, even encrypted messages — Apple's servers are gathering a "surprising" amount of personal data through Apple Intelligence, Lumia Security's Yoav Magid warns in his new analysis.
0
Interpol Arrests Over 1K Cybercriminals in 'Operation Serengeti 2.0'
Việt Nam Hacker
The operation disrupted countless scams, and authorities seized a significant amount of evidence and recovered nearly $100 million in lost funds.
0
Why Video Game Anti-Cheat Systems Are a Cybersecurity Goldmine
Thứ Năm, 21 tháng 8, 2025
Việt Nam Hacker
Sam Collins and Marius Muench of the University of Birmingham, UK, join the Black Hat USA 2025 News Desk to explain how anti-cheat systems in video games provide valuable lessons on defending against threat actors' techniques and strategies.
0
Hackers Abuse VPS Infrastructure for Stealth, Speed
Việt Nam Hacker
New research highlights how threat actors abuse legitimate virtual private server offerings in order to spin up infrastructure cheaply, quietly, and fast.
0
Tree of AST: A Bug-Hunting Framework Powered by LLMs
Việt Nam Hacker
Teenaged security researchers Sasha Zyuzin and Ruikai Peng discuss how their new vulnerability discovery framework leverages LLMs to address limitations of the past.
0
FBI, Cisco Warn of Russian Attacks on 7-Year-Old Flaw
Thứ Tư, 20 tháng 8, 2025
Việt Nam Hacker
In the past year, "Static Tundra," aka "Energetic Bear," has breached thousands of end-of-life Cisco devices unpatched against a 2018 flaw, in a campaign targeting enterprises and critical infrastructure.
0
Hacker Finds Flaws in McDonald’s Staff, Partner Hubs
Việt Nam Hacker
Exposure of APIs, sensitive data, and corporate documents are just some of the security issues that the purveyor of Big Macs was cooking up.
0
'RingReaper' Sneaks Right Past Linux EDRs
Thứ Ba, 19 tháng 8, 2025
Việt Nam Hacker
The highly sophisticated post-compromise tool abuses the Linux kernel's io_uring interface to remain hidden from endpoint detection and response systems.
0
AI Agents Access Everything, Fall to Zero-Click Exploit
Việt Nam Hacker
Zenity CTO Michael Bargury joins the Black Hat USA 2025 News Desk to discuss research on a dangerous exploit, how generative AI technology has "grown arms and legs" —and what that means for cyber risk.
0
Millions Allegedly Affected in Allianz Insurance Breach
Việt Nam Hacker
Have I Been Pwned claims that the compromised data includes physical addresses, dates of birth, phone numbers, and more, for life insurance customers.
0
PipeMagic Backdoor Resurfaces as Part of Play Ransomware Attack Chain
Việt Nam Hacker
Attackers are wielding the sophisticated modular malware while exploiting CVE-2025-29824, a previously zero-day flaw in Windows Common Log File System (CLFS) that allows attackers to gain system-level privileges on compromised systems.
0
'DripDropper' Hackers Patch Their Own Exploit
Việt Nam Hacker
An attacker is breaking into Linux systems via a widely abused 2-year-old vulnerability in Apache ActiveMQ, installing malware and then patching the flaw.
0
Secure AI Use Without the Blind Spots
Việt Nam Hacker
0
Noodlophile Stealer Hides Behind Bogus Copyright Complaints
Thứ Hai, 18 tháng 8, 2025
Việt Nam Hacker
Noodlophile is targeting enterprises in spear-phishing attacks using copyright claims as phishing lures.
0
Workday Breach Likely Linked to ShinyHunters Salesforce Attacks
Việt Nam Hacker
The HR giant said hackers mounted a socially engineered cyberattack on its third-party CRM system, but did not gain access to customer information; only 'commonly available' business contact info was exposed.
0
Internet-wide Vulnerability Enables Giant DDoS Attacks
Việt Nam Hacker
A good chunk of all websites today have been affected by the biggest DDoS risk on the Web since 2023.
0
Defending Against Cloud Threats Across Multicloud Environments
Việt Nam Hacker
The vast majority of companies are using more than one cloud platform, yet struggle to establish and monitor security across different environments giving attackers an opening.
0
New Quantum-Safe Alliance Aims to Accelerate PQC Implementation
Việt Nam Hacker
The new Quantum-Safe 360 Alliance will provide road maps, technology, and services to help organizations navigate the post-quantum cryptography transition before the 2030 deadline.
0
New Crypto24 Ransomware Attacks Bypass EDR
Thứ Sáu, 15 tháng 8, 2025
Việt Nam Hacker
While several cybercrime groups have embraced "EDR killers," researchers say the deep knowledge and technical skills demonstrated by Crypto24 signify a dangerous escalation.
0
Colt Telecommunications Struggles in Wake of Cyber Incident
Việt Nam Hacker
The UK telco said it temporarily took some systems offline as a "protective" measure in its investigation.
0
How Maclaren Racing Gets From the Browser to the Track
Thứ Năm, 14 tháng 8, 2025
Việt Nam Hacker
In a conversation with Dark Reading's Terry Sweeney, Dr. Lisa Jarman from McLaren Racing says cutting-edge innovation must coexist with rigorous security protocols.
0
Cybersecurity Spending Slows & Security Teams Shrink
Việt Nam Hacker
Security budgets are lowest in healthcare, professional and business services, retail, and hospitality, but budget growth remained above 5% in financial services, insurance, and tech.
0
Google Chrome Enterprise: Keeping Businesses Safe From Threats on the Web
Việt Nam Hacker
Dark Reading's Terry Sweeney and Google Cloud Security's Jason Kemmerer discuss how organizations can secure the modern workplace with zero trust browser protection for remote and hybrid teams.
0
Whispers of XZ Utils Backdoor Live on in Old Docker Images
Thứ Tư, 13 tháng 8, 2025
Việt Nam Hacker
Developers maintaining the images made the "intentional choice" to leave the artifacts available as "a historical curiosity," given the improbability they'd be exploited.
0
How an AI-Based 'Pen Tester' Became a Top Bug Hunter on HackerOne
Việt Nam Hacker
AI researcher explains how an automated penetration-testing tool became the first non-human member on HackerOne to reach the top of the platform's US leaderboard.
0
Patch Now: Attackers Target OT Networks via Critical RCE Flaw
Việt Nam Hacker
Researchers observed exploitation attempts against a vulnerability with a CVSS score of 10 in a popular Erlang-based platform for critical infrastructure and OT development.
0
What the LockBit 4.0 Leak Reveals About RaaS Groups
Việt Nam Hacker
The leak serves as a wake-up call: Being prepared is the cornerstone of a successful defense, and those who don't prepare are going to face uncertainty caused by the lack of attackers' accountability.
0
China Questions Security of AI Chips From Nvidia, AMD
Thứ Ba, 12 tháng 8, 2025
Việt Nam Hacker
The US banned the sale of AI chips to China and then backed off. Now, Chinese sources are calling on NVIDIA to prove its AI chips have no backdoors.
0
Elevation-of-Privilege Vulns Dominate Microsoft's Patch Tuesday
Việt Nam Hacker
The company's August security update consisted of patches for 111 unique Common Vulnerabilities and Exposures (CVEs).
0
Black Hat NOC Expands AI Implementation Across Security Operations
Việt Nam Hacker
Corelight's James Pope gave Dark Reading an inside look at this year's Black Hat Network Operations Center, detailing security challenges and rising trends — many related to increased AI use.
0
BlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement
Thứ Hai, 11 tháng 8, 2025
Việt Nam Hacker
A swarm of US agencies joined with international partners to take down servers and domains and seize more than $1 million associated with BlackSuit (Royal) ransomware operations, a group that has been a chronic, persistent threat against critical infrastructure.
0
REvil Actor Accuses Russia of Planning 2021 Kaseya Attack
Việt Nam Hacker
REvil affiliate Yaroslav Vasinskyi, who was convicted last year for his role in the 2021 Kaseya ransomware supply chain attack, said the Russian government was instrumental to the attack's execution.
0
Echo Chamber, Prompts Used to Jailbreak GPT-5 in 24 Hours
Việt Nam Hacker
Researchers paired the jailbreaking technique with storytelling in an attack flow that used no inappropriate language to guide the LLM into producing directions for making a Molotov cocktail.
0
Utilities, Factories at Risk From Encryption Holes in Industrial Protocol
Việt Nam Hacker
The OPC UA communication protocol is widely used in industrial settings, but despite its complex cryptography, the open source protocol appears to be vulnerable in a number of different ways.
0
Will Secure AI Be the Hottest Career Path in Cybersecurity?
Việt Nam Hacker
Securing AI systems represents cybersecurity's next frontier, creating specialized career paths as organizations grapple with novel vulnerabilities, regulatory requirements, and cross-functional demands.
0
860K Compromised in Columbia University Data Breach
Thứ Sáu, 8 tháng 8, 2025
Việt Nam Hacker
While no data has yet to be misused, the university doesn't rule out the possibility of that occurring in the future, prompting it to warn affected individuals to remain vigilant in the wake of the breach.
0
BigID Launches Shadow AI Discovery to Uncover Rogue Models and Risky AI Data
Việt Nam Hacker
0
Ransomware Attacks Fall by Almost Half in Q2
Việt Nam Hacker
0
Privilege Escalation Issue in Amazon ECS Leads to IAM Hijacking
Thứ Năm, 7 tháng 8, 2025
Việt Nam Hacker
A software developer discovered a way to abuse an undocumented protocol in Amazon's Elastic Container Service to escalate privileges, cross boundaries and gain access to other cloud resources.
0
Citizen Lab Founder Flags Rise of US Authoritarianism
Việt Nam Hacker
Citizen Lab director and founder Ron Deibert explained how civil society is locked in "vicious cycle," and human rights are being abused as a result, covering Israeli spyware, the Khashoggi killing, and an erosion of democratic norms in the US.
0
Payback: 'ShinyHunters' Clocks Google via Salesforce
Việt Nam Hacker
In 2024, it was Snowflake. In 2025, it's Salesforce. ShinyHunters is back, with low-tech hacks that nonetheless manage to bring down international megaliths like Google, Cisco, and Adidas.
0
Critical Zero-Day Bugs Crack Open CyberArk, HashiCorp Password Vaults
Thứ Tư, 6 tháng 8, 2025
Việt Nam Hacker
Secrets managers hold all the keys to an enterprise's kingdom. Two popular ones had longstanding, critical, unauthenticated RCE vulnerabilities.
0
'ReVault' Security Flaws Impact Millions of Dell Laptops
Việt Nam Hacker
The now-patched vulnerabilities exist at the firmware level and enable deep persistence on compromised systems.
0
Google Gemini AI Bot Hijacks Smart Homes, Turns Off the Lights
Việt Nam Hacker
Using invisible prompts, the attacks demonstrate a physical risk that could soon become reality as the world increasingly becomes more interconnected with artificial intelligence.
0
Pandora Confirms Third-Party Data Breach, Warns of Phishing Attempts
Thứ Ba, 5 tháng 8, 2025
Việt Nam Hacker
0
Cisco User Data Stolen in Vishing Attack
Việt Nam Hacker
The networking giant said this week that an employee suffered a voice phishing attack that resulted in the compromise of select user data, including email addresses and phone numbers.
0
Google Chrome Enterprise: More Than an Access Point to the Web
Việt Nam Hacker
In a conversation with Dark Reading's Terry Sweeney, Lauren Miskelly from Google explains that Chrome Enterprise is the same Chrome browser that consumers use, but with additional enterprise-grade controls, reporting capabilities, and administrative features.
0
Threat Actors Increasingly Leaning on GenAI Tools
Thứ Hai, 4 tháng 8, 2025
Việt Nam Hacker
From "eCrime" actors to fake IT tech workers, CrowdStrike researchers found that adversaries are using AI to enhance their offensive cyber operations.
0
42% of Developers Using AI Say Their Codebase is Now Mostly AI-Generated
Việt Nam Hacker
0
Akira Ramps Up Assault on SonicWall Firewalls, Suggesting Zero-Day
Việt Nam Hacker
An uptick of ransomware activity by the group in late July that uses the vendor's SSL VPN devices for initial intrusion shows evidence of an as-yet-undisclosed flaw under exploitation.
0
Turning Human Vulnerability Into Organizational Strength
Việt Nam Hacker
Investing in building a human-centric defense involves a combination of adaptive security awareness training, a vigilant and skeptical culture, and the deployment of layered technical controls.
0
What Is the Role of Provable Randomness in Cybersecurity?
Việt Nam Hacker
Random numbers are the cornerstone of cryptographic security — cryptography depends on generating random keys. As organizations adopt quantum-resistant algorithms, it's equally important to examine the randomness underpinning them
0
Dark Reading News Desk Turns 10, Back at Black Hat USA for 2025
Thứ Sáu, 1 tháng 8, 2025
Việt Nam Hacker
Dark Reading's 2025 News Desk marks a decade of Black Hat USA memories. We're making our return with a slate of interviews that help you stay up on the latest research from Black Hat — no trip to Las Vegas required.
0
ISC2 Launches New Security Certificate for AI Expertise
Việt Nam Hacker
ISC2 is launching a 6-course certification program to address the growing demand for AI security expertise. Courses cover topics such as AI fundamentals, ethics, and risks.
0
Gen Z Falls for Scams 2x More Than Older Generations
Thứ Năm, 31 tháng 7, 2025
Việt Nam Hacker
Forget gullible old people — Gen Z is the most at-risk age group on the Web. Older folks might want to ignore it, but employers are likely to feel the brunt.
0
DragonForce Ransom Cartel Profits Off Rivals' Demise
Việt Nam Hacker
The fall of RansomHub led to a major consolidation of the ransomware ecosystem last quarter, which was a boon for the DragonForce and Qilin gangs.
0
SafePay Claims Ingram Micro Breach, Sets Ransom Deadline
Việt Nam Hacker
The ransomware gang claims to have stolen 3.5TB of data, and told the technology distributor to pay up or suffer a data breach.
0
3 Things CFOs Need to Know About Mitigating Threats
Việt Nam Hacker
To reposition cybersecurity as a strategic, business-critical investment, CFOs and CISOs play a critical role in articulating the significant ROI that robust security measures can deliver.
0
Inside the FBI's Strategy for Prosecuting Ransomware
Việt Nam Hacker
The US government is throwing the book at even mid-level cybercriminals. Is it just, and is it working?
0
Koreans Hacked, Blackmailed by 250+ Fake Mobile Apps
Thứ Tư, 30 tháng 7, 2025
Việt Nam Hacker
A swath of copycat Korean apps are hiding spyware, occasionally leading to highly personal, disturbing extortions.
0
Silk Typhoon Linked to Powerful Offensive Tools, PRC-Backed Companies
Việt Nam Hacker
An unsealed indictment associated with the Chinese threat group shows its members worked for companies closely aligned with the PRC as part of a larger contractor ecosystem.
0
The CrowdStrike Outage Was Bad, but It Could Have Been Worse
Việt Nam Hacker
A year after the largest outage in IT history, organizations need to make an active effort to diversify their technology and software vendors and create a more resilient cyber ecosystem moving forward.
0
Attackers Can Use Browser Extensions to Inject AI Prompts
Việt Nam Hacker
A proof-of-concept attack shows how threat actors can use a poisoned browser extension to inject malicious prompts into a generative AI tool.
0
African Orgs Fall to Mass Microsoft SharePoint Exploits
Việt Nam Hacker
The National Treasury of South Africa is among the half-dozen known victims in South Africa — along with other nations — of the mass compromise of on-premises Microsoft SharePoint servers.
0
Nimble 'Gunra' Ransomware Evolves With Linux Variant
Thứ Ba, 29 tháng 7, 2025
Việt Nam Hacker
The emerging cybercriminal gang, which initially targeted Microsoft Windows systems, is looking to go cross-platform using sophisticated, multithread encryption.
0
New Risk Index Helps Organizations Tackle Cloud Security Chaos
Việt Nam Hacker
Enterprises can use the IaC Risk Index to identify vulnerable cloud resources in their infrastructure-as-code environment which are not managed or governed.
0
Insurance Giant Allianz Life Grapples With Breach Affecting 'Majority' of Customers
Thứ Hai, 28 tháng 7, 2025
Việt Nam Hacker
The company has yet to report an exact number of how many individuals were impacted by the breach and plans to start the notification process around Aug. 1.
0
Chaos Ransomware Rises as BlackSuit Gang Falls
Việt Nam Hacker
Researchers detailed a newer double-extortion ransomware group made up of former members of BlackSuit, which was recently disrupted by international law enforcement.
0
Sophisticated Shuyal Stealer Targets 19 Browsers, Demonstrates Advanced Evasion
Việt Nam Hacker
A new infostealing malware making the rounds can exfiltrate credentials and other system data even from browsing software considered more privacy-focused than mainstream options.
0
How to Spot Malicious AI Agents Before They Strike
Việt Nam Hacker
The rise of agentic AI means the battle of the machines is just beginning. To win, we'll need our own agents — human and machine — working together.
0
Cyber Career Opportunities: Weighing Certifications vs. Degrees
Thứ Sáu, 25 tháng 7, 2025
Việt Nam Hacker
Longtime CISO Melina Scotto joins Dark Reading to discuss career advice gleaned from her 30 years in the cyber industry.
0
'Fire Ant' Cyber Spies Compromise Siloed VMware Systems
Việt Nam Hacker
Suspected China-nexus threat actors targeted virtual environments and used several tools and techniques to bypass security barriers and reach isolated portions of victims' networks.
0
AI-Generated Linux Miner 'Koske' Beats Human Malware
Việt Nam Hacker
AI malware is becoming less of a gimmick, with features that meet or exceed what traditional human-developed malware typically can do.
0
North Korea's IT Worker Rampage Continues Amid DoJ Action
Việt Nam Hacker
Arrests and indictments keep coming, but the North Korean fake IT worker scheme is only snowballing, and businesses can't afford to assume their applicant-screening processes are up to the task of weeding the imposters out.
0
The Young and the Restless: Young Cybercriminals Raise Concerns
Việt Nam Hacker
National governments warn that many hacker groups attract young people through a sense of community, fame, or the promise of money and the perception of a lack of risk of prosecution.
0
Can Security Culture Be Taught? AWS Says Yes
Việt Nam Hacker
Newly appointed Amazon Web Services CISO Amy Herzog believes security culture goes beyond frameworks and executive structures. Having the right philosophy throughout the organization is key.
0
Ransomware Actors Pile on 'ToolShell' SharePoint Bugs
Thứ Năm, 24 tháng 7, 2025
Việt Nam Hacker
Storm-2603, a China-based threat actor, is targeting SharePoint customers in an ongoing ransomware campaign.
0
Department of Education Site Mimicked in Phishing Scheme
Thứ Tư, 23 tháng 7, 2025
Việt Nam Hacker
An ongoing phishing campaign is using fake versions of the department's G5 grant portal, taking advantage of political turmoil associated with the DoE's 1,400 layoffs.
0
US Nuclear Agency Hacked in Microsoft SharePoint Frenzy
Việt Nam Hacker
Threat actors are piling on the zero-day vulnerabilities in SharePoint, including at least three Chinese nation-state cyberespionage groups.
0
Microsoft Integrates Data Lake With Sentinel SIEM
Việt Nam Hacker
Microsoft Sentinel Data Lake aims to provide inexpensive storage for large volumes of telemetry, while threat intelligence will be included with Defender XDR at no extra cost.
0
CISO Conversations: How IT and OT Security Worlds Are Converging
Việt Nam Hacker
Dark Reading's Kelly Jackson Higgins interviews Carmine Valente, Deputy CISO at Con Edison, about his role at the New York-based electric utility and the state of IT and OT security. Valente highlights current threats like ransomware and supply chain attacks, as well as the impact of AI on both defense and threats.
0
China Introduces National Cyber ID Amid Privacy Concerns
Thứ Ba, 22 tháng 7, 2025
Việt Nam Hacker
China officially rolled out a voluntary Internet identity system to protect citizens' online identities and personal information, but critics worry about privacy and surveillance.
0
3 China Nation-State Actors Target SharePoint Bugs
Việt Nam Hacker
Hackers and cybercrime groups are part of a virtual feeding frenzy, after Microsoft's recent disclosure of new vulnerabilities in on-premises editions of SharePoint Server.
0
Human Digital Twins Could Give Attackers a Dangerous Advantage
Việt Nam Hacker
While this emerging technology offers many benefits, digital twins also have several drawbacks, as these convincing impersonations can be used in social engineering attacks.
0
China-Backed APT41 Cyberattack Surfaces in Africa
Việt Nam Hacker
Up to now, the prolific China-sponsored cyber-espionage group has been mostly absent from the region, but a sophisticated and highly targeted attack on an African IT company shows Beijing is branching out.
0
Malicious Implants Are Coming to AI Components, Applications
Thứ Hai, 21 tháng 7, 2025
Việt Nam Hacker
A red teamer is publishing research next month about how weaknesses in modern security products lay the groundwork for stealthy implants in AI-powered applications.
0
Europol Sting Leaves Russian Cybercrime's 'NoName057(16)' Group Fractured
Việt Nam Hacker
National authorities have issued seven arrest warrants in total relating to the cybercrime collective known as NoName057(16), which recruits followers to carry out DDoS attacks on perceived enemies of Russia.
0
Containment as a Core Security Strategy
Việt Nam Hacker
We cannot keep reacting to vulnerabilities as they emerge. We must assume the presence of unknown threats and reduce the blast radius that they can affect.
0
'PoisonSeed' Attacker Skates Around FIDO Keys
Thứ Sáu, 18 tháng 7, 2025
Việt Nam Hacker
Researchers discovered a novel phishing attack that serves the victim a QR code as part of supposed multifactor authentication (MFA), in order to get around FIDO-based protections.
0
Printer Security Gaps: A Broad, Leafy Avenue to Compromise
Thứ Năm, 17 tháng 7, 2025
Việt Nam Hacker
Security teams aren't patching firmware promptly, no one's vetting the endpoints before purchase, and visibility into potential dangers is limited — despite more and more cyberattackers targeting printers as a matter of course.
0
Armenian Extradited to US Over Ryuk Ransomware
Việt Nam Hacker
The suspect faces three charges for his alleged crimes that could earn him up to five years in federal prison, and a heap of fines.
0
Why Cybersecurity Still Matters for America's Schools
Việt Nam Hacker
Cyberattacks on educational institutions are growing. But with budget constraints and funding shortfalls, leadership teams are questioning whether — and how — they can keep their institutions safe.
0
ISC2 Finds Orgs Are Increasingly Leaning on AI
Thứ Tư, 16 tháng 7, 2025
Việt Nam Hacker
While many organizations are eagerly integrating AI into their workflows and cybersecurity practices, some remain undecided and even concerned about potential drawbacks of AI deployment.
0
Women Who 'Hacked the Status Quo' Aim to Inspire Cybersecurity Careers
Việt Nam Hacker
A group of female cybersecurity pioneers will share what they've learned about navigating a field dominated by men, in order to help other women empower themselves and pursue successful cybersecurity careers.
0
AI Is Reshaping How Attorneys Practice Law
Thứ Ba, 15 tháng 7, 2025
Việt Nam Hacker
Experts recommend enhanced AI literacy, training around the ethics of using AI, and verification protocols to maintain credibility in an increasingly AI-influenced courtroom.
0
AsyncRAT Spawns Concerning Labyrinth of Forks
Việt Nam Hacker
Since surfacing on GitHub in 2019, AsyncRAT has become a poster child for how open source malware can democratize cybercrime, with a mazelike footprint of variants available across the spectrum of functionality.
0
Attackers Abuse AWS Cloud to Target Southeast Asian Governments
Việt Nam Hacker
The intelligence-gathering cyber campaign introduces the novel HazyBeacon backdoor and uses legitimate cloud communication channels for command-and-control (C2) and exfiltration to hide its malicious activities.
0
MITRE Launches AADAPT Framework for Financial Systems
Việt Nam Hacker
The new framework is modeled after and meant to complement the MITRE ATT&CK framework, and it is aimed at detecting and responding to cyberattacks on cryptocurrency assets and other financial targets.
0
Web-Inject Campaign Debuts Fresh Interlock RAT Variant
Thứ Hai, 14 tháng 7, 2025
Việt Nam Hacker
A cyber-threat campaign is using legitimate websites to inject victims with remote access Trojans belonging to the Interlock ransomware group, in order to gain control of devices.
0
Military Veterans May Be What Cybersecurity Is Looking For
Việt Nam Hacker
As the field struggles with a shortage, programs that aim to provide veterans with the technical skills needed to succeed in cybersecurity may be the solution for everyone.
0
Google Gemini AI Bug Allows Invisible, Malicious Prompts
Việt Nam Hacker
A prompt-injection vulnerability in the AI assistant allows attackers to create messages that appear to be legitimate Google Security alerts but instead can be used to target users across various Google products with vishing and phishing.
0
The Dark Side of Global Power Shifts & Demographic Decline
Việt Nam Hacker
As global power realigns and economies falter, the rise in cybercrime is no longer hypothetical — it's inevitable.
0
350M Cars, 1B Devices Exposed to 1-Click Bluetooth RCE
Thứ Sáu, 11 tháng 7, 2025
Việt Nam Hacker
Mercedes, Skoda, and Volkswagen vehicles, as well as untold industrial, medical, mobile, and consumer devices, may be exposed to a vulnerable Bluetooth implementation called "PerfektBlue."
0
eSIM Bug in Millions of Phones Enables Spying, Takeover
Thứ Năm, 10 tháng 7, 2025
Việt Nam Hacker
eSIMs around the world may be fundamentally vulnerable to physical and network attacks because of a 6-year-old Oracle vulnerability in technology that underlies billions of cards.
0
Ingram Micro Up and Running After Ransomware Attack
Việt Nam Hacker
Customers were the first to notice the disruption on the distributor's website when they couldn't place orders online.
0
4 Arrested in UK Over M&S, Co-op, Harrods Hacks
Việt Nam Hacker
The UK's National Crime Agency arrested four people, who some experts believe are connected to the notorious cybercriminal collective known as Scattered Spider.
0
AirMDR Tackles Security Burdens for SMBs With AI
Việt Nam Hacker
This security startup provides managed detection and response services for small-to-midsized businesses to detect and address modern threats such as ransomware, phishing attacks, and malicious insiders.
0
North American APT Uses Exchange Zero-Day to Attack China
Thứ Tư, 9 tháng 7, 2025
Việt Nam Hacker
Stories about Chinese APTs attacking the US and Canada are plentiful. In a turnabout, researchers found what they believe is a North American entity attacking a Chinese entity, thanks to a mysterious issue in Microsoft Exchange.
0
A NVIDIA Container Bug & Chance to Harden Kubernetes
Việt Nam Hacker
A container escape flaw involving the NVIDIA Container Toolkit could have enabled a threat actor to access AI datasets across tenants.
0
New AI Malware PoC Reliably Evades Microsoft Defender
Việt Nam Hacker
Worried about hackers employing LLMs to write powerful malware? Using targeted reinforcement learning (RL) to train open source models in specific tasks has yielded the capability to do just that.
0
South Korean Government Imposes Penalties on SK Telecom for Breach
Thứ Ba, 8 tháng 7, 2025
Việt Nam Hacker
Following a breach at the country's top mobile provider that exposed 27 million records, the South Korean government imposed a small monetary penalty but stiff regulatory requirements.
0
Malicious Open Source Packages Spike 188% YoY
Việt Nam Hacker
Data exfiltration was the most common malware in Sonatype report, with more than 4,400 packages designed to steal secrets, personally identifiable information, credentials, and API tokens.
0
Suspected Hacker Linked to Silk Typhoon Arrested in Milan
Việt Nam Hacker
The alleged Chinese state-sponsored hacker faces multiple charges, including wire fraud, aggravated identity theft, and unauthorized access to protected computers.
0
DPRK macOS 'NimDoor' Malware Targets Web3, Crypto Platforms
Thứ Hai, 7 tháng 7, 2025
Việt Nam Hacker
Researchers observed North Korean threat actors targeting cryptocurrency and Web3 platforms on Telegram using malicious Zoom meeting requests.
0
Ransomware Attack Triggers Widespread Outage at Ingram Micro
Việt Nam Hacker
The outage began shortly before the July 4 holiday weekend and caused disruptions for customer ordering and other services provided by the IT distributor.
0
'Hunters International' RaaS Group Closes Its Doors
Việt Nam Hacker
The announcement comes just months after security researchers observed that the group was making the transition to rebrand to World Leaks, a data theft outfit.
0
Chrome Store Features Extension Poisoned With Sophisticated Spyware
Việt Nam Hacker
A color picker for Google's browser with more than 100,000 downloads hijacks sessions every time a user navigates to a new webpage and also redirects them to malicious sites.
0
US Treasury Sanctions BPH Provider Aeza Group
Thứ Tư, 2 tháng 7, 2025
Việt Nam Hacker
In the past, the bulletproof group has been affiliated with many well-known ransomware and malware groups, such as BianLian and Lumma Stealer.
0
Russian APT 'Gamaredon' Hits Ukraine With Fierce Phishing
Việt Nam Hacker
A Russian APT known as "Gamaredon" is using spear-phishing attacks and network-drive weaponization to target government entities in Ukraine.
0
ClickFix Spin-off Attack Bypasses Key Browser Safeguards
Việt Nam Hacker
A new threat vector exploits how modern browsers save HTML files, bypassing Mark of the Web and giving attackers another social-engineering attack for delivering malware.
0
1 Year Later: Lessons Learned From the CrowdStrike Outage
Việt Nam Hacker
The ever-growing volume of vulnerabilities and threats requires organizations to remain resilient and anti-fragile — that is, to be able to proactively respond to issues and continuously improve.
0
Scope, Scale of Spurious North Korean IT Workers Emerges
Thứ Ba, 1 tháng 7, 2025
Việt Nam Hacker
Microsoft warns thousands of North Korean workers have infiltrated tech, manufacturing, and transportation sectors to steal money and data.
0
We've All Been Wrong: Phishing Training Doesn't Work
Việt Nam Hacker
Teaching employees to detect malicious emails isn't really having an impact. What other options do organizations have?
0
DoJ Disrupts North Korean IT Worker Scheme Across Multiple US States
Việt Nam Hacker
The US also conducted searches of 29 "laptop farms" across 16 states and seized 29 financial accounts used to launder funds.
0
Scattered Spider Hacking Spree Continues With Airline Sector Attacks
Thứ Hai, 30 tháng 6, 2025
Việt Nam Hacker
0
Chinese Company Hikvision Banned By Canadian Government
Việt Nam Hacker
Though the company's video surveillance products will be prohibited for government use, individuals and private businesses can still buy the vendor's products.
0
Airoha Chip Vulns Put Sony, Bose Earbuds & Headphones at Risk
Việt Nam Hacker
The vulnerabilities, which have yet to be published, could allow a threat actor to hijack not only Bluetooth earbuds and headphones but also the devices connected to them.
0
AI-Themed SEO Poisoning Attacks Spread Info, Crypto Stealers
Việt Nam Hacker
Malicious websites designed to rank high in Google search results for ChatGPT and Luma AI deliver the Lumma and Vidar infostealers and other malware.
0
Why Cybersecurity Should Come Before AI in Schools
Việt Nam Hacker
The sooner we integrate cybersecurity basics into school curriculum, the stronger and more resilient our children — and their futures — will be.
0
Top Apple, Google VPN Apps May Help China Spy on Users
Thứ Sáu, 27 tháng 6, 2025
Việt Nam Hacker
Apple and Google espouse strong values about data privacy, but they allow programs from a Big Brother state to thrive on their app stores, researchers allege.
0
'CitrixBleed 2' Shows Signs of Active Exploitation
Việt Nam Hacker
If exploited, the critical vulnerability allows attackers to maintain access for longer periods of time than the original CitrixBleed flaw, all while remaining undetected.
0
Scattered Spider Taps CFO Credentials in 'Scorched Earth' Attack
Việt Nam Hacker
In a recent intrusion, the notorious cybercriminal collective accessed CyberArk vaults and obtained more 1,400 secrets, subverted Azure, VMware, and Snowflake environments, and for the first known time, actively fought back against incident response teams.
0
Vulnerability Debt: How Do You Put a Price on What to Fix?
Việt Nam Hacker
Putting a vulnerability debt figure together involves work, but having vulnerability debt figures lets you measure real-world values against your overall security posture.
0
US Falling Behind China in Exploit Production
Việt Nam Hacker
Cyber operations have become critical to national security, but the United States has fallen behind in one significant area — exploit production — while China has built up a significant lead.
0
'Cyber Fattah' Hacktivist Group Leaks Saudi Games Data
Thứ Năm, 26 tháng 6, 2025
Việt Nam Hacker
As tensions in the Middle East rise, hacktivist groups are coming out of the woodwork with their own agendas, leading to notable shifts in the hacktivist threat landscape.
0
'IntelBroker' Suspect Arrested, Charged in High-Profile Breaches
Việt Nam Hacker
A British national arrested earlier this year in France was charged by the US Department of Justice in connection with a string of major cyberattacks.
0
Charming Kitten APT Tries Spying on Israeli Cybersecurity Experts
Thứ Tư, 25 tháng 6, 2025
Việt Nam Hacker
Israel's cyber pros are having to put theory into practice, as a notorious nation-state APT sponsored by Iran targets them with spear-phishing attacks.
0
And Now Malware That Tells AI to Ignore It?
Việt Nam Hacker
Though rudimentary and largely non-functional, the wryly named "Skynet" binary could be a harbinger of things to come on the malware front.
0
Millions of Brother Printers Hit by Critical, Unpatchable Bug
Việt Nam Hacker
A slew of vulnerabilities, including a critical CVSS 9.8 that enables an attacker to generate the default admin password, affect hundreds of printer, scanner, and label-maker models made by manufacturer Brother.
0
CISA is Shrinking: What Does it Mean for Cyber?
Việt Nam Hacker
Dark Reading Confidential Episode 7: Cyber experts Tom Parker and Jake Williams offer their views on the practical impact of cuts to the US Cybersecurity and Infrastructure Security Agency.
0
Africa Sees Surge in Cybercrime as Law Enforcement Struggles
Thứ Ba, 24 tháng 6, 2025
Việt Nam Hacker
Cybercrime accounts for more than 30% of all reported crime in East Africa and West Africa, with online scams, ransomware, business email compromise, and digital sextortion taking off.
0
Threat Actor Trojanizes Copy of SonicWall NetExtender VPN App
Việt Nam Hacker
A threat actor hacked a version of SonicWall's NetExtender SSL VPN application in an effort to trick users into installing a Trojanized version of the product.
0
China-Nexus 'LapDogs' Network Thrives on Backdoored SOHO Devices
Việt Nam Hacker
The campaign infected devices in the US and Southeast Asia to build an operational relay box (ORB) network for use as an extensive cyber-espionage infrastructure.
0
Steel Giant Nucor Confirms Data Stolen in Cyberattack
Việt Nam Hacker
America's largest steel producer initially disclosed the breach in May and took potentially affected systems offline to investigation the intrusion and contain any malicious activity.
0
Citrix Patches Critical Vulns in NetScaler ADC and Gateway
Thứ Hai, 23 tháng 6, 2025
Việt Nam Hacker
Citrix is recommending its customers upgrade their appliances to mitigate potential exploitation of the vulnerabilities.
0
'Echo Chamber' Attack Blows Past AI Guardrails
Việt Nam Hacker
An AI security researcher has developed a proof of concept that uses subtle, seemingly benign prompts to get GPT and Gemini to generate inappropriate content.
0
DHS Warns of Rise in Cyberattacks in Light of US-Iran Conflict
Việt Nam Hacker
After President's Trump decision to enter the US into the conflict in the Middle East, the Department of Homeland Security expects there to be an uptick in Iranian hacktivists and state-sponsored actors targeting US systems.
0
Attackers Use Docker APIs, Tor Anonymity in Stealthy Crypto Heist
Việt Nam Hacker
The attack is similar to previous campaigns by an actor called Commando Cat to use misconfigured APIs to compromise containers and deploy cryptocurrency miners.
0
A CISO's AI Playbook
Việt Nam Hacker
In a market where security budgets flatten while threats accelerate, improving analyst throughput is fiscal stewardship.
0
AWS Enhances Cloud Security With Better Visibility Features
Thứ Sáu, 20 tháng 6, 2025
Việt Nam Hacker
At this week's re:Inforce 2025 conference, the cloud giant introduced new capabilities to several core security products to provide customers with better visibility and more context on potential threats.
0
Hackers Post Dozens of Malicious Copycat Repos to GitHub
Việt Nam Hacker
As package registries find better ways to combat cyberattacks, threat actors are finding other methods for spreading their malware to developers.
0
How Cyberwarfare Changes the Face of Geopolitical Conflict
Việt Nam Hacker
As geopolitical tensions rise, the use of cyber operations and hacktivists continues to grow, with the current conflict between Israel and Iran showing the new face of cyber-augmented war.
0
Telecom Giant Viasat Is Latest Salt Typhoon Victim
Việt Nam Hacker
The communications company shared the discoveries of its investigation with government partners, but there is little information they can publicly disclose other than that there seems to be no impact to customers.
0
How to Lock Down the No-Code Supply Chain Attack Surface
Việt Nam Hacker
Securing the no-code supply chain isn't just about mitigating risks — it's about enabling the business to innovate with confidence.
0
OpenAI Awarded $200M Contract to Work With DoD
Thứ Tư, 18 tháng 6, 2025
Việt Nam Hacker
OpenAI intends to help streamline the Defense Department's administrative processes using artificial intelligence.
0
New Tool Traps Jitters to Detect Beacons
Việt Nam Hacker
Concerned by rapidly evolving evasion tactics, the new Jitter-Trap tool from Varonis aims to help organizations detect beacons that help attackers establish communication inside a victim network.
0
The Triple Threat of Burnout: Overworked, Unsatisfied, Trapped
Việt Nam Hacker
Many cybersecurity professionals still don't feel comfortable admitting when they need a break. And the impact goes beyond being overworked.
0
GodFather Banking Trojan Debuts Virtualization Tactic
Việt Nam Hacker
The Android malware is targeting Turkish financial institutions, completely taking over legitimate banking and crypto apps by creating an isolated virtualized environment on a device.
0
Serpentine#Cloud Uses Cloudflare Tunnels in Sneak Attacks
Việt Nam Hacker
An unidentified threat actor is using .lnk Windows shortcut files in a series of sophisticated attacks utilizing in-memory code execution and living-off-the-land cyberattack strategies.
0
Indian Car-Sharing Firm Zoomcar Latest to Suffer Breach
Thứ Ba, 17 tháng 6, 2025
Việt Nam Hacker
The company acknowledged that cybercriminals had taken sensitive information on more than 8 million users, including names, phone numbers, car registration numbers, addresses, and emails.
0
'HoldingHands' Acts Like a Pickpocket With Taiwan Orgs
Việt Nam Hacker
Since at least January, the threat actor has been employing multiple malware tools to steal information for potential future attacks against Taiwanese businesses and government agencies.
0
Malicious Chimera Turns Larcenous on Python Package Index
Thứ Hai, 16 tháng 6, 2025
Việt Nam Hacker
Unlike typical data-stealing malware, this attack tool targets data specific to corporate and cloud infrastructures in order to execute supply chain attacks.
0
Anubis Ransomware-as-a-Service Kit Adds Data Wiper
Việt Nam Hacker
The threat of wiping files and servers clean gives Anubis affiliates yet another way to leverage ransomware victims who may be hesitant to pay to get their data back, Trend Micro said.
0
Washington Post Staffer Emails Targeted in Cyber Breach
Việt Nam Hacker
Journalists' Microsoft accounts were breached, which would have given attackers access to emails of staff reporters covering national security, economic policy, and China.
0
'Water Curse' Targets Infosec Pros Via Poisoned GitHub Repositories
Việt Nam Hacker
The emerging threat group attacks the supply chain via weaponized repositories posing as legitimate pen-testing suites and other tools that are poisoned with malware.
0
Security Is Only as Strong as the Weakest Third-Party Link
Việt Nam Hacker
Third-party risks are increasing dramatically, requiring CISOs to evolve from periodic assessments to continuous monitoring and treating partner vulnerabilities as their own to enhance organizational resilience.
0
NIST Outlines Real-World Zero-Trust Examples
Việt Nam Hacker
SP 1800-35 offers 19 examples of how to implement zero-trust architecture (ZTA) using off-the-shelf commercial technologies.
0
CISA Reveals 'Pattern' of Ransomware Attacks Against SimpleHelp RMM
Thứ Sáu, 13 tháng 6, 2025
Việt Nam Hacker
A new Cybersecurity and Infrastructure Security Agency (CISA) advisory warned ransomware actors have been actively exploiting a critical SimpleHelp flaw since January.
0
Cyberattacks on Humanitarian Orgs Jump Worldwide
Việt Nam Hacker
These groups suffered three times the cyberattacks as the year previous, with DDoS attacks dominating and vulnerability scans and SQL injection also more common.
0
New COPPA Rules to Take Effect Over Child Data Privacy Concerns
Thứ Năm, 12 tháng 6, 2025
Việt Nam Hacker
New regulations and compliance standards for the Children's Online Privacy Protection Act reflect how much technology has grown since the Federal Trade Commission last updated it in 2013.
0
Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'
Việt Nam Hacker
Researchers at Aim Security disclosed a Microsoft Copilot vulnerability of critical severity this week that could have enabled sensitive data exfiltration via prompt injection attacks.
0
Hacking the Hackers: When Bad Guys Let Their Guard Down
Việt Nam Hacker
A string of threat-actor OpSec failures have yielded unexpected windfalls for security researchers and defenders.
0
ConnectWise to Rotate Code-Signing Certificates
Thứ Tư, 11 tháng 6, 2025
Việt Nam Hacker
The move is unrelated to a recent nation-state attack the vendor endured but stems from a report by a third-party researcher.
0
Agentic AI Takes Over Gartner's SRM Summit
Việt Nam Hacker
Agentic AI was everywhere at Gartner's Security & Risk Management Summit in Washington, DC, this year, as the AI security product engine chugs ahead at full speed.
0
Google Bug Allowed Brute-Forcing of Any User Phone Number
Việt Nam Hacker
The weakness in Google's password-recovery page, discovered by a researcher called Brutecat, exposed private user contact information to attackers, opening the door to phishing, SIM-swapping, and other attacks.
0
PoC Code Escalates Roundcube Vuln Threat
Thứ Ba, 10 tháng 6, 2025
Việt Nam Hacker
0
GitHub: How Code Provenance Can Prevent Supply Chain Attacks
Việt Nam Hacker
Through artifact attestation and the SLSA framework, GitHub's Jennifer Schelkopf argues that at least some supply chain attacks can be stopped in their tracks.
0
United Natural Food's Operations Limp Through Cybersecurity Incident
Việt Nam Hacker
It's unclear what kind of cyberattack occurred, but UNFI proactively took certain systems offline, which has disrupted the company's operations.
0
Gartner: How Security Teams Can Turn Hype Into Opportunity
Thứ Hai, 9 tháng 6, 2025
Việt Nam Hacker
During the opening keynote at Gartner Security & Risk Management Summit 2025, analysts weighed in on how CISOs and security teams can use security fervor around AI and other tech to the betterment of their security posture.
0
SIEMs Missing the Mark on MITRE ATT&CK Techniques
Việt Nam Hacker
CardinalOps' report shows that organizations are struggling to keep up with the evolution of the latest threats while a significant number of detection rules remain non-functional.
0
China-Backed Hackers Target SentinelOne in 'PurpleHaze' Attack Spree
Việt Nam Hacker
Known threat groups APT15 and UNC5174 unleashed attacks against SentinelOne and more than 70 other high-value targets, as part of ongoing cyber-espionage and other malicious activity involving ShadowPad malware.
0
Docuseries Explores Mental, Physical Hardships of CISOs
Thứ Sáu, 6 tháng 6, 2025
Việt Nam Hacker
During "CISO: The Worst Job I Ever Wanted," several chief information security officers reveal how difficult it is to be in a role that, despite being around for decades, remains undefined.
0
BADBOX 2.0 Targets Home Networks in Botnet Campaign, FBI Warns
Việt Nam Hacker
Though the operation was partially disrupted earlier this year, the botnet remains active and continues to target connected Android devices.
0
'PathWiper' Attack Hits Critical Infrastructure In Ukraine
Thứ Năm, 5 tháng 6, 2025
Việt Nam Hacker
Cisco Talos researchers observed the new wiper malware in a destructive attack against an unnamed critical infrastructure organization.
0
Cisco Warns of Credential Vuln on AWS, Azure, Oracle Cloud
Việt Nam Hacker
The vulnerability, with a 9.9 CVSS score on a 10-point scale, results in different Cisco ISE deployments all sharing the same credentials as long as the software release and cloud platform remain the same.
0
Backdoored Malware Reels in Newbie Cybercriminals
Việt Nam Hacker
Sophos researchers found this operation has similarities or connections to many other campaigns targeting GitHub repositories dating back to August 2022.
0
35K Solar Devices Vulnerable to Potential Hijacking
Thứ Tư, 4 tháng 6, 2025
Việt Nam Hacker
A little more than three-quarters of these exposed devices are located in Europe, followed by Asia, with 17%.
0
Vishing Crew Targets Salesforce Data
Việt Nam Hacker
A group Google is tracking as UNC6040 has been tricking users into installing a malicious version of a Salesforce app to gain access to and steal data from the platform.
0
How Neuroscience Can Help Us Battle 'Alert Fatigue'
Việt Nam Hacker
By understanding the neurological realities of human attention, organizations can build more sustainable security operations that protect not only their digital assets but also the well-being of those who defend them.
0
Researchers Bypass Deepfake Detection With Replay Attacks
Việt Nam Hacker
An international group of researchers found that simply rerecording deepfake audio with natural acoustics in the background allows it to bypass detection models at a higher-than-expected rate.
0
Chrome Drops Trust for Chunghwa, Netlock Certificates
Thứ Ba, 3 tháng 6, 2025
Việt Nam Hacker
Digital certificates authorized by the authorities will no longer have trust by default in the browser starting in August, over what Google said is a loss of integrity in actions by the respective companies.
0
LummaC2 Fractures as Acreed Malware Becomes Top Dog
Việt Nam Hacker
LummaC2 formerly accounted for almost 92% of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.
0
LummaC2 Fractures as Acreed Malware Becomes Top Dog
Việt Nam Hacker
LummaC2 formerly accounted for almost 92% of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.
0
Beyond the Broken Wall: Why the Security Perimeter Is Not Enough
Thứ Hai, 2 tháng 6, 2025
Việt Nam Hacker
Organizations need to abandon perimeter-based security for data-centric protection strategies in today's distributed IT environments.
0
EMR-ISAC Shuts Down: What Happens Now?
Việt Nam Hacker
The Emergency Management and Response - Information Sharing and Analysis Center provided essential information to the emergency services sector on physical and cyber threats and its closure leaves an information vacuum for these organizations.
0
Exploitation Risk Grows for Critical Cisco Bug
Việt Nam Hacker
New details on the Cisco IOS XE vulnerability could help attackers develop a working exploit soon, researchers say.
0
Trickbot, Conti Ransomware Operator Unmasked Amid Huge Ops Leak
Việt Nam Hacker
An anonymous whistleblower has leaked large amounts of data tied to the alleged operator behind Trickbot and Conti ransomware.
0
Critical Bugs Could Spark Takeover of Widely Used Fire Safety OT/ICS Platform
Việt Nam Hacker
The unpatched security vulnerabilities in Consilium Safety's CS5000 Fire Panel could create "serious safety issues" in environments where fire suppression and safety are paramount, according to a CISA advisory.
0
In the AI Race With China, Don't Forget About Security
Việt Nam Hacker
The US needs to establish a clear framework to provide reasonable guardrails to protect its interests — the quicker, the better.
0
'Earth Lamia' Exploits Known SQL, RCE Bugs Across Asia
Thứ Sáu, 30 tháng 5, 2025
Việt Nam Hacker
A "highly active" Chinese threat group is taking proverbial candy from babies, exploiting known bugs in exposed servers to steal data from organizations in sensitive sectors.
0
FBI Warns of Filipino Tech Company Running Sprawling Crypto Scams
Việt Nam Hacker
The US Treasury said cryptocurrency investment schemes like the ones facilitated by Funnull Technology Inc. have cost Americans billions of dollars annually.
0
SentinelOne Reports Services Are Back Online After Global Outage
Thứ Năm, 29 tháng 5, 2025
Việt Nam Hacker
The outage reportedly hit 10 commercial customer consoles for SentinelOne's Singularity platform, including Singularity Endpoint, XDR, Cloud Security, Identity, Data Lake, RemoteOps, and more.
0
Zscaler's Buyout of Red Canary Shows Telemetry's Value
Việt Nam Hacker
Red Canary's MDR portfolio complements Zscaler's purchase last year of Israeli startup Avalor, which automates collection, curation, and enrichment of security data.
0
LexisNexis Informs 360K+ Customers of Third-Party Data Leak
Việt Nam Hacker
While the leak affected customer data, LexisNexis said in a notification letter that its products and systems were not compromised.
0
PumaBot Targets Linux Devices in Latest Botnet Campaign
Việt Nam Hacker
While the botnet may not be completely automated, it uses certain tactics when targeting devices that indicate that it may, at the very least, be semiautomated.
0
CISA Issues SOAR, SIEM Implementation Guidance
Việt Nam Hacker
The Cybersecurity and Infrastructure Security Agency (CISA) and Australian Cyber Security Centre (ACSC) recommend that organizations conduct thorough testing and manage costs, which can be hefty, before implementing the platforms.
0
'Haozi' Gang Sells Turnkey Phishing Tools to Amateurs
Việt Nam Hacker
The phishing operation is using Telegram groups to sell a phishing-as-a-service kit with customer service, a mascot, and infrastructure that requires little technical knowledge to install.
0
Hundreds of Web Apps Have Full Access to OneDrive Files
Thứ Tư, 28 tháng 5, 2025
Việt Nam Hacker
Researchers at Oasis Security say the problem has to do with OneDrive File Picker having overly broad permissions.
0
Implementing Secure by Design Principles for AI
Việt Nam Hacker
Harnessing AI's full transformative potential safely and securely requires more than an incremental enhancement of existing cybersecurity practices. A Secure by Design approach represents the best path forward.
0
MathWorks, Creator of MATLAB, Confirms Ransomware Attack
Thứ Ba, 27 tháng 5, 2025
Việt Nam Hacker
The attack dirsupted MathWorks' systems and online applications, but it remains unclear which ransomware group targeted the software company and whether they stole any data.
0
Danabot Takedown Deals Blow to Russian Cybercrime
Việt Nam Hacker
A multiyear investigation by a public-private partnership has resulted in the seizure of the botnet's US-based infrastructure and indictments for its key players, significantly disrupting a vast cybercriminal enterprise.
0
CVE Uncertainty Underlines Importance of Cyber Resilience
Việt Nam Hacker
Organizations need to broaden their strategy to manage vulnerabilities more effectively and strengthen network cyber resilience.
0
Russian Threat Actor TAG-110 Goes Phishing in Tajikistan
Thứ Năm, 22 tháng 5, 2025
Việt Nam Hacker
While Ukraine remains Russia's major target for cyberattacks, TAG-110 is part of a strategy to preserve "a post-Soviet sphere of influence" by embedding itself in other countries' infrastructures.
0
3am Ransomware Adopts Email Bombing, Vishing Combo Attack
Việt Nam Hacker
The emerging threat group is the latest to adopt the combo attack tactic, which Black Basta and other groups already are using to gain initial access for ransomware deployment.
0
Blurring Lines Between Scattered Spider and Russian Cybercrime
Việt Nam Hacker
The loosely affiliated hacking group has shifted closer to ransomware gangs, raising questions about Scattered Spider's ties to the Russian cybercrime underground.
0
CISA: Russia's Fancy Bear Targeting Logistics, IT Firms
Việt Nam Hacker
0
Pandas Galore: Chinese Hackers Boost Attacks in Latin America
Thứ Tư, 21 tháng 5, 2025
Việt Nam Hacker
Vixen Panda, Aquatic Panda — both Beijing-sponsored APTs and financially motivated criminal groups continued to pose the biggest threat to organizations in Central and South America last year, says CrowdStrike.
0
Unimicron, Presto Attacks Mark Industrial Ransomware Surge
Việt Nam Hacker
A number of major industrial organizations suffered ransomware attacks last quarter, such as PCB manufacturer Unimicron, appliance maker Presto, and more — a harbinger of a rapidly developing and diversifying threat landscape.
0
Coinbase Breach Compromises Nearly 70K Customers' Information
Việt Nam Hacker
Coinbase asserts that this number is only a small fraction of the number of its verified users, though its still offering a $20 million reward to catch the criminals.
0
Fake Kling AI Malvertisements Lure Victims With False Promises
Thứ Ba, 20 tháng 5, 2025
Việt Nam Hacker
Researchers noted that they found several similar websites, two of which are still operating and require the same kind of behavior on behalf of the victim.
0
Virgin Media 02 Vuln Exposes Call Recipient Location
Việt Nam Hacker
A hacker exploiting the security flaw in the mobile provider's network could have potentially located a call recipient with accuracy of up to 100 square meters.
0
Tenable Adds Third-Party Connectors to Exposure Management Platform
Việt Nam Hacker
TenableOne now pulls in data from AWS, Microsoft, and competitors to provide a holistic security view of the organization's attack surface.
0
Regeneron Pledges Privacy Protection in $256M Bid for 23andMe
Việt Nam Hacker
Regeneron's acquisition of 23andMe raises significant privacy concerns as experts warn about the lack of comprehensive federal regulations governing the transfer of genetic information.
0
Why Rigid Security Programs Keep Failing
Việt Nam Hacker
Organizations that stay ahead of attacks won't be the most compliant ones — they'll be the ones most honest about what actually works.
0
'Operation RoundPress' Targets Ukraine in XSS Webmail Attacks
Thứ Hai, 19 tháng 5, 2025
Việt Nam Hacker
A cyber-espionage campaign is targeting Ukrainian government entities with a series of sophisticated spear-phishing attacks that exploit XSS vulnerabilities.
0
Legal Aid Agency Warns Lawyers, Defendants on Data Breach
Việt Nam Hacker
The online service has since been shut down as the agency grapples with the cyberattack, though it assures the public that those most in need of legal assistance will still be able to access help.
0
CVE Disruption Threatens Foundations of Defensive Security
Việt Nam Hacker
If the Common Vulnerabilities and Exposures system continues to face uncertainty, the repercussions will build slowly, and eventually the cracks will become harder to contain.
0
Australian Human Rights Commission Leaks Docs in Data Breach
Thứ Sáu, 16 tháng 5, 2025
Việt Nam Hacker
An internal error led to public disclosure of reams of sensitive data that could be co-opted for follow-on cyberattacks.
0
Attacker Specialization Puts Threat Modeling on Defensive
Việt Nam Hacker
Specialization among threat groups poses challenges for defenders, who now must distinguish between different actors responsible for different facets of an attack.
0
Big Steelmaker Halts Operations After Cyber Incident
Thứ Năm, 15 tháng 5, 2025
Việt Nam Hacker
Nucor made it clear its investigation is still in the early stages and didn't specify the nature or scope of the breach, nor who the threat actor might be.
0
International Crime Rings Defraud US Gov't Out of Billions
Việt Nam Hacker
Fraudsters worldwide apply for money from the US government using stolen and forged identities, making off with hundreds of billions of dollars annually.
0
Attackers Target Samsung MagicINFO Server Bug, Patch Now
Việt Nam Hacker
CVE-2025-4632, a patch bypass for a Samsung MagicInfo 9 Server vulnerability disclosed last year, has been exploited by threat actors in the wild.
0
Critical SAP NetWeaver Vuln Faces Barrage of Cyberattacks
Việt Nam Hacker
As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.
0
Using a Calculator to Take Guesswork Out of Measuring Cyber-Risk
Việt Nam Hacker
Organizations face the complex challenge of accurately measuring their cyber-risk across multiple variables. Resilience's risk calculator tool can help organizations measure their cyber-risk based on their own factors so that they can make informed decisions about their security posture.
0
AI Agents May Have a Memory Problem
Thứ Tư, 14 tháng 5, 2025
Việt Nam Hacker
A new study by researchers at Princeton University and Sentient shows it's surprisingly easy to trigger malicious behavior from AI agents by implanting fake "memories" into the data they rely on for making decisions.
0
Ivanti EPMM Zero-Day Flaws Exploited in Chained Attack
Việt Nam Hacker
The security software maker said the vulnerabilities in Endpoint Manager Mobile have been exploited in the wild against "a very limited number of customers" — for now — and stem from open source libraries.
0
Chinese Actor Hit Taiwanese Drone Makers, Supply Chains
Thứ Ba, 13 tháng 5, 2025
Việt Nam Hacker
Tidrone concentrated on military entities and the satellite sector, using their associated service providers and ERP software to infect not just drones but all the entities that are part of their supply chains.
0
What Does EU's Bug Database Mean for Vulnerability Tracking?
Việt Nam Hacker
The EU cyber agency ENISA has launched its vulnerability database, the EUVD; security experts shared their thoughts regarding what this means for CVEs, as well as the larger conversation around how bugs are tracked.
0
CISA Warns of TeleMessage Vuln Despite Low CVSS Score
Việt Nam Hacker
Though the app claims to use end-to-end encryption, hackers have reportedly accessed archived data on the app's servers via a new vulnerability.
0
North Korea's TA406 Targets Ukraine for Intel
Việt Nam Hacker
The threat group's goal is to help Pyongyang assess risk to its troops deployed in Ukraine and to figure out if Moscow might want more.
0
Attackers Lace Fake Generative AI Tools With 'Noodlophile' Malware
Thứ Hai, 12 tháng 5, 2025
Việt Nam Hacker
Threat actors are scamming users by advertising legitimate-looking generative AI websites that, when visited, install credential-stealing malware onto the victim's computer.
0
4 Hackers Arrested After Millions Made in Global Botnet Business
Việt Nam Hacker
The cybercriminals infected older wireless Internet routers with Anyproxy and 5socks malware in order to reconfigure them — all without the users' knowledge.
0
Can Cybersecurity Keep Up In the AI Arms Race?
Việt Nam Hacker
New research shows China is quickly catching up with the US in AI innovation. Experts weigh in on what it means for cyber defenders.
0
Vulnerability Detection Tops Agentic AI at RSAC's Startup Competition
Việt Nam Hacker
Agentic-native startups threaten to reduce the zero-day problem to just a zero-hour issue. Of course, AI agents will accelerate offensive attacks as well.
0
New UK Security Guidelines Aims to Reshape Software Development
Việt Nam Hacker
The voluntary Software Security Code of Practice is the latest initiative to come out of the United Kingdom to boost best practices in application security and software development.
0
After Pahalgam Attack, Hacktivists Unite Under #OpIndia
Thứ Sáu, 9 tháng 5, 2025
Việt Nam Hacker
0
LockBit Ransomware Gang Hacked, Operations Data Leaked
Việt Nam Hacker
Exposed data from LockBit's affiliate panel includes Bitcoin addresses, private chats with victim organizations, and user information such as credentials.
0
Cyber Then & Now: Inside a 2-Decade Industry Evolution
Việt Nam Hacker
On Dark Reading's 19-year anniversary, Editor-in-Chief Kelly Jackson Higgins stops by Informa TechTarget's RSAC 2025 Broadcast Alley studio to discuss how things have changed since the early days of breaking Windows and browsers, lingering challenges, and what's next beyond AI.
0
Commvault: Vulnerability Patch Works as Intended
Việt Nam Hacker
The security researcher who questioned the effectiveness of a patch for recently disclosed bug in Commvault Command Center did not test patched version, the company says.
0
How Security Has Changed the Hacker Marketplace
Việt Nam Hacker
Your ultimate goal shouldn't be security perfection — it should be making exploitation of your organization unprofitable.
0
SonicWall Issues Patch for Exploit Chain in SMA Devices
Thứ Năm, 8 tháng 5, 2025
Việt Nam Hacker
Three vulnerabilities in SMA 100 gateways could facilitate root RCE attacks, and one of the vulnerabilities has already been exploited in the wild.
0
Email-Based Attacks Top Cyber-Insurance Claims
Việt Nam Hacker
Cyber-insurance carrier Coalition said business email compromise and funds transfer fraud accounted for 60% of claims in 2024.
0
Operation PowerOFF Takes Down 9 DDoS-for-Hire Domains
Việt Nam Hacker
Four different countries, including the United States and Germany, were included in the latest international operation alongside Europol's support.
0
Meta Wins Lawsuit Against Spyware Vendor NSO Group
Thứ Tư, 7 tháng 5, 2025
Việt Nam Hacker
The spyware company must pay the tech giant $168 million in punitive and compensatory damages after a 2019 attack targeting 1,400 devices.
0
Play Ransomware Group Used Windows Zero-Day
Việt Nam Hacker
Previously, Microsoft reported that Storm-2460 had also used the privilege escalation bug to deploy ransomware on organizations in several countries.
0
'Bring Your Own Installer' Attack Targets SentinelOne EDR
Việt Nam Hacker
Researchers from Aon's Stroz Friedberg incident response firm discovered a new attack type, known as "Bring Your Own Installer," targeting misconfigured SentinelOne EDR installs.
0
Infrastructure as Code: An IaC Guide to Cloud Security
Việt Nam Hacker
IaC is powerful. It brings speed, scale, and structure to cloud infrastructure. But none of that matters if your security can't keep up.
0
Researcher Says Patched Commvault Bug Still Exploitable
Thứ Ba, 6 tháng 5, 2025
Việt Nam Hacker
CISA added CVE-2025-34028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.
0
'Easily Exploitable' Langflow Vulnerability Requires Immediate Patching
Việt Nam Hacker
The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.
0
The Dark Side of Digital: Breaking The Silence on Youth Mental Health
Việt Nam Hacker
Industry experts at RSAC 2025 call for urgent accountability in addressing technology's negative impact on youth, highlighting concerns about internet anonymity, mental health, and the growing disconnect between generations.
0
'Venom Spider' Targets Hiring Managers in Phishing Scheme
Thứ Hai, 5 tháng 5, 2025
Việt Nam Hacker
Researchers from Arctic Wolf Labs detailed a new spear-phishing campaign that targets hiring managers and recruiters by posing as a job seeker.
0
Phony Hacktivist Pleads Guilty to Disney Data Leak
Việt Nam Hacker
After stealing sensitive data from Disney, Ryan Mitchell Kramer claimed to be part of a Russian hacktivist group protecting artists' rights and ensuring they receive fair compensation for their work.
0
How to Prevent AI Agents From Becoming the Bad Guys
Việt Nam Hacker
When designed with strong governance principles, AI can drive innovation while maintaining the people's trust and security.
0
What NYDFS Rules Mean for Businesses (in and outside of NY)
Thứ Sáu, 2 tháng 5, 2025
Việt Nam Hacker
Starting this month, finance companies operating in New York must implement a variety of protections against unauthorized access to IT systems.
0
Enterprises Need to Beware of These 5 Threats
Thứ Năm, 1 tháng 5, 2025
Việt Nam Hacker
A panelist of SANS Institute leaders detailed current threats and provided actionable steps for enterprises to consider.
0
SANS Top 5: Cyber Has Busted Out of the SOC
Việt Nam Hacker
This year's top cyber challenges include cloud authorization sprawl, ICS cyberattacks and ransomware, a lack of cloud logging, and regulatory constraints keeping defenders from fully utilizing AI's capabilities.
0
Experts Debate Real ID Security Ahead of May 7 Deadline
Việt Nam Hacker
Real IDs have been in the works since 2005. Are their security standards still rigorous enough in 2025?
0
Getting Outlook.com Ready for Bulk Email Compliance
Việt Nam Hacker
Microsoft has set May 5 as the deadline for bulk email compliance. In this Tech Tip, we show how organizations can still make the deadline.
0
Former CISA Head Slams Trump Admin Over 'Loyalty Mandate'
Thứ Tư, 30 tháng 4, 2025
Việt Nam Hacker
Jen Easterly, former director of CISA, discussed the first 100 days of the second Trump administration and criticized the president's "mandate for loyalty" during a panel at RSAC 2025.
0
TheWizards APT Casts a Spell on Asian Gamblers With Novel Attack
Việt Nam Hacker
A SLAAC-spoofing, adversary-in-the-middle campaign is hiding the WizardNet backdoor malware inside updates for legitimate software and popular applications.
0
NVIDIA's AI Security Offering Protects From Software Landmines
Việt Nam Hacker
0
Many Fuel Tank Monitoring Systems Vulnerable to Disruption
Thứ Ba, 29 tháng 4, 2025
Việt Nam Hacker
Thousands of automatic tank gauge (ATG) devices are accessible over the Internet and are just "a packet away" from compromise, security researcher warns at 2025 RSAC Conference.
0
From Mission-Centric to People-Centric: Competitive Leadership in Cyber
Việt Nam Hacker
0
Hacking in Space: Not as Tough as You Might Think
Việt Nam Hacker
Barbara Grofe, space asset security architect at Spartan Corp, discussed the realities of hacking in space, and the outlook is not pie-in-the-sky.
0
Risks of Using AI Models Developed by Competing Nations
Việt Nam Hacker
The current offline/open source model boom is unstoppable. Its impact depends on how well the risks are managed today.
0
Windows Backdoor Targets Members of Exiled Uyghur Community
Việt Nam Hacker
A spear-phishing campaign sent Trojanized versions of legitimate word-processing software to members of the World Uyghur Congress as part of China's continued cyber-espionage activity against the ethnic minority.
0
Vulnerability Exploitation Is Shifting in 2024-25
Việt Nam Hacker
The number of vulnerabilities exploited by attacks may not be growing these days, but they are increasingly affecting enterprise technologies.
0
SAP NetWeaver Visual Composer Flaw Under Active Exploitation
Thứ Hai, 28 tháng 4, 2025
Việt Nam Hacker
CVE-2025-31324 is a maximum severity bug that attackers exploited weeks before SAP released a patch for it.
0
AI, Automation, and Dark Web Fuel Evolving Threat Landscape
Việt Nam Hacker
Attackers are leveraging the benefits of new technology and the availability of commodity tools, credentials, and other resources to develop sophisticated attacks more quickly than ever, putting defenders on their heels.
0
Forget the Stack; Focus on Control
Việt Nam Hacker
Security teams are under more pressure than ever — and cybersecurity debt is adding fuel to the fire. While it can't be eliminated overnight, it can be managed.
0
DoJ Data Security Program Highlights Data Sharing Challenges
Việt Nam Hacker
The Department of Justice announced compliance rules for the Data Security Program that will require organizations to reexamine how they do business and with whom.
0
Digital Twins Bring Simulated Security to the Real World
Thứ Sáu, 25 tháng 4, 2025
Việt Nam Hacker
By simulating business environments or running software, while incorporating real-time data from production systems, companies can model the impact of software updates, exploits, or disruptions.
0
'SessionShark' ToolKit Evades Microsoft Office 365 MFA
Thứ Năm, 24 tháng 4, 2025
Việt Nam Hacker
The creators of the toolkit are advertising it as an educational and ethical resource, but what it promises to provide users if purchased indicates it's anything but.
0
Max-Severity Commvault Bug Alarms Researchers
Việt Nam Hacker
Though already patched, the vulnerability is especially problematic because of the highly privileged access it offers to business-critical systems, sensitive data, and backups for attackers.
0
NFC-Powered Android Malware Enables Instant Cash-Outs
Việt Nam Hacker
Researchers at security vendor Cleafy detailed a malware known as "SuperCard X" that uses the NFC reader on a victim's own phone to steal credit card funds instantly.
0
FBI: Cybercrime Losses Rocket to $16.6B in 2024
Việt Nam Hacker
The losses are 33% higher than the year before, with phishing leading the way as the most-reported cybercrime last year, and ransomware was the top threat to critical infrastructure, according to the FBI Internet Crime Report.
0
North Korean Operatives Use Deepfakes in IT Job Interviews
Thứ Tư, 23 tháng 4, 2025
Việt Nam Hacker
Use of synthetic identities by malicious employment candidates is yet another way state-sponsored actors are trying to game the hiring process and infiltrate Western organizations.
0
Japan Warns on Unauthorized Stock Trading via Stolen Credentials
Việt Nam Hacker
Attackers are using credentials stolen via phishing websites that purport to be legitimate securities company homepages, duping victims and selling their stocks before they realize they've been hacked.
0
Kubernetes Pods Are Inheriting Too Many Permissions
Việt Nam Hacker
Scalable, effective — and best of all, free — securing Kubernetes workload identity cuts cyber-risk without adding infrastructure, according to new research from SANS.
0
Microsoft Purges Millions of Cloud Tenants in Wake of Storm-0558
Thứ Ba, 22 tháng 4, 2025
Việt Nam Hacker
The tech giant is boosting Entra ID and MSA security as part of the wide-ranging Secure Future Initiative (SFI) that the company launched following a Chinese APT's breach of its Exchange Online environment in 2023.
0
3 More Healthcare Orgs Hit by Ransomware Attacks
Việt Nam Hacker
Dialysis firm DaVita, Wisconsin-based Bell Ambulance, and Alabama Ophthalmology Associates all suffered apparent or confirmed ransomware attacks this month.
0
'Cookie Bite' Entra ID Attack Exposes Microsoft 365
Việt Nam Hacker
A proof-of-concept (PoC) attack vector exploits two Azure authentication tokens from within a browser, giving threat actors persistent access to key cloud services, including Microsoft 365 applications.
0
'Elusive Comet' Attackers Use Zoom to Swindle Victims
Thứ Hai, 21 tháng 4, 2025
Việt Nam Hacker
The threat actor uses sophisticated social engineering techniques to infect a victim's device, either with an infostealer or remote access Trojan (RAT).
0
Nation-State Threats Put SMBs in Their Sights
Việt Nam Hacker
Cyberthreat groups increasingly see small and medium-sized businesses, especially those with links to larger businesses, as the weak link in the supply chain for software and IT services.
0
Can Cybersecurity Weather the Current Economic Chaos?
Việt Nam Hacker
Cybersecurity firms tend to be more software- and service-oriented than their peers, and threats tend to increase during a downturn, leaving analysts hopeful that the industry will buck a recession.
0
Nation-State Threats Put SMBs in Their Sights
Việt Nam Hacker
Cyberthreat groups increasingly see small and medium businesses, especially those with links to larger businesses, as the weak link in the supply chain for software and IT services.
0
ASUS Urges Users to Patch AiCloud Router Vuln Immediately
Việt Nam Hacker
The vulnerability is only found in the vendor's router series and can be triggered by an attacker using a crafted request — all of which helps make it a highly critical vulnerability with a 9.2 CVSS score.
0
The Global AI Race: Balancing Innovation and Security
Việt Nam Hacker
The AI security race is on — and it will be won where defenders come together with developers and researchers to do things right.
0
Organizations Fix Less Than Half of All Exploitable Vulnerabilities, With Just 21% of GenAI App Flaws Resolved
Thứ Sáu, 18 tháng 4, 2025
Việt Nam Hacker
0
Attackers and Defenders Lean on AI in Identity Fraud Battle
Việt Nam Hacker
Identity verification, insurance claims, and financial services are all seeing surges in AI-enabled fraud, but organizations are taking advantage of AI systems to fight fire with fire.
0
Chinese APT Mustang Panda Debuts 4 New Attack Tools
Việt Nam Hacker
The notorious nation-state-backed threat actor has added two new keyloggers, a lateral movement tool, and an endpoint detection and response (EDR) evasion driver to its arsenal.
0
If Boards Don't Fix OT Security, Regulators Will
Việt Nam Hacker
Around the world, governments are setting higher-bar regulations with clear corporate accountability for breaches on the belief organizations won't drive up security maturity for operational technology unless they're made to.
0
PromptArmor Launches to Help Assess, Monitor Third-Party AI Risks
Việt Nam Hacker
The AI security startup has already made waves with critical vulnerability discoveries and seeks to address emerging AI concerns with its PromptArmor platform.
0
Android Phones Pre-Downloaded With Malware Target User Crypto Wallets
Thứ Năm, 17 tháng 4, 2025
Việt Nam Hacker
The threat actors lace pre-downloaded applications with malware to steal cryptocurrency by covertly swapping users' wallet addresses with their own.
0
GPS Spoofing Attacks Spike in Middle East, Southeast Asia
Thứ Tư, 16 tháng 4, 2025
Việt Nam Hacker
An Indian disaster-relief flight delivering aid is the latest air-traffic incident, as attacks increase in the Middle East and Myanmar and along the India-Pakistan border.
0
China-Linked Hackers Lay Brickstorm Backdoors on Euro Networks
Việt Nam Hacker
Researchers discovered new variants of the malware, which is tied to a China-nexus threat group, targeting Windows environments of critical infrastructure networks in Europe.
0
Ransomware gang 'CrazyHunter' Targets Critical Taiwanese Orgs
Việt Nam Hacker
Trend Micro researchers detailed an emerging ransomware campaign by a new group known as "CrazyHunter" that is targeting critical sectors in Taiwan.
0
AI-Powered Presentation Tool Leveraged in Phishing Attacks
Thứ Ba, 15 tháng 4, 2025
Việt Nam Hacker
Researchers at Abnormal Security said threat actors are using a legitimate presentation and graphic design tool named "Gamma" in phishing attacks.
0
Hertz Falls Victim to Cleo Zero-Day Attacks
Việt Nam Hacker
Customer data such as birth dates, credit card numbers and driver's license information were stolen when threat actors exploited zero-day vulnerabilities in Cleo-managed file transfer products.
0
Hertz Falls Victim to Cleo Zero-Day Attacks
Việt Nam Hacker
Customer data such as birth dates, credit card numbers and driver's license information were stolen when threat actors exploited zero-day vulnerabilities in Cleo-managed file transfer products.
0
Are We Prioritizing the Wrong Security Metrics?
Việt Nam Hacker
True security isn't about meeting deadlines — it's about mitigating risk in a way that aligns with business objectives while protecting against real-world threats.
0
Threat Intel Firm Offers Crypto in Exchange for Dark Web Accounts
Thứ Hai, 14 tháng 4, 2025
Việt Nam Hacker
Prodaft is currently buying accounts from five Dark Web forums and offers to pay extra for administrator or moderator accounts. The idea is to infiltrate forums to boost its threat intelligence.
0
Fortinet Zero-Day Bug May Lead to Arbitrary Code Execution
Việt Nam Hacker
A threat actor posted about the zero-day exploit on the same day that Fortinet published a warning about known vulnerabilities under active exploitation.
0
A New 'It RAT': Stealthy 'Resolver' Malware Burrows In
Việt Nam Hacker
A new infostealer on the market is making big waves globally, replacing Lumma et al. in attacks and employing so many stealth, persistence, and anti-analysis tricks that it's downright difficult to count them all.
0
7 RSAC 2025 Cloud Security Sessions You Don't Want to Miss
Việt Nam Hacker
0
How DigitalOcean Moved Away From Manual Identity Management
Việt Nam Hacker
DigitalOcean executives describe how they automated and streamlined many of the identity and access management functions which had been previously handled manually.
0
Morocco Investigates Social Security Agency Data Leak
Chủ Nhật, 13 tháng 4, 2025
Việt Nam Hacker
A threat actor has claimed responsibility for the alleged politically motivated attack and has uploaded the stolen data to a Dark Web forum.
0
Pall Mall Process Progresses but Leads to More Questions
Thứ Sáu, 11 tháng 4, 2025
Việt Nam Hacker
Nations continue to sign the Code of Practice for States in an effort to curb commercial spyware, yet implementation and enforcement concerns have yet to be figured out.
0
Paper Werewolf Threat Actor Targets Flash Drives With New Malware
Việt Nam Hacker
The threat actor, also known as Goffee, has been active since at least 2022 and has changed its tactics and techniques over the years while targeting Russian organizations.
0
Financial Fraud, With a Third-Party Twist, Dominates Cyber Claims
Việt Nam Hacker
The most damaging attacks continue to be ransomware, but financial fraud claims are more numerous — and both are driven by increasing third-party breaches.
0
What Should the US Do About Salt Typhoon?
Thứ Năm, 10 tháng 4, 2025
Việt Nam Hacker
Security experts weigh in on the problem Salt Typhoon and its hacking of telecoms poses against the United States, including what the US should do and how defenders can protect themselves.
0
Open Source Poisoned Patches Infect Local Software
Việt Nam Hacker
Malicious packages lurking on open source repositories like npm have become less effective, so cyberattackers are using a new strategy: offering "patches" for locally installed programs.
0
CrushFTP Exploitation Continues Amid Disclosure Dispute
Thứ Tư, 9 tháng 4, 2025
Việt Nam Hacker
Attacks on a critical authentication bypass flaw in CrushFTP's file transfer product continue this week after duplicate CVEs sparked confusion.
0
Tariffs May Prompt Increase in Global Cyberattacks
Việt Nam Hacker
Cybersecurity and policy experts worry that if tariffs give way to a global recession, organizations will reduce their spending on cybersecurity.
0
Oracle Appears to Admit Breach of 2 'Obsolete' Servers
Việt Nam Hacker
The database company said its Oracle Cloud Infrastructure (OCI) was not involved in the breach. And at least one law firm seeking damages is already on the case.
0
China-Linked Hackers Continue Harassing Ethnic Groups With Spyware
Việt Nam Hacker
Threat actors are trolling online forums and spreading malicious apps to target Uyghurs, Taiwanese, Tibetans, and other individuals aligned with interests that China sees as a threat to its authority.
0
Aurascape Brings Visibility, Security Controls to Manage AI Applications
Việt Nam Hacker
New cybersecurity startup Aurascape emerged from stealth today with an AI-native security platform to automate security policies for AI applications.
0
Microsoft Drops Another Massive Patch Update
Thứ Ba, 8 tháng 4, 2025
Việt Nam Hacker
A threat actor has already exploited one of the flaws in a ransomware campaign with victims in the US and other countries.
0
UK Orgs Pull Back Digital Projects With Looming Threat of Cyberwarfare
Việt Nam Hacker
Artificial intelligence poses a significant concern when it comes to nation-state cyberthreats and AI's ability to supercharge attacks.
0
2 Android Zero-Day Bugs Under Active Exploit
Việt Nam Hacker
Neither security issue requires user interaction; and one of the vulnerabilities was used to unlock a student activist's device in an attempt to install spyware.
0
Palo Alto Networks Begins Unified Security Rollout
Việt Nam Hacker
Cortex Cloud integrates Prisma Cloud with CDR to provide a consolidated security posture management and real-time threat detection and remediation.
0
ToddyCat APT Targets ESET Bug to Load Silent Malware
Thứ Hai, 7 tháng 4, 2025
Việt Nam Hacker
Researchers found the threat actor attempting to use the now-patched flaw to load and execute a malicious dynamic link library on infected systems.
0
NIST to Implement 'Deferred' Status to Dated Vulnerabilities
Việt Nam Hacker
The changes will go into effect over the next several days to reflect which CVEs are being prioritized in the National Vulnerability Database (NVD).
0
Scattered Spider's 'King Bob' Pleads Guilty to Cyber Charges
Việt Nam Hacker
The 20-year-old was arrested in January 2024 alongside four other group members who carried out related cybercriminal acts, earning them similar charges.
0
Autonomous, GenAI-Driven Attacker Platform Enters the Chat
Việt Nam Hacker
"Xanthorox AI" provides a modular GenAI platform for offensive cyberattacks, which supplies a model-agnostic, one-stop shop for developing a range of cybercriminal operations.
0
Intergenerational Mentoring: Key to Cybersecurity's AI Future
Việt Nam Hacker
As threats evolve and technology changes, our ability to work together across generations will determine our success.
0
CISA Warns: Old DNS Trick 'Fast Flux' Is Still Thriving
Thứ Sáu, 4 tháng 4, 2025
Việt Nam Hacker
An old DNS switcheroo technique is still helping attackers keep their infrastructure alive. But is it really a pressing issue in 2025?
0
Minnesota Tribe Struggles After Ransomware Attack
Việt Nam Hacker
Hotel and casino operations for the Lower Sioux Indians have been canceled or postponed, and the local health center is redirecting those needing medical or dental care.
0
Disclosure Drama Clouds CrushFTP Vulnerability Exploitation
Thứ Năm, 3 tháng 4, 2025
Việt Nam Hacker
CrushFTP CEO Ben Spink slammed several cybersecurity companies for creating confusion around a critical authentication bypass flaw that's currently under attack.
0
Counterfeit Phones Carrying Hidden Revamped Triada Malware
Việt Nam Hacker
The malware, first discovered in 2016, has been updated over the years, and the latest version is now hiding in the firmware of counterfeit mobile phones.
0
Runtime Ventures Launches New Fund for Seed, Pre-Seed Startups
Việt Nam Hacker
Co-founders Michael Sutton and David Endler raised $32 million to invest in early stage cybersecurity startups as well as to provide mentoring support.
0
New PCI DSS Rules Say Merchants on Hook for Compliance, Not Providers
Việt Nam Hacker
Merchants and retailers will now face penalties for not being compliant with PCI DSS 4.0.1, and the increased security standards make it clear they cannot transfer compliance responsibility to third-party service providers.
0
Israel Enters 'Stage 3' of Cyber Wars With Iran Proxies
Thứ Tư, 2 tháng 4, 2025
Việt Nam Hacker
While Israel and Iranian proxies fight it out IRL, their conflict in cyberspace has developed in parallel. These days attacks have decelerated, but advanced in sophistication.
0
DPRK 'IT Workers' Pivot to Europe for Employment Scams
Việt Nam Hacker
By using fake references and building connections with recruiters, some North Korean nationals are landing six-figure jobs that replenish DPRK coffers.
0
In Salt Typhoon's Wake, Congress Mulls Potential Options
Việt Nam Hacker
While the House Committee on Government Reform was looking for retaliatory options, cybersecurity experts pointed them toward building better defenses.
0
Surge in Scans on PAN GlobalProtect VPNs Hints at Attacks
Thứ Ba, 1 tháng 4, 2025
Việt Nam Hacker
Over the past few weeks, bad actors from different regions have been scanning devices with the VPN for potential vulnerabilities.
0
As CISA Downsizes, Where Can Enterprises Get Support?
Việt Nam Hacker
In this roundtable, cybersecurity experts — including two former CISA executives — weigh in on alternate sources for threat intel, incident response, and other essential cybersecurity services.
0
Japan Bolsters Cybersecurity Safeguards With Cyber Defense Bill
Việt Nam Hacker
The bill will allow Japan to implement safeguards and strategies that have been in use by other countries for some time.
0
Check Point Disputes Hacker's Breach Claims
Việt Nam Hacker
The security vendor counters that none of the information came directly from its systems but rather was acquired over a period of time by targeting individuals.
0
CoffeeLoader Malware Is Stacked With Viscous Evasion Tricks
Thứ Hai, 31 tháng 3, 2025
Việt Nam Hacker
Next-level malware represents a new era of malicious code developed specifically to get around modern security software like digital forensics tools and EDR, new research warns.
0
DoJ Seizes Over $8M from Sprawling Pig Butchering Scheme
Việt Nam Hacker
The department was able to trace the stolen funds to three main cryptocurrency accounts after being routed through a series of other platforms.
0
CISA Warns of Resurge Malware Connected to Ivanti Vuln
Việt Nam Hacker
Threat actors are exploiting a vulnerability in Ivanti Connect Secure first disclosed by the vendor in January.
0
Qakbot Resurfaces in Fresh Wave of ClickFix Attacks
Việt Nam Hacker
Attackers post links to fake websites on LinkedIn to ask people to complete malicious CAPTCHA challenges that install malware.
0
GSA Plans FedRAMP Revamp
Việt Nam Hacker
The General Services Administration is planning to use automation to speed up the process to determine which cloud services federal agencies are allowed to buy.
0
Traditional Data Loss Prevention Solutions Are Not Working for Most Organizations
Thứ Sáu, 28 tháng 3, 2025
Việt Nam Hacker
0
Malaysia PM Refuses to Pay $10M Ransomware Demand
Việt Nam Hacker
The attack hit the Kuala Lumpur airport over the weekend, and it remains unclear who the threat actors are and what kind of information they may have stolen.
0
Concord Orthopaedic Notifies Individuals of Security Incident
Việt Nam Hacker
0
OpenAI Bumps Up Bug Bounty Reward to $100K in Security Update
Thứ Năm, 27 tháng 3, 2025
Việt Nam Hacker
The artificial intelligence research company previously had its maximum payout set at $20,000 before exponentially raising the reward.
0
Security Tech That Can Make a Difference During an Attack
Việt Nam Hacker
The recent report of how Volt Typhoon compromised systems at a water utility highlights security technologies and processes that helped detect the compromise and clean up the network.
0
DoJ Recovers $5M Lost in BEC Fraud Against Workers' Union
Việt Nam Hacker
The union received a spoofed email that led to the loss of $6.4 million, much of it transferred to other accounts or to a cryptocurrency exchange.
0
Security Tech That Can Make a Difference During an Attack
Việt Nam Hacker
The recent report of how Volt Typhoon compromised systems at a water utility highlight security technologies and processes that helped detect the compromise and clean up the network.
0
High-Severity Cloud Security Alerts Tripled in 2024
Việt Nam Hacker
Attackers aren't just spending more time targeting the cloud — they're ruthlessly stealing more sensitive data and accessing more critical systems than ever before.
0
Security Expert Troy Hunt Lured in by Mailchimp Phish
Thứ Tư, 26 tháng 3, 2025
Việt Nam Hacker
Hunt quickly took to his blog to notify the public of the breach and provide further details on how this could have happened.
0
Cybersecurity Gaps Leave Doors Wide Open
Việt Nam Hacker
Attackers don't always need to resort to sophisticated gambits to break and enter; organizations often make it easy for them to walk right in.
0
Public-Private Ops Net Big Wins Against African Cybercrime
Việt Nam Hacker
Three cybersecurity firms worked with Interpol and authorities in Nigeria, South Africa, Rwanda, and four other African nations to arrest more than 300 cybercriminals.
0
South African Poultry Company Reports $1M Loss After Cyber Intrusion
Thứ Ba, 25 tháng 3, 2025
Việt Nam Hacker
The company reports that no sensitive information was breached or stolen in the cyber intrusion and that its operations are running normally again.
0
Accused Snowflake Attacker 'Judische' Agrees to US Extradition
Việt Nam Hacker
Though there is no confirmation as to when this extradition will occur, Alexander Moucka agreed to be transferred in writing before a judge.
0
Critical 'IngressNightmare' Vulns Imperil Kubernetes Environments
Thứ Hai, 24 tháng 3, 2025
Việt Nam Hacker
0
China-Nexus APT 'Weaver Ant' Caught in Yearslong Web Shell Attack
Việt Nam Hacker
The persistent threat actor was caught using sophisticated Web shell techniques against an unnamed telecommunications company in Asia.
0
FCC Investigates China-Backed Tech Suppliers for Evading US Operations Ban
Việt Nam Hacker
FCC chairman warns these companies may still be operating in the US because they don't believe that being added to its "Covered List" poses any serious risk.
0
Oracle Denies Claim of Oracle Cloud Breach of 6M Records
Việt Nam Hacker
A threat actor posted data on Breachforums from an alleged supply-chain attack that affected more than 140K tenants, claiming to have compromised the cloud via a zero-day flaw in WebLogic, researchers say.
0
Is the Middle East's Race to Digitize a Threat to Infrastructure?
Chủ Nhật, 23 tháng 3, 2025
Việt Nam Hacker
As the region continues with its ambitious road map, cybersecurity must be woven into every step of the process.
0
What CISA's Red Team Disarray Means for US Cyber Defenses
Thứ Sáu, 21 tháng 3, 2025
Việt Nam Hacker
DOGE is making wild moves at CISA, including bringing back fired probationary employees only to put them on paid leave, and reportedly gutting the agency's red teams.
0
Attackers Pivot to SEMrush Spoof to Steal Google Credentials
Việt Nam Hacker
The attackers are taking an indirect approach to targeting SEO professionals and their Google credentials, using a fake digital marketing website.
0
Nation-State 'Paragon' Spyware Infections Target Civil Society
Việt Nam Hacker
Law enforcement entities in democratic states have been deploying top-of-the-line messaging app spyware against journalists and aid workers.
0
Why Cyber Quality Is the Key to Security
Việt Nam Hacker
The time to secure foundations, empower teams, and make cyber resilience the standard is now — because the cost of waiting is far greater than the investment in proactive security.
0
University Competition Focuses on Solving Generative AI Challenges
Việt Nam Hacker
The Amazon Nova AI Challenge puts student research to the test and aims to bring a new perspective to challenges arising from the increase in AI-assisted software development.
0
VexTrio Using 20,000 Hacked WordPress Sites in Traffic Redirect Scheme
Thứ Năm, 20 tháng 3, 2025
Việt Nam Hacker
A massive cybercrime network known as "VexTrio" is using thousands of compromised WordPress sites to funnel traffic through a complex redirection scheme.
0
Why It's So Hard to Stop Rising Malicious TDS Traffic
Việt Nam Hacker
Cybersecurity vendors say threat actors' abuse of traffic distribution systems (TDS) is becoming more complex and sophisticated — and much harder to detect and block.
0
Enterprises Gain Control Over LLM Oversharing With Prompt Security's GenAI Authorization
Thứ Tư, 19 tháng 3, 2025
Việt Nam Hacker
0
Infosys Settles $17.5M Class Action Lawsuit After Sprawling Third-Party Breach
Việt Nam Hacker
Several major companies in the finance sector were impacted by the third-party breach, prompting them to notify thousands of customers of their compromised data.
0
AI Cloud Adoption Is Rife With Cyber Mistakes
Việt Nam Hacker
Research finds that organizations are granting root access by default and making other big missteps, including a Jenga-like building concept, in deploying and configuring AI services in cloud deployments.
0
Google to Acquire Wiz for $32B in Multicloud Security Play
Thứ Ba, 18 tháng 3, 2025
Việt Nam Hacker
The all-cash deal offers a path for Google to better support cloud customers who have assets spread across public environments, including Azure and others.
0
Black Basta Leader in League With Russian Officials, Chat Logs Show
Việt Nam Hacker
Though the chat logs were leaked a month ago, analysts are now seeing that Russian officials may have assisted Black Basta members according, to the shared messages.
0
Extortion Reboot: Ransomware Crew Threatens Leak to Snowden
Việt Nam Hacker
Though the group initially stuck to classic ransomware TTPs before demanding the ransom, it went off script when it began threatening the group and detailing potential consequences the victim would face.
0
Denmark Warns of Increased Cyber Espionage Against Telecom Sector
Thứ Hai, 17 tháng 3, 2025
Việt Nam Hacker
A new threat assessment from the Danish Civil Protection Authority (SAMSIK) warned of cyberattacks targeting the telecommunications sector after citing a wave of incidents hitting European organizations the past few years.
0
Apache Tomcat RCE Vulnerability Under Fire With 2-Step Exploit
Việt Nam Hacker
The researchers who discovered the initial assault warned that the simple, staged attack is just the beginning for advanced exploit sequences that will test cyber defenses in new and more difficult ways.
0
RansomHub Taps FakeUpdates to Target US Government Sector
Việt Nam Hacker
A ransomware activity wave using the SocGholish MaaS framework for initial access also has affected banking and consulting firms in the US, Taiwan, and Japan since the beginning of the year.
0
How 'Open Innovation' Can Help Solve Problems Faster, Better & Cheaper
Việt Nam Hacker
Cybersecurity is not just a technical challenge but also a very human one. The more humans that organizations can get involved, the more diverse perspectives and experiences that can be tapped into.
0
How Economic Headwinds Influence the Ransomware Ecosystem
Việt Nam Hacker
Inflation, cryptocurrency market volatility, and the ability to invest in defenses all influence the impact and severity of a ransomware attack, according to incident response efforts and ransomware negotiators.
0
Intel’s Secure Data Tunnel Moves AI Training Models to Data Sources
Chủ Nhật, 16 tháng 3, 2025
Việt Nam Hacker
The chip maker's Tiber Secure Federated AI service creates a secure tunnel between AI models on remote servers and data sources on origin systems.
0
Man-in-the-Middle Vulns Provide New Research Opportunities for Car Security
Thứ Sáu, 14 tháng 3, 2025
Việt Nam Hacker
A pair of researchers plan on detailing effective tools to dig into the effectiveness of vehicle cybersecurity without breaking the bank.
0
Ransomware Developer Extradited, Admits Working for LockBit
Việt Nam Hacker
Law enforcement discovered admin credentials on the suspect's computer for an online repository hosted on the Dark Web that stored source code for multiple versions of the LockBit builder.
0
Threat Actor Tied to LockBit Ransomware Targets Fortinet Users
Việt Nam Hacker
The Mora_001 group uses similar post-exploitation patterns and ransomware customization originated by LockBit.
0
Remote Access Infra Remains Riskiest Corp. Attack Surface
Việt Nam Hacker
Exposed login panels for VPNs and remote access systems leave companies open to attack, sometimes tripling the risk of ransomware and making it harder to get cyber insurance.
0
Consumer Groups Push IoT Security Bill to Address EoL Concerns
Việt Nam Hacker
Consumer Reports, Secure Resilient Future Foundation (SRFF) and US Public Interest Research Group (PIRG) introduced a model bill to increase transparency around Internet of Things that have reached end-of-life status.
0
FBI, CISA Raise Alarms As Medusa Ransomware Attacks Grow
Thứ Năm, 13 tháng 3, 2025
Việt Nam Hacker
Medusa developers have been targeting a wide variety of critical infrastructure sectors, from healthcare and technology to manufacturing and insurance, racking up its victim count as it seemingly adds to its numbers of affiliates.
0
NIST Finalizes Differential Privacy Rules to Protect Data
Thứ Tư, 12 tháng 3, 2025
Việt Nam Hacker
The National Institute of Standards and Technology (NIST) released updated differential privacy guidelines for organizations to follow to protect personally identifiable information when sharing data.
0
Apple Drops Another WebKit Zero-Day Bug
Việt Nam Hacker
A threat actor leveraged the vulnerability in an "extremely sophisticated" attack on targeted iOS users, the company says.
0
Volt Typhoon Strikes Massachusetts Power Utility
Việt Nam Hacker
The prolonged attack, which lasted 300+ days, is the first known compromise of the US electric grid by the Voltzite subgroup of the Chinese APT; during it, the APT attempted to exfiltrate critical OT infrastructure data.
0
The CISO as Business Resilience Architect
Việt Nam Hacker
To truly become indispensable in the boardroom, CISOs need to meet the dual demands of defending against sophisticated adversaries while leading resilience strategies.
0
Whopping Number of Microsoft Zero-Days Under Attack
Thứ Ba, 11 tháng 3, 2025
Việt Nam Hacker
The number of zero-day vulnerabilities getting patched in Microsoft's March update is the company's second-largest ever.
0
'Desert Dexter' Hot Button Facebook Ads Tag Mideast Victims
Việt Nam Hacker
A Libya-linked threat actor has resurfaced attacking the Middle East and North Africa, using the same old political phishing tricks to deliver AsyncRAT that have worked for years.
0
'SideWinder' Intensifies Attacks on Maritime Sector
Thứ Hai, 10 tháng 3, 2025
Việt Nam Hacker
The likely India-based threat group is also targeting logistics companies in a continued expansion of its activities.
0
Google Pays Out Nearly $12M in 2024 Bug Bounty Program
Việt Nam Hacker
The program underwent a series of changes in the past year, including richer maximum rewards in a variety of bug categories.
0
APT 'Blind Eagle' Targets Colombian Government
Việt Nam Hacker
The South American-based advanced persistent threat group is using an exploit with a "high infection rate," according to research from Check Point.
0
Ex-Employee Found Guilty in Revenge Kill-Switch Scheme
Việt Nam Hacker
Clandestine kill switch was designed to lock out other users if the developer's account in the company's Windows Active Directory was ever disabled.
0
GitHub-Hosted Malware Infects 1M Windows Users
Việt Nam Hacker
Microsoft has identified a complex, malvertising-based attack chain that delivered Lumma and other infostealers to enterprise and consumer PC users; the campaign is unlikely the last of its kind.
0
Cybercrime's Cobalt Strike Use Plummets 80% Worldwide
Thứ Sáu, 7 tháng 3, 2025
Việt Nam Hacker
Fortra, Microsoft, and Health-ISAC have combined forces to claw back one of hackers' most prized attack tools, with massive takedowns.
0
Zero-Days Put Tens of 1,000s of Orgs at Risk for VM Escape Attacks
Việt Nam Hacker
More than 41,000 ESXi instances remain vulnerable to a critical VMware vulnerability, one of three that Broadcom disclosed earlier this week.
0
Taylor Swift Ticket Thieves Charged in Court for Resale Operation
Việt Nam Hacker
The pair found a loophole through StubHub's services, allowing them to steal tickets and resell them for personal profit, amassing hundreds of thousands of dollars.
0
'EncryptHub' OPSEC Failures Reveal TTPs & Big Plans
Thứ Năm, 6 tháng 3, 2025
Việt Nam Hacker
Is EncryptHub the most prolific cybercriminal in recent history? Or, as new information suggests, a bumbling amateur?
0
Under Pressure: US Charges China's APT-for-Hire Hackers
Việt Nam Hacker
The US Justice Department on Wednesday announced charges against members of the Chinese-backed i-Soon "secret" APT and APT27, the latter implicated in January's Treasury breach.
0
Enterprise AI Through a Data Security Lens: Balancing Productivity With Safety
Việt Nam Hacker
Recently, 57 countries signed an agreement pledging an "open" and "inclusive" approach to AI's development. The US and UK were not among them, with the US vice president implying productivity should be the priority over safety. Should the opportunity for AI to drive innovation and productivity be prioritized over safety and security?
0
China's Silk Typhoon APT Shifts to IT Supply Chain Attacks
Thứ Tư, 5 tháng 3, 2025
Việt Nam Hacker
The nation-state threat group has been breaching providers of remote management tools, identity management providers, and other IT companies to access networks of targeted entities, according to Microsoft.
0
'Crafty Camel' APT Targets Aviation, OT With Polygot Files
Việt Nam Hacker
The Iran-linked nation-state group made its debut with a stealthy, sophisticated, and laser-focused cyber-espionage attack on targets in UAE.
0
Bogus 'BianLian' Gang Sends Snail-Mail Extortion Letters
Việt Nam Hacker
The letters mimic typical ransom notes and threaten to delete or leak compromised data if payments aren't made, though none of the organizations that received them had active ransomware attacks.
0
Serbian Police Hack Protester's Phone With Cellebrite Exploit Chain
Thứ Ba, 4 tháng 3, 2025
Việt Nam Hacker
Amnesty International said Serbian police used an exploit chain in tandem with legitimate mobile extraction dongle from vendor Cellebrite in an attack that brings up questions around ethical technology development.
0
North Korea's Latest 'IT Worker' Scheme Seeks Nuclear Funds
Việt Nam Hacker
Fraudulent IT workers are looking for engineering and developer positions in the US and Japan, and this time it's not about espionage.
0
Pentagon, CISA Deny Change in US Cyber Policy on Russia
Việt Nam Hacker
Media reports over the weekend suggested the Trump Administration ordered US Cyber Command and CISA to draw down cyber activities targeting Russia.
0
Qilin Cybercrime Ring Claims Credit for Lee Newspaper Breach
Thứ Hai, 3 tháng 3, 2025
Việt Nam Hacker
The ransomware-as-a-service (RaaS) cybercrime group intends to leak the stolen information in just two days, it claims; but oddly, it doesn't seek a ransom payment from its victim.
0
Phishers Wreak 'Havoc,' Disguising Attack Inside SharePoint
Việt Nam Hacker
A complex campaign allows cyberattackers to take over Windows systems by a combining a ClickFix-style attack and sophisticated obfuscation that abuses legitimate Microsoft services.
0
EU's New Product Liability Directive & Its Cybersecurity Impact
Việt Nam Hacker
By proactively addressing liabilities tied to software updates, data loss, and AI technologies, businesses can mitigate risks and achieve compliance.
0
Latin American Orgs Face 40% More Attacks Than Global Average
Việt Nam Hacker
Technological adoption, demographics, politics, and uniquely Latin American law enforcement challenges have combined to make the region uniquely fertile for cyberattacks.
0
Cisco's SnapAttack Deal Expands Splunk's Capabilities
Việt Nam Hacker
The addition of SnapAttack, a startup incubated by Booz Allen Hamilton’s Darklabs, will enhance Splunk with accelerated SIEM migration and proactive threat hunting.
0
Third-Party Risk Top Cybersecurity Claims
Việt Nam Hacker
Data collected by cyber-insurers show that ransomware accounts for the majority of insurance claims, but that much of the losses stem from third-party breaches affecting policyholders.
0
Microsoft Busts Hackers Selling Illegal Azure AI Access
Thứ Sáu, 28 tháng 2, 2025
Việt Nam Hacker
LLMjacking operation leveraged illicit access GenAI services to produce explicit celebrity images and other harmful content, Microsoft's digital crimes unit says.
0
US Soldier Intends to Admit Hacking 15 Telecom Carriers
Việt Nam Hacker
The federal government views the defendant as a flight risk and danger to the community due to his ability to access sensitive and private information.
0
Targeted by Ransomware, Middle East Banks Shore Up Security
Thứ Năm, 27 tháng 2, 2025
Việt Nam Hacker
As the UAE financial sector finished up its annual cyberattack exercise, its worries about ransomware compromises and geopolitical attacks are on the rise.
0
Cleveland Municipal Court Remains Closed After Cyber Incident
Việt Nam Hacker
No details yet on what forced the court to shut down affected systems and halt operations as of late Feb. 23.
0
Nakivo Fixes Critical Flaw in Backup & Replication Tool
Việt Nam Hacker
The vendor's products fall in a category that ransomware operators like to target to circumvent victims' ability to recover from a successful attack.
0
Microsoft Rolls Out Fresh Outlook Fix After Faulty Windows Update
Việt Nam Hacker
0
Water Utility Co. Still Paying the Breach Price a Year Later
Thứ Tư, 26 tháng 2, 2025
Việt Nam Hacker
The UK's Southern Water has been forced to shell out millions due to a Black Basta cyberattack, and it has come to light that the total could include a ransom payment.
0
'Silver Fox' APT Skirts Windows Blocklist in BYOVD Attack
Việt Nam Hacker
There's an untapped universe of exploitable drivers in the wild today. By exploiting just one of them, attackers were able to defeat security tools and infect Asian citizens with Gh0stRAT.
0
Name That Toon: Ka-Ching!
Việt Nam Hacker
Feeling creative? Have something to say about cybersecurity? Submit your caption and our panel of experts will reward the winner with a $25 gift card.
Đăng ký:
Bài đăng (Atom)