The April/May zero-day exploitations of Ivanti's mobile device management platform meant unprecedented pwning of thousands of orgs by a Chinese APT — and history will probably repeat itself.
0
Sunken Ships: Will Orgs Learn From Ivanti EPMM Attacks?
Thứ Tư, 31 tháng 12, 2025
Việt Nam Hacker
0
Contrarians No More: AI Skepticism Is on the Rise
Việt Nam Hacker
Concerns about an economic bubble bursting, along with doubts regarding return on investment, suggest the tide may be turning for the artificial intelligence industry.
0
Cybersecurity Predictions 2026: An AI Arms Race and Malware Autonomy
Việt Nam Hacker
The year ahead will see an intensified AI-driven cybersecurity arms race, with attackers leveraging autonomous malware and advanced AI technologies to outpace defenders, while security teams adopt increasingly sophisticated AI tools to combat evolving threats amidst growing vendor consolidation and platformization in the industry.
0
New Tech Deployments Cyber Insurers Recommend for 2026
Thứ Ba, 30 tháng 12, 2025
Việt Nam Hacker
An analysis of cyber-insurance claims data shows which cyber defenses actually work for policyholders. Here are six technologies that will pay off for companies in 2026.
0
Dark Reading Confidential: Stop Secrets Creep Across Developer Platforms
Thứ Hai, 29 tháng 12, 2025
Việt Nam Hacker
Dark Reading Confidential Episode 13: Developers are exposing their organizations' most sensitive information; our guests explain why it's happening and how to stop it.
0
5 Threats That Defined Security in 2025
Việt Nam Hacker
2025 included a number of monumental threats, from the global attacks of Salt Typhoon to dangerous vulnerabilities like React2Shell.
0
Mentorship and Diversity: Shaping the Next Generation of Cyber Experts
Thứ Sáu, 26 tháng 12, 2025
Việt Nam Hacker
Patricia Voight, CISO at Webster Bank, shares her expertise on advancing cybersecurity careers, combating financial crimes, and championing diversity in a rapidly changing industry.
0
As More Coders Adopt AI Agents, Security Pitfalls Lurk in 2026
Việt Nam Hacker
Developers are leaning more heavily on AI for code generation, but in 2026, the development pipeline and security need to be prioritized.
0
Dark Reading Opens The State of Application Security Survey
Việt Nam Hacker
Take part in the new survey from Dark Reading and help uncover trends, challenges, and solutions shaping the future of application security.
0
ServiceNow Buys Armis for $7.75B, Gets 'AI Control Tower'
Thứ Ba, 23 tháng 12, 2025
Việt Nam Hacker
The latest cybersecurity acquisition will help further ServiceNow's plans for autonomous cybersecurity and building a security stack to proactively manage AI.
0
Sprawling 'Operation Sentinel' Neutralizes African Cybercrime Syndicates
Việt Nam Hacker
Interpol said law enforcement across 19 countries made 574 arrests and recovered $3 million, against a backdrop of spiraling cybercrime in the region, including business email compromise, digital extortion, and ransomware schemes.
0
Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
Thứ Hai, 22 tháng 12, 2025
Việt Nam Hacker
With attacks on the critical firewall vulnerability, WatchGuard joins a list of edge device vendors that have been targeted in recent weeks.
0
Uzbek Users Under Attack by Android SMS Stealers
Việt Nam Hacker
Telegram users in Uzbekistan are being targeted with Android SMS stealer malware, and what's worse, the attackers are improving their methods.
0
Cisco VPNs, Email Services Hit in Separate Threat Campaigns
Thứ Sáu, 19 tháng 12, 2025
Việt Nam Hacker
The company suffered one sophisticated five-alarm campaign and one messy spray-and-pray attack, mere days apart.
0
LongNosedGoblin Caught Snooping on Asian Governments
Việt Nam Hacker
New China-aligned APT group is deploying Group Policy to sniff through government networks across Southeast Asia and Japan.
0
Identity Fraud Among Home Care Workers Puts Patients at Risk
Việt Nam Hacker
Reports of patients being cared for by unqualified home-care aides with fake identities continue to emerge, highlighting a need for more stringent identity authentication.
0
A Good Year for North Korean Cybercriminals
Việt Nam Hacker
North Korea shifted its strategy to patiently target "bigger fish" for larger payouts, using sophisticated methods to execute attacks at opportune times.
0
SonicWall Edge Access Devices Hit by Zero-Day Attacks
Thứ Năm, 18 tháng 12, 2025
Việt Nam Hacker
In the latest attacks against the vendor's SMA1000 devices, threat actors have chained a new zero-day flaw with a critical vulnerability disclosed earlier this year.
0
"Fake Proof" and AI Slop Hobble Defenders
Việt Nam Hacker
In the React2Shell saga, non-working and trivial proof-of-concept exploits led to confusion and perhaps a false sense of security. Can the onslaught of PoCs be tamed?
0
Critical Fortinet Flaws Under Active Attack
Thứ Tư, 17 tháng 12, 2025
Việt Nam Hacker
Attackers targeted admin accounts, and once authenticated, exported device configurations including hashed credentials and other sensitive information.
0
In Cybersecurity, Claude Leaves Other LLMs in the Dust
Việt Nam Hacker
Anthropic proves that LLMs can be fairly resistant to abuse. Most developers are either incapable of building safer tools, or unwilling to invest in doing so.
0
'Cellik' Android RAT Leverages Google Play Store
Việt Nam Hacker
The remote access Trojan lets an attacker remotely control a victim's phone and can generate malicious apps from inside the Play Store.
0
Afripol Focuses on Regional Cyber Challenges, Deepening Cooperation
Thứ Ba, 16 tháng 12, 2025
Việt Nam Hacker
Rapid digitization, uneven cybersecurity know-how, and growing cybercriminal syndicates in the region have challenged law enforcement and prosecutors.
0
Russia Hits Critical Orgs Via Misconfigured Edge Devices
Việt Nam Hacker
Amazon detailed a long-running campaign by Russia against critical infrastructure organizations, particularly in the energy sector.
0
Browser Extension Harvests 8M Users' AI Chatbot Data
Việt Nam Hacker
Urban VPN Proxy, which claims to protect users' privacy, collects data from conversations with ChatGPT, Claude, Gemini, Copilot and other AI assistants.
0
Enterprises Gear Up for 2026’s IT Transformation
Việt Nam Hacker
Experts predict big changes are coming for IT infrastructure in 2026 driven by AI adoption, hybrid cloud strategies, and evolving security demands.
0
How Cyber Insurance MGAs Shape Policies for Evolving Cyber Risks
Thứ Hai, 15 tháng 12, 2025
Việt Nam Hacker
Managing general agents help insurers navigate sectors where they lack expertise. A cybersecurity policy written by an MGA is more likely to reflect an understanding of the risks CISOs deal with.
0
Apple Patches More Zero-Days Used in 'Sophisticated' Attack
Việt Nam Hacker
Two Apple zero-day vulnerabilities discovered this month have overlap with another mysterious zero-day flaw Google patched last week.
0
Think Like an Attacker: Cybersecurity Tips From Cato Networks' CISO
Việt Nam Hacker
Etay Mayor, a cybersecurity strategist and professor, shares his journey, insights, and advice on breaking into the diverse and ever-evolving field of cybersecurity.
0
Flaw in Hacktivist Ransomware Lets Victims Decrypt Own Files
Việt Nam Hacker
A new version of VolkLocker, wielded by the pro-Russia RaaS group CyberVolk, has some key enhancements but one fatal flaw.
0
Microsoft Will Bundle Security Copilot with M365 Enterprise Licenses
Thứ Sáu, 12 tháng 12, 2025
Việt Nam Hacker
The move aims to expand the use of Security Copilot and comes with the launch of 12 new agents from Microsoft at the company's Ignite conference last week.
0
Supply Chain Attacks Targeting GitHub Actions Increased in 2025
Việt Nam Hacker
At this week's Black Hat Europe conference, two researchers urged developers to adopt a shared responsibility model for open source software and not leave it all up to GitHub to handle.
0
Are Trade Concerns Trumping US Cybersecurity?
Việt Nam Hacker
The Trump administration appears to have dropped sanctions against Chinese actors for the Salt Typhoon attacks on US telecoms; but focusing on diplomacy alone misses the full picture, experts say.
0
Encouraging Industry Voices to Write for the Commentary Section
Việt Nam Hacker
Dark Reading will continue to publish Tech Talks and Ask the Expert pieces in the Commentary section. Read on for submission guidelines.
0
Hamas-Linked Hackers Probe Middle Eastern Diplomats
Thứ Năm, 11 tháng 12, 2025
Việt Nam Hacker
Hamas's best hackers have been maturing, building better malware, and spreading their attacks more widely across the region.
0
Attackers Exploited Gogs Zero-Day Flaw for Months
Việt Nam Hacker
Wiz disclosed a still-unpatched vulnerability in self-hosted Git service Gogs, which is a bypass for a previous RCE bug disclosed last year.
0
AI in OT Sparks Cascade of Complex Challenges
Việt Nam Hacker
Using artificial intelligence in operational technology environments could be a bumpy ride full of trust issues and security challenges.
0
Copilot's No-Code AI Agents Liable to Leak Company Data
Việt Nam Hacker
Microsoft puts the power of AI in the hands of everyday non-technical Joes. It's a nice idea, and a surefire recipe for security issues.
0
Storm-0249 Abuses EDR Processes in Stealthy Attacks
Thứ Tư, 10 tháng 12, 2025
Việt Nam Hacker
The initial access broker has been weaponizing endpoint detection and response (EDR) platforms and Windows utilities in recent high-precision attacks.
0
ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery
Việt Nam Hacker
A new twist on the social engineering tactic is making waves, combining SEO poisoning and legitimate AI domains to install malware on victims' computers.
0
Japanese Firms Suffer Long Tail of Ransomware Damage
Thứ Ba, 9 tháng 12, 2025
Việt Nam Hacker
Ransomware actors have targeted manufacturers, retailers, and the Japanese government, with many organizations requiring months to recover.
0
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday
Việt Nam Hacker
Proof-of-concept exploit code is publicly available for two other flaws in this month's Patch Tuesday. In total, the company issued patches for more than 1,150 flaws this year.
0
Packer-as-a-Service Shanya Hides Ransomware, Kills EDR
Việt Nam Hacker
Shanya is the latest in an emerging field of packing malware, selling obfuscation functionality in order to help ransomware actors reach their target.
0
Analysts Warn of Cybersecurity Risks in Humanoid Robots
Việt Nam Hacker
0
Gemini Enterprise No-Click Flaw Exposes Sensitive Data
Việt Nam Hacker
Google has fixed a critical vulnerability that enabled attackers to add malicious instructions to common documents to exfiltrate sensitive corporate information.
0
Exploitation Activity Ramps Up Against React2Shell
Thứ Hai, 8 tháng 12, 2025
Việt Nam Hacker
Attacks against CVE-2025-55182, which began almost immediately after public disclosure last week, have increased as more threat actors take advantage of the flaw.
0
US Treasury Tracks $4.5B in Ransom Payments since 2013
Việt Nam Hacker
The US Treasury's Financial Crimes Enforcement Network shared data showing how dramatically ransomware attacks have changed over time.
0
‘Broadside’ Mirai Variant Targets Maritime Logistics Sector
Việt Nam Hacker
'Broadside' is targeting a critical flaw in DVR systems to conduct command injection attacks, which can hijack devices to achieve persistence and move laterally.
0
A Tale of Two CISOs: Why An Engineering-Focused CISO Can Be a Liability
Thứ Bảy, 6 tháng 12, 2025
Việt Nam Hacker
When hiring a CISO, understand the key difference between engineering and holistic security leaders.
0
India Rolls Back App Mandate Amid Surveillance Concerns
Thứ Sáu, 5 tháng 12, 2025
Việt Nam Hacker
Remember when Apple put that U2 album in everyone's music libraries? India wanted to do that to all of its citizens, but with a cybersecurity app. It wasn't a good idea.
0
CISOs Should Be Asking These Quantum Questions Today
Việt Nam Hacker
As quantum quietly moves beyond lab experiment and into production workflows, here's what enterprise security leaders should be focused on, according to Lineswala.
0
How Agentic AI Can Boost Cyber Defense
Thứ Năm, 4 tháng 12, 2025
Việt Nam Hacker
Transurban head of cyber defense Muhammad Ali Paracha shares how his team is automating the triaging and scoring of security threats as part of the Black Hat Middle East conference.
0
CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks
Việt Nam Hacker
State-sponsored actors tied to China continue to target VMware vSphere environments at government and technology organizations.
0
CISA Publishes Security Guidance for Using AI in OT
Việt Nam Hacker
Global cybersecurity agencies published guidance regarding AI deployments in operational technology, a backbone of critical infrastructure.
0
GISEC GLOBAL 2026 – The Middle East & Africa’s Largest Cybersecurity Event
Thứ Tư, 3 tháng 12, 2025
Việt Nam Hacker
0
Arizona AG Sues Temu Over 'Stealing' User Data
Việt Nam Hacker
The suit alleges the Chinese retailer's app secretly accesses and harvests users' sensitive information without their knowledge or consent.
0
New Raptor Framework Uses Agentic Workflows to Create Patches
Thứ Ba, 2 tháng 12, 2025
Việt Nam Hacker
Researchers utilized prompts and large language models to develop an open-source AI framework capable of generating both vulnerability exploits and patches.
0
China Researches Ways to Disrupt Satellite Internet
Việt Nam Hacker
While satellite constellations — such as Starlink — are resilient, 2,000 drones could cut communications to a region the size of Taiwan, researchers find.
0
Iran's 'MuddyWater' Levels Up With MuddyViper Backdoor
Việt Nam Hacker
New Fooder loader and memory-only tactics suggest MuddyWater has evolved from its usual noisy ops to more stealthy espionage operations.
0
Researchers Use Poetry to Jailbreak AI Models
Việt Nam Hacker
When prompts were presented in poetic rather than prose form, attack success rates increased from 8% to 43%, on average — a fivefold increase.
0
DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory
Việt Nam Hacker
North Korean attackers have delivered more than 197 malicious packages with 31K-plus downloads since Oct. 10, as part of ongoing state-sponsored activity to compromise software developers.
0
Tomiris Unleashes 'Havoc' With New Tools, Tactics
Thứ Hai, 1 tháng 12, 2025
Việt Nam Hacker
The Russian-speaking group is targeting government and diplomatic entities in CIS member states and Central Asia in its latest cyber-espionage campaign.
0
CodeRED Emergency Alert Platform Shut Down Following Cyberattack
Việt Nam Hacker
The Inc ransomware gang took responsibility for the attack earlier this month and claimed it stole sensitive subscriber data.
0
Police Disrupt 'Cryptomixer,' Seize Millions in Crypto
Việt Nam Hacker
Multiple European law enforcement agencies recently disrupted Cryptomixer, a service allegedly used by cybercriminals to launder ill-gotten gains from ransomware and other cyber activities.
0
Shai-hulud 2.0 Variant Threatens Cloud Ecosystem
Việt Nam Hacker
The latest attack from the self-replicating, npm-package poisoning worm can also steal credentials and secrets from AWS, Google Cloud Platform, and Azure.
0
How Malware Authors Are Incorporating LLMs to Evade Detection
Thứ Tư, 26 tháng 11, 2025
Việt Nam Hacker
Cyberattackers are integrating large language models (LLMs) into the malware, running prompts at runtime to evade detection and augment their code on demand.
0
'Dark LLMs' Aid Petty Criminals, But Underwhelm Technically
Việt Nam Hacker
As in the wider world, AI is not quite living up to the hype in the cyber underground. But it's definitely helping low-level cybercriminals do competent work.
0
DPRK's FlexibleFerret Tightens macOS Grip
Thứ Ba, 25 tháng 11, 2025
Việt Nam Hacker
The actor behind the "Contagious Interview" campaign is continuing to refine its tactics and social engineering scams to wrest credentials from macOS users.
0
Advanced Security Isn't Stopping Ancient Phishing Tactics
Việt Nam Hacker
New research reveals that sophisticated phishing attacks consistently bypass traditional enterprise security measures.
0
As Gen Z Enters Cybersecurity, Jury Is Out on AI's Impact
Việt Nam Hacker
Despite possibly supplanting some young analysts, one Gen Z cybersecurity specialist sees AI helping teach those willing to learn and removing drudge work.
0
Infamous Shai-hulud Worm Resurfaces From the Depths
Thứ Hai, 24 tháng 11, 2025
Việt Nam Hacker
This campaign introduces a new variant that executes malicious code during preinstall, significantly increasing potential exposure in build and runtime environments, researchers said.
0
CISOs Get Real About Hiring in the Age of AI
Việt Nam Hacker
Dark Reading Confidential Episode 12: Experts help cyber job seekers get noticed, make an argument for a need to return to the hacker ethos of a bygone era, and have a stark conversation about keeping AI from breaking the sector's talent pipeline for years to come.
0
Cloudflare's One-Stop-Shop Convenience Takes Down Global Digital Economy
Thứ Sáu, 21 tháng 11, 2025
Việt Nam Hacker
Even the most advanced systems like Cloudflare can fall victim to software issues and become a global point of failure, Dr. David Utzke argues, adding that the recent outage should be a warning for enterprises.
0
Hack the Hackers: 6 Laws for Staying Ahead of the Attackers
Việt Nam Hacker
A new security framework responds to a shift in attackers' tactics, one that allows them to infiltrate enterprises 'silently' through their own policies.
0
Inside Iran's Cyber Objectives: What Do They Want?
Thứ Năm, 20 tháng 11, 2025
Việt Nam Hacker
The regime's cyber-espionage strategy employs dual-use targeting, collecting info that can support both military needs and broader political objectives.
0
Chinese APT Infects Routers to Hijack Software Updates
Việt Nam Hacker
A unique take on the software update gambit has allowed "PlushDaemon" to evade attention as it mostly targets Chinese organizations.
0
Same Old Security Problems: Cyber Training Still Fails Miserably
Việt Nam Hacker
Editors from Dark Reading, Cybersecurity Dive, and TechTarget Search Security break down the depressing state of cybersecurity awareness campaigns and how organizations can overcome basic struggles with password hygiene and phishing attacks.
0
‘Matrix Push’ C2 Tool Hijacks Browser Notifications
Việt Nam Hacker
Have you ever given two seconds of thought to a browser notification? No? That's what hackers bent on phishing are counting on.
0
US Creates 'Strike Force' to Take Out SE Asian Scam Centers
Thứ Tư, 19 tháng 11, 2025
Việt Nam Hacker
The collaborative effort combines multiple federal departments, along with private companies to reduce, if not eliminate, billions lost annually to fraud.
0
The AI Attack Surface: How Agents Raise the Cyber Stakes
Việt Nam Hacker
Researcher shows how agentic AI is vulnerable to hijacking to subvert an agent's goals and how agent interaction can be altered to compromise whole networks.
0
Can a Global, Decentralized System Save CVE Data?
Thứ Ba, 18 tháng 11, 2025
Việt Nam Hacker
As vulnerabilities in the Common Vulnerabilities and Exposures ecosystem pile up, one Black Hat Europe presenter hopes for a global, distributed alternative.
0
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
Việt Nam Hacker
A malware campaign presents fake websites that can check if a visitor is a potential victim or a security researcher, and then proceed accordingly to defraud or evade.
0
Bug Bounty Programs Rise as Key Strategic Security Solutions
Việt Nam Hacker
Bug bounty programs create formal channels for organizations to leverage external security expertise, offering researchers legal protection and financial incentives for ethical vulnerability disclosure.
0
US Citizens Plead Guilty to Aiding North Korean IT Worker Campaigns
Thứ Hai, 17 tháng 11, 2025
Việt Nam Hacker
Four individuals admitted to assisting foreign IT workers in gaining employment at US companies by providing false identities and remote access to employer-owned laptops.
0
Cursor Issue Paves Way for Credential-Stealing Attacks
Việt Nam Hacker
Researchers discovered a security weakness in the AI-powered coding tool that allows malicious MCP server to hijack Cursor's internal browser.
0
150,000 Packages Flood NPM Registry in Token Farming Campaign
Thứ Sáu, 14 tháng 11, 2025
Việt Nam Hacker
A self-replicating attack led to a tidal wave of malicious packages in the NPM registry, targeting tokens for the tea.xyz protocol.
0
Shadow Program Gives AWS Exec New Security Lens
Việt Nam Hacker
Sara Duffer highlights the top lessons she brought back to her security role following three years in Amazon's shadow program.
0
Identity Governance and Administration, App Proliferation, and the App Integration Chasm
Việt Nam Hacker
Most enterprises use more than 1,000 apps, according to ESG research, yet about half are integrated with IGA. Industry innovations enable teams to expand app coverage and get more IGA value.
0
How CISOs Can Best Work with CEOs and the Board: Lessons from the Field
Việt Nam Hacker
To build an effective relationship with the CEO and the Board, CISOs must translate technical risks into business terms and position cybersecurity as a strategic business enabler rather than just a business function.
0
[Dark Reading Virtual Event] Cybersecurity Outlook 2026
Thứ Năm, 13 tháng 11, 2025
Việt Nam Hacker
0
Kenya Kicks Off 'Code Nation' With a Nod to Cybersecurity
Thứ Tư, 12 tháng 11, 2025
Việt Nam Hacker
The African country aims to train 1 million workers in tech skills in the short term, with a focus on software engineering, cybersecurity, and data science.
0
Google Looks to Dim 'Lighthouse' Phishing-as-a-Service Op
Việt Nam Hacker
The phishing kit, run by a group known as the "Smishing Triad," has powered massive amounts of unpaid tolls and package tracking texts.
0
Microsoft Exchange 'Under Imminent Threat', Act Now
Việt Nam Hacker
Threats against Microsoft Exchange continue to mount, but there are steps both organizations and Microsoft can take.
0
Phishing Tool Uses Smart Redirects to Bypass Detection
Việt Nam Hacker
A campaign against Microsoft 365 users leverages Quantum Route Redirection, which simplifies previously technical attack steps and has affected victims across 90 countries.
0
Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs
Thứ Ba, 11 tháng 11, 2025
Việt Nam Hacker
Security teams may have a less burdensome rollout in November after October's Goliath Patch Tuesday, but shouldn't wait on a few top-priority fixes.
0
Grandparents to C-Suite: Elder Fraud Reveals Gaps in Human-Centered Cybersecurity
Việt Nam Hacker
Cybercriminals are weaponizing AI voice cloning and publicly available data to craft social engineering scams that emotionally manipulate senior citizens—and drain billions from their savings.
0
Kimsuky APT Takes Over South Korean Androids, Abuses KakaoTalk
Việt Nam Hacker
Konni, a subset of the state-sponsored DPRK cyberespionage group, first exploits Google Find Hub, which ironically aims to protect lost Android devices, to remotely wipe devices.
0
Bridging the Skills Gap: How Military Veterans Are Strengthening Cybersecurity
Việt Nam Hacker
From intelligence analysts to surface warfare officers, military veterans of all backgrounds are successfully pivoting to cybersecurity careers and strengthening the industry's defense capabilities.
0
GlassWorm Returns, Slices Back into VS Code Extensions
Thứ Hai, 10 tháng 11, 2025
Việt Nam Hacker
GlassWorm, a self-propagating VS Code malware first found in the Open VSX marketplace, continues to infect developer devices around the world.
0
ClickFix Campaign Targets Hotels, Spurs Secondary Customer Attacks
Việt Nam Hacker
Attackers compromise hospitality providers with an infostealer and RAT malware and then use stolen data to launch a phishing attacks against customers via both email and WhatsApp.
0
'Landfall' Malware Targeted Samsung Galaxy Users
Thứ Sáu, 7 tháng 11, 2025
Việt Nam Hacker
The tool let its operators secretly record conversations, track device locations, capture photos, collect contacts, and perform other surveillance on compromised devices.
0
Microsoft Backs Massive AI Push in UAE, Raising Security Concerns
Việt Nam Hacker
In partnership with Emirates tech company G42, Microsoft is building the first stage of a 5-gigawatt US-UAE AI campus using Nvidia GPUs.
0
Ollama, Nvidia Flaws Put AI Infrastructure at Risk
Việt Nam Hacker
Security researchers discovered multiple vulnerabilities in AI infrastructure products, including one capable of remote code execution.
0
Sora 2 Makes Videos So Believable, Reality Checks Are Required
Thứ Năm, 6 tháng 11, 2025
Việt Nam Hacker
Threat actors will continue to abuse deepfake technology to conduct fraudulent activity, so organizations need to implement strong security protocols – even if it adds to user friction.
0
SonicWall Firewall Backups Stolen by Nation-State Actor
Việt Nam Hacker
The network security vendor said the MySonicWall breach was unrelated to the recent wave of Akira ransomware attacks targeting the company's devices.
0
Multiple ChatGPT Security Bugs Allow Rampant Data Theft
Việt Nam Hacker
Attackers can use them to inject arbitrary prompts, exfiltrate personal user information, bypass safety mechanisms, and take other malicious actions.
0
APT 'Bronze Butler' Exploits Zero-Day to Root Japan Orgs
Thứ Tư, 5 tháng 11, 2025
Việt Nam Hacker
A critical security issue in a popular endpoint manager (CVE-2025-61932) allowed Chinese state-sponsored attackers to backdoor Japanese businesses.
0
Nikkei Suffers Breach Via Slack Compromise
Việt Nam Hacker
The Japanese media giant said thousands of employee and business partners were impacted by an attack that compromised Slack account data and chat histories.
0
Elusive Iranian APT Phishes Influential US Policy Wonks
Việt Nam Hacker
Iran is spying on American foreign policy influencers. But exactly which of its government's APTs is responsible remains a mystery.
0
Kimsuky Debuts HTTPTroy Backdoor Against South Korea Users
Thứ Ba, 4 tháng 11, 2025
Việt Nam Hacker
The well-known North Korean threat group continues to improve the obfuscation and anti-analysis features of its attack toolchain.
0
Europe Sees Increase in Ransomware, Extortion Attacks
Việt Nam Hacker
European organizations face an escalating cyber threat landscape as attackers leverage geopolitical tensions and AI-enhanced social engineering for attacks.
0
SesameOp Backdoor Uses OpenAI API for Covert C2
Việt Nam Hacker
Malware used in a months-long attack demonstrates how bad actors are misusing generative AI services in unique and stealthy ways.
0
Android Malware Mutes Alerts, Drains Crypto Wallets
Thứ Hai, 3 tháng 11, 2025
Việt Nam Hacker
Android/BankBot-YNRK is currently targeting users in Indonesia by masquerading as legitimate applications.
0
Hackers Weaponize Remote Tools to Hijack Cargo Freight
Việt Nam Hacker
Researchers uncovered a new threat campaign in which attackers use RMM tools to steal physical cargo out of the supply chain.
0
‘TruffleNet’ Attack Wields Stolen Credentials Against AWS
Việt Nam Hacker
Reconnaissance and BEC are among the malicious activities attackers commit after compromising cloud accounts, using a framework based on the TruffleHog tool.
0
Let's Get Physical: A New Convergence for Electrical Grid Security
Việt Nam Hacker
The power grid is being attacked online and IRL. Increasingly, regulators and industry experts agree: Security teams need to focus on both cyber and physical threats, together.
0
AI Developed Code: 5 Critical Security Checkpoints for Human Oversight
Việt Nam Hacker
To write secure code with LLMs developers must have the skills to use AI as a collaborative assistant rather than an autonomous tool, Madou argues.
0
Ribbon Communications Breach Marks Latest Telecom Attack
Thứ Sáu, 31 tháng 10, 2025
Việt Nam Hacker
The US telecom company disclosed that suspected nation-state actors first gained access to its network in December of last year, though it's unclear if attackers obtained sensitive data.
0
Cyber's Role in the Rapid Rise of Digital Authoritarianism
Việt Nam Hacker
Dark Reading Confidential Episode 11: Enterprise cyber teams are in prime position to push back against our current "Golden Age of Surveillance," according to our guests Ronald Deibert from Citizen Lab and David Greene from the EFF.
0
LotL Attack Hides Malware in Windows Native AI Stack
Thứ Năm, 30 tháng 10, 2025
Việt Nam Hacker
Security programs trust AI data files, but they shouldn't: they can conceal malware more stealthily than most file types.
0
The AI Trust Paradox: Why Security Teams Fear Automated Remediation
Việt Nam Hacker
Security teams invest in AI for automated remediation but hesitate to trust it fully due to fears of unintended consequences and lack of transparency.
0
AI Search Tools Easily Fooled by Fake Content
Thứ Tư, 29 tháng 10, 2025
Việt Nam Hacker
0
Dentsu Subsidiary Breached, Employee Data Stolen
Việt Nam Hacker
A subsidiary of Japanese marketing and PR giant Dentsu lost sensitive data to unidentified threat actors, the parent company said.
0
Microsoft Security Change for Azure VMs Creates Pitfalls
Việt Nam Hacker
Firms using Azure infrastructure gained a reprieve from a security-focused switch that could have broken apps that relied on public Internet access.
0
From Power Users to Protective Stewards: How to Tune Security Training for Specialized Employees
Việt Nam Hacker
How the best security training programs build strong security culture by focusing on high-risk groups like developers, executives, finance pros and more.
0
Cybersecurity Firms See Surge in AI-Powered Attacks Across Africa
Thứ Ba, 28 tháng 10, 2025
Việt Nam Hacker
Africa becomes a proving ground for AI-driven phishing, deepfakes, and impersonation, with attackers testing techniques against governments and enterprises.
0
From Chef to CISO: An Empathy-First Approach to Cybersecurity Leadership
Việt Nam Hacker
Myke Lyons, CISO at data-processing SaaS company Cribl, shares how he cooked up an unconventional journey from culinary school to cybersecurity leadership.
0
Oracle EBS Attack Victims May Be More Numerous Than Expected
Việt Nam Hacker
Numerous organizations have been attacked via Oracle EBS zero-day CVE-2025-61882, and evidence suggests more like Schneider Electric could be on that list.
0
Attackers Sell Turnkey Remote Access Trojan 'Atroposia'
Việt Nam Hacker
Atroposia, a new RAT malware, offers low-level cybercriminal affiliates the ability to utilize sophisticated stealth and persistence capabilities.
0
'Jingle Thief' Highlights Retail Cyber Threats
Thứ Hai, 27 tháng 10, 2025
Việt Nam Hacker
A Morocco-based gift card fraud campaign is a sign of what retailers can expect this holiday season.
0
Memento Spyware Tied to Chrome Zero-Day Attacks
Việt Nam Hacker
While investigating the cyberattacks, researchers uncovered a new spyware product from Memento Labs, the successor to the infamous Hacking Team.
0
CISOs Finally Get a Seat at the Board's Table — But There's a Catch
Việt Nam Hacker
AI's explosive growth has lifted cybersecurity to the top of the board's agenda. Here's how CISOs can seize the moment, according to Diana Kelley.
0
Qilin Targets Windows Hosts With Linux-Based Ransomware
Việt Nam Hacker
The attack by the one of the most impactful RaaS groups active today demonstrates an evasion strategy that can stump defenses not equipped to detect cross-platform threats.
0
How CISA Layoffs Weaken Civilian Cyber Defense
Thứ Sáu, 24 tháng 10, 2025
Việt Nam Hacker
Cyber teams need to get to work backfilling diminishing federal resources, according to Alexander Garcia-Tobar, who shares clear steps on a path forward for protecting enterprises with less CISA help.
0
Shutdown Sparks 85% Increase in US Government Cyberattacks
Việt Nam Hacker
Attackers are pouncing on financially strapped US government agencies and furloughed employees. And the effects of this period might be felt for a long time hereafter.
0
US Crypto Bust Offers Hope in Battle Against Cybercrime Syndicates
Thứ Năm, 23 tháng 10, 2025
Việt Nam Hacker
A $14 billion seizure by US investigators presents a warning for cybercriminals' reliance on bitcoin but is still a positive development for the cryptocurrency industry.
0
Tired of Unpaid Toll Texts? Blame the 'Smishing Triad'
Việt Nam Hacker
Chinese smishers — the bane of every American with a phone — have been shifting to lower-frequency, possibly higher-impact government impersonation attacks.
0
Asian Nations Ramp Up Pressure on Cybercrime 'Scam Factories'
Thứ Tư, 22 tháng 10, 2025
Việt Nam Hacker
After a particularly gruesome murder, South Korea issues "code black" travel ban for several regions in Cambodia, while other nations urge more raids.
0
Too Many Secrets: Attackers Pounce on Sensitive Data Sprawl
Việt Nam Hacker
Hardcoded credentials, access tokens, and API keys are ending up in the darnedest places, prompting a call for organizations to stop over-privileging secrets.
0
WhatsApp Secures Ban on NSO Group After 6-Year Legal Battle
Việt Nam Hacker
NSO Group must pay $4 million in damages and is permanently prohibited from reverse-engineering WhatsApp or creating new accounts after targeting users with spyware.
0
MuddyWater Targets 100+ Gov Entities in MEA with Phoenix Backdoor
Việt Nam Hacker
The Iranian threat group is using a compromised mailbox accessed through NordVPN to send phishing emails that prompt recipients to enable macros.
0
Verizon: Mobile Blindspot Leads to Needless Data Breaches
Việt Nam Hacker
People habitually ignore cybersecurity on their phones. Instead of compensating for that, organizations are falling into the very same trap, even though available security options could cut smishing success and breaches in half.
0
Electronic Warfare Puts Commercial GPS Users on Notice
Thứ Ba, 21 tháng 10, 2025
Việt Nam Hacker
Interference with the global positioning system (GPS) isn't just a problem for airlines, but for shipping, trucking, car navigation, agriculture, and even the financial sector.
0
Self-Propagating GlassWorm Attacks VS Code Supply Chain
Thứ Hai, 20 tháng 10, 2025
Việt Nam Hacker
The sophisticated worm — which uses invisible code to steal credentials and turn developer systems into criminal proxies — has so far infected nearly 36k machines.
0
Flawed Vendor Guidance Exposes Enterprises to Avoidable Risk
Việt Nam Hacker
Oracle E-Business Suite customers received conflicting deployment guidance, leaving enterprises exposed a recent zero-day flaw, Andrew argues.
0
Cyber Academy Founder Champions Digital Safety for All
Thứ Bảy, 18 tháng 10, 2025
Việt Nam Hacker
Aliyu Ibrahim Usman, founder of the Cyber Cadet Academy in Nigeria, shares his passion for raising cybersecurity awareness in the wake of mounting security concerns worldwide.
0
Microsoft Disrupts Ransomware Campaign Abusing Azure Certificates
Thứ Sáu, 17 tháng 10, 2025
Việt Nam Hacker
Microsoft revoked more than 200 digital certificates that threat actors used to sign fake Teams binaries that set the stage for Rhysida ransomware attacks.
0
AI Agent Security: Whose Responsibility Is It?
Việt Nam Hacker
The shared responsibility model of data security, familiar from cloud deployments, is key to agentic services, but cybersecurity teams and corporate users often struggle with awareness and managing that risk.
0
AI Chat Data Is History’s Most Thorough Record of Enterprise Secrets, Secure it Wisely
Việt Nam Hacker
AI interactions are becoming one of the most revealing records of human thinking; and we're only beginning to understand what that means for law enforcement, accountability, and privacy.
0
Cyberattackers Target LastPass, Top Password Managers
Thứ Năm, 16 tháng 10, 2025
Việt Nam Hacker
Be aware: a rash of phishing campaigns are leveraging the anxiety and trust employees have in password vaults securing all of their credentials.
0
Leaks in Microsoft VS Code Marketplace Put Supply Chain at Risk
Việt Nam Hacker
Researchers discovered more than 550 unique secrets exposed in Visual Studio Code marketplaces, prompting Microsoft to bolster security measures.
0
China Hackers Test AI-Optimized Attack Chains in Taiwan
Việt Nam Hacker
AI might help some threat actors in certain respects, but one group is proving that its use for cyberattacks has its limits.
0
LevelBlue Announces Plans to Acquire XDR Provider Cybereason
Thứ Tư, 15 tháng 10, 2025
Việt Nam Hacker
The deal, which builds on LevelBlue’s recent acquisition of Trustwave and Aon, aims to provide customers with a broad portfolio of extended detection and response (XDR), managed detection and response (MDR), and forensic services.
0
'Mysterious Elephant' Moves Beyond Recycled Malware
Việt Nam Hacker
The cyber-espionage group has been using sophisticated custom tools to target government and diplomatic entities in South Asia since early 2025.
0
F5 BIG-IP Environment Breached by Nation-State Actor
Việt Nam Hacker
F5 disclosed a breach this week that included zero-day bugs, source code, and some customer information.
0
Africa Remains Top Global Target, Even as Attacks Decline
Việt Nam Hacker
Organizations across the continent saw 10% fewer attacks in September, but Africa remains the most attacked region in the world, leading the Global South.
0
Microsoft Drops Terrifyingly Large October Patch Update
Thứ Ba, 14 tháng 10, 2025
Việt Nam Hacker
October 2025's enormous Patch Tuesday offers plenty of nightmares for admins, including actively exploited zero-days and insidious high-severity privilege-escalation bugs — and it spells curtains for Windows 10 updates.
0
China's Flax Typhoon Turns Geo-Mapping Server into a Backdoor
Việt Nam Hacker
Chinese APT threat actors compromised an organization's ArcGIS server, modifying the widely used geospatial mapping software for stealth access.
0
Pixnapping Attack Lets Attackers Steal 2FA on Android
Việt Nam Hacker
The proof-of-concept exploit allows an attacker to steal sensitive data from Gmail, Google Accounts, Google Authenticator, Google Maps, Signal, and Venmo.
0
Financial, Other Industries Urged to Prepare for Quantum Computers
Thứ Hai, 13 tháng 10, 2025
Việt Nam Hacker
Despite daunting technical challenges, a quantum computer capable of breaking public-key encryption systems may only be a decade or two off.
0
Critical infrastructure CISOs Can't Ignore 'Back-Office Clutter' Data
Việt Nam Hacker
OT and ICS systems indeed hold the crown jewels of critical infrastructure organizations, but unmonitored data sprawl is proving to be pure gold for increasingly brazen nation-state threat actors like Volt Typhoon, Pearce argues.
0
Generation AI: Why Today's Tech Graduates Are At a Disadvantage
Việt Nam Hacker
With artificial intelligence supplanting entry-level security jobs, new cyber professionals will have to up their game to stay competitive in the industry.
0
The Fight Against Ransomware Heats Up on the Factory Floor
Thứ Sáu, 10 tháng 10, 2025
Việt Nam Hacker
Ransomware gangs continue to set their sights on the manufacturing industry, but companies are taking steps to protect themselves, starting with implementing timely patch management protocols.
0
RondoDox Botnet: an 'Exploit Shotgun' for Edge Vulns
Việt Nam Hacker
RondoDox takes a hit-and-run, shotgun approach to exploiting bugs in consumer edge devices around the world.
0
Microsoft Adds Agentic AI Capabilities to Sentinel
Việt Nam Hacker
Microsoft previewed the Sentinel security graph and MCP server at its annual Microsoft Secure virtual event earlier this month.
0
Feds Shutter ShinyHunters Salesforce Extortion Site
Việt Nam Hacker
The group warned that law-enforcement crackdowns are imminent in the wake of the takedown, but its extortion threats against Salesforce victims remain active.
0
Deepfake Awareness High at Orgs, But Cyber Defenses Badly Lag
Việt Nam Hacker
The vast majority of organizations are encountering AI-augmented threats, but remain confident in their defenses, despite inadequate detection investment and more than half falling to successful attacks.
0
Commentary Section Launches New, More Opinionated Era
Việt Nam Hacker
Dark Reading is looking for leading industry experts with a point of view they want to share with the rest of the cybersecurity community for our new Commentary section.
0
GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data
Thứ Năm, 9 tháng 10, 2025
Việt Nam Hacker
While GitHub has advanced protections for its built-in AI agent, a researcher came up with a creative proof-of-concept (PoC) attack for exfiltrating code and secrets via Copilot.
0
SonicWall: 100% of Firewall Backups Were Breached
Việt Nam Hacker
SonicWall said a breach it disclosed last month affected firewall configuration files for all customers who have used SonicWall’s cloud backup service — up from its previous 5% estimate.
0
Red Hat Hackers Team Up With Scattered Lapsus$ Hunters
Thứ Tư, 8 tháng 10, 2025
Việt Nam Hacker
Crimson Collective, which recently breached the GitLab instance of Red Hat Consulting, has teamed up with the notorious cybercriminal collective.
0
LockBit, Qilin & DragonForce Join Forces in Ransomware 'Cartel'
Việt Nam Hacker
The three extortion gangs also invited other e-crime attackers to join their collaboration to share attack information and resources, in the wake of LockBit 5.0 being released.
0
Figma MCP Server Opens Orgs to Agentic AI Compromise
Việt Nam Hacker
Patch now: A bug (CVE-2025-53967) in the popular Web design tool's option for talking to agentic AI can lead to remote code execution (RCE).
0
Cyberattack Leads to Beer Shortage as Asahi Recovers
Thứ Ba, 7 tháng 10, 2025
Việt Nam Hacker
A ransomware last week left the Asahi brewery in Japan struggling to take orders and deliver its products domestically, as manufacturers become a favored target.
0
Attackers Season Spam With a Touch of 'Salt'
Việt Nam Hacker
Researchers report an increase in the use of hidden content in spam and malicious email to confuse filters and other security mechanisms.
0
Security Concerns Shadow Vibe Coding Adoption
Việt Nam Hacker
In a recent poll, readers shared how they're using vibe coding in AppDev (if they are at all). While some found success, others found the risks too great.
0
Medusa Ransomware Actors Exploit Critical Fortra GoAnywhere Flaw
Việt Nam Hacker
Researchers say exploitation of CVE-2025-10035 requires a private key, and it's unclear how Storm-1175 threat actors pulled this off.
0
Patch Now: ‘RediShell’ Threatens Cloud Via Redis RCE
Việt Nam Hacker
A 13-year-old flaw with a CVSS score of 10 in the popular data storage service allows for full host takeover, and more than 300k instances are currently exposed.
0
Cyberattackers Exploit Zimbra Zero-Day Via ICS
Thứ Hai, 6 tháng 10, 2025
Việt Nam Hacker
A threat actor purporting to be from the Libyan Navy's Office of Protocol targeted Brazil's military earlier this year using the rare tactic.
0
Clop Ransomware Hits Oracle Customers Via Zero-Day Flaw
Việt Nam Hacker
The infamous Clop gang has targeted a wide range of Oracle E-Business Suite customers using a newly disclosed zero-day vulnerability.
0
Self-Propagating Malware Hits WhatsApp Users in Brazil
Việt Nam Hacker
The enterprise-focused Water Saci campaign spreads Sorvepotel, which can steal credentials and monitor browser activity to defraud financial institutions in the region.
0
Dutch Authorities Arrest Two Teens for Alleged Pro-Russian Espionage
Thứ Sáu, 3 tháng 10, 2025
Việt Nam Hacker
Dutch Prime Minister Dick Schoof described the incident as part of a broader pattern of Russian hybrid attacks against Europe.
0
BCI: The Thing of Nightmare or Dreams?
Việt Nam Hacker
Brain computer interface technology looks to provide users with hands-free device control, but could security ever keep up with the risks?
0
Microsoft's Voice Clone Becomes Scary & Unsalvageable
Việt Nam Hacker
An attacker's dream: Windows Speak for Me could integrate into apps, creating perfect voice replicas for Teams calls and AI agent interactions across multiple SaaS platforms.
0
There Are More CVEs, But Cyber Insurers Aren't Altering Policies
Thứ Năm, 2 tháng 10, 2025
Việt Nam Hacker
With nearly 47,000 CVEs expected by the end of the year, organizations must balance comprehensive vulnerability management with strategic cyber insurance policy selection to effectively navigate this rapidly evolving threat landscape.
0
'Confucius' Cyberspy Evolves From Stealers to Backdoors in Pakistan
Việt Nam Hacker
The long-running South Asian advanced persistent threat (APT) group is advancing its objectives against Pakistani targets, with a shift to deploying Python-based surveillance malware.
0
Android Spyware in the UAE Masquerades as ... Spyware
Việt Nam Hacker
In a clever, messed-up twist on brand impersonation, attackers are passing off their spyware as a notorious UAE government surveillance app.
0
Shutdown Threatens US Intel Sharing, Cyber Defense
Thứ Tư, 1 tháng 10, 2025
Việt Nam Hacker
0
China Imposes One-Hour Reporting Rule for Major Cyber Incidents
Thứ Ba, 30 tháng 9, 2025
Việt Nam Hacker
The sweeping new regulations show that China's serious about hardening its own networks after launching widespread attacks on global networks.
0
New China APT Strikes With Precision and Persistence
Việt Nam Hacker
Phantom Taurus demonstrates a deep understanding of Windows environments, including advanced components like IIServerCore, a fileless backdoor that executes in memory to evade detection.
0
'Klopatra' Trojan Makes Bank Transfers While You Sleep
Việt Nam Hacker
A sophisticated new banking malware is hard to detect, capable of stealing lots of money, and infecting thousands of people in Italy and Spain.
0
China Exploited New VMware Bug for Nearly a Year
Việt Nam Hacker
A seemingly benign privilege-escalation process in VMware and other software has likely benefited attackers and other malware strains for years, researchers noted.
0
AI-Powered Voice Cloning Raises Vishing Risks
Việt Nam Hacker
A researcher-developed framework could enable attackers to conduct real-time conversations using simulated audio to compromise organizations and extract sensitive information.
0
Akira Hits SonicWall VPNs in Broad Ransomware Campaign
Thứ Hai, 29 tháng 9, 2025
Việt Nam Hacker
Akira ransomware actors are currently targeting SonicWall firewall customers vulnerable to a bug discovered last year.
0
Ukrainian Cops Spoofed in Fileless Phishing Attacks on Kyiv
Việt Nam Hacker
Attackers impersonate the National Police of Ukraine to deploy Amatera Stealer and PureMiner, using malicious Scalable Vector Graphics to trick victims.
0
Volvo Employee SSNs Stolen in Supplier Ransomware Attack
Thứ Sáu, 26 tháng 9, 2025
Việt Nam Hacker
Three international vehicle manufacturers have fallen to supply chain cyberattacks in the past month alone.
0
Iranian State Hackers Use SSL.com Certificates to Sign Malware
Việt Nam Hacker
Security researchers say multiple threat groups, including Iran's Charming Kitten APT offshoot Subtle Snail, are deploying malware with code-signing certificates from the Houston-based company.
0
Prep is Underway, But 2026 FIFA World Cup Poses Significant Cyber Challenges
Việt Nam Hacker
The world's most-popular sports contest starts in June 2026 across 16 venues in three countries: Securing the event infrastructure from cyber threats will require massive collaboration.
0
Salesforce AI Agents Forced to Leak Sensitive Data
Thứ Năm, 25 tháng 9, 2025
Việt Nam Hacker
Yet again researchers have uncovered an opportunity (dubbed "ForcedLeak" for indirect prompt injection against autonomous agents lacking sufficient security controls — but this time the risk involves PII, corporate secrets, physical location data, and so much more.
0
Chinese APT Drops 'Brickstorm' Backdoors on Edge Devices
Việt Nam Hacker
The China-linked cyber-espionage group UNC5221 is compromising network appliances that cannot run traditional EDR agents to deploy new versions of the "Brickstorm" backdoor.
0
CISA: Attackers Breach Federal Agency via Critical GeoServer Flaw
Thứ Tư, 24 tháng 9, 2025
Việt Nam Hacker
Threat actors exploited CVE-2024-36401 less than two weeks after it was initially disclosed and used it to gain access to a large federal civilian executive branch (FCEB) agency that uses the geospatial mapping data.
0
Russia Targets Moldovan Election in Disinformation Play
Việt Nam Hacker
Researchers have tracked a Russian disinformation campaign against upcoming Moldovan elections, linking it to a previous campaign that began in 2022.
0
Npm Package Hides Malware in Steganographic QR Codes
Việt Nam Hacker
The poisoned package, purporting to be a JavaScript utility, threatens the software supply chain with a highly obsfuscated credential stealer.
0
Exposed Docker Daemons Fuel DDoS Botnet
Thứ Ba, 23 tháng 9, 2025
Việt Nam Hacker
The for-hire platform leverages legitimate cloud-native tools to make detection and disruption harder for defenders and SOC analysts.
0
From FBI to CISO: Unconventional Paths to Cybersecurity Success
Việt Nam Hacker
Cybersecurity leader Jason Manar shares insights on diverse career paths, essential skills, and practical advice for entering and thriving in the high-stress yet rewarding field of cybersecurity.
0
Dark Reading Confidential: Battle Space: Cyber Pros Land on the Front Lines of Protecting US Critical Infrastructure
Việt Nam Hacker
Dark Reading Confidential Episode 10: It’s past time for a comprehensive plan to protect vital US systems from nation-state cyberattacks, and increasingly, that responsibility is falling to asset owners across a vast swath of organizations, who likely never bargained for an international cyber conflict playing out in their environments. But here we are. And here’s what comes next, according to Frank Cilluffo from the McCrary Institute and Booz Allen’s Dave Forbes.
0
Zero Trust: Strengths and Limitations in the AI Attack Era
Thứ Hai, 22 tháng 9, 2025
Việt Nam Hacker
Zero Trust could help organizations fight back against attackers who use artificial intelligence, but new threats will require the architecture to evolve.
0
Attackers Use Phony GitHub Pages to Deliver Mac Malware
Việt Nam Hacker
Threat actors are using a large-scale SEO poisoning campaign and fake GitHub repositories to deliver Atomic infostealers to Mac users.
0
Airport Chaos Shows Human Impact of 3rd-Party Attacks
Việt Nam Hacker
Major EU airports such as Heathrow were disrupted over the weekend after a cyberattack hit the provider of check-in kiosk software, which caused delays and flight cancellations.
0
15 Years of Zero Trust: Why It Matters More Than Ever
Việt Nam Hacker
With the emergence of AI-driven attacks and quantum computing, and the explosion of hyperconnected devices, zero trust remains a core strategy for security operations.
0
Patch Now: Max-Severity Fortra GoAnywhere Bug Allows Command Injection
Thứ Sáu, 19 tháng 9, 2025
Việt Nam Hacker
Exploitation of the flaw, tracked as CVE-2025-10035, is highly dependent on whether systems are exposed to the Internet, according to Fortra.
0
'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails
Việt Nam Hacker
The loophole allows cyberattackers to exfiltrate company data via OpenAI's infrastructure, leaving no trace at all on enterprise systems.
0
Critical Azure Entra ID Flaw Highlights Microsoft IAM Issues
Việt Nam Hacker
While the cloud vulnerability was fixed prior to disclosure, the researcher who discovered it says it could have led to catastrophic attacks.
0
7 Lessons for Securing AI Transformation From Former CIA Digital Guru
Việt Nam Hacker
Jennifer Ewbank, former CIA deputy director of digital innovation, discusses resilience, cultural shifts, and cyber fundamentals in the AI era.
0
TikTok Deal Won't End Enterprise Risks
Thứ Năm, 18 tháng 9, 2025
Việt Nam Hacker
The proposed restructuring plan would address many concerns related to the social media platform, but risks remain for security teams.
0
SonicWall Breached, Firewall Backup Data Exposed
Việt Nam Hacker
Threat actors breached the MySonicWall service and accessed backup firewall configuration files belonging to "fewer than 5%" of its install base, according to the company.
0
Mastering Digital Breadcrumbs to Stay Ahead of Evolving Threats
Việt Nam Hacker
Digital forensics offers a challenging but rewarding career path for cybersecurity professionals willing to invest in specialized knowledge and continuous learning.
0
The Cloud Edge Is The New Attack Surface
Việt Nam Hacker
The cloud now acts as the connecting infrastructure for many companies' assets — from IoT devices to workstations to applications and workloads — exposing the edge to threats.
0
Microsoft Disrupts 'RaccoonO365' Phishing Service
Thứ Tư, 17 tháng 9, 2025
Việt Nam Hacker
Phishing-as-a-service (PhaaS) kits have become an increasingly popular way for lower-skill individuals who want to get into cybercrime.
0
'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree
Việt Nam Hacker
Though the groups have shared their decision to go dark, threat researchers say there are signs that it's business as usual.
0
North Korean Group Targets South With Military ID Deepfakes
Thứ Ba, 16 tháng 9, 2025
Việt Nam Hacker
The North Korea-linked group Kimsuky used ChatGPT to create deepfakes of military ID documents in an attempt to compromise South Korean targets.
0
Critical Bugs in Chaos Mesh Enable Cluster Takeover
Việt Nam Hacker
"Chaotic Deputy" is a set of four vulnerabilities in the chaos engineering platform that many organizations use to test the resilience of their Kubernetes environments.
0
'Vane Viper' Threat Group Tied to PropellerAds, Commercial Entities
Việt Nam Hacker
Researchers say the commercial adtech platform and several other companies form the infrastructure of a massive cybercrime operation.
0
'HybridPetya' Ransomware Bypasses Secure Boot
Việt Nam Hacker
The malware, which has traits of Petya ransomware and the infamous NotPetya wiper, is designed to target UEFI-based systems, according to researchers.
0
SecurityScorecard Buys AI Automation Capabilities, Boosts Vendor Risk Management
Việt Nam Hacker
The company acquired HyperComply to help enterprises automate vendor security reviews and gain a real-time picture of the security of their entire supply chain.
0
FBI Warns of Threat Actors Hitting Salesforce Customers
Thứ Hai, 15 tháng 9, 2025
Việt Nam Hacker
The FBI's IC3 recently warned of two threat actors, UNC6040 and UNC6395, targeting Salesforce customers, separately and in tandem.
0
'Lies-in-the-Loop' Attack Defeats AI Coding Agents
Việt Nam Hacker
Researchers convince Anthropic's AI-assisted coding tool to engage in dangerous behavior by lying to it, paving the way for a supply chain attack.
0
French Advisory Sheds Light on Apple Spyware Activity
Thứ Sáu, 12 tháng 9, 2025
Việt Nam Hacker
CERT-FR's advisory follows last month's disclosure of a zero-day flaw Apple said was used in "sophisticated" attacks against targeted individuals.
0
'Gentlemen' Ransomware Abuses Vulnerable Driver to Kill Security Gear
Thứ Năm, 11 tháng 9, 2025
Việt Nam Hacker
By weaponizing the ThrottleStop.sys driver, attackers are disrupting antivirus and endpoint detection and response (EDR) systems.
0
AI-Enhanced Malware Sports Super-Stealthy Tactics
Việt Nam Hacker
With legit sounding names, EvilAI's "productivity" apps are reviving classic threats like Trojans while adding new evasion capabilities against modern antivirus defenses.
0
Vidar Infostealer Back with a Vengeance
Việt Nam Hacker
The pervasive Vidar infostealer has evolved with a suite of new evasion techniques and covert data exfiltration methods, according to researchers.
0
'K2 Think' AI Model Jailbroken Mere Hours After Release
Việt Nam Hacker
Researchers discovered that measures designed to make AI more transparent to users and regulators can also make it easier for bad actors to abuse.
0
Russian APT Attacks Kazakhstan's Largest Oil Company
Việt Nam Hacker
Researchers say a likely Russian APT used a compromised employee email account to attack Kazakhstan's biggest company, though the oil and gas firm claims it was a pen test.
0
Students Pose Inside Threat to Education Sector
Thứ Tư, 10 tháng 9, 2025
Việt Nam Hacker
0
Chinese Hackers Allegedly Pose as US Lawmaker
Việt Nam Hacker
Chinese state-backed threat actors are suspected of posing as Michigan congressman John Moolenaar in a series of spearphishing attacks.
0
EoP Flaws Again Lead Microsoft Patch Day
Thứ Ba, 9 tháng 9, 2025
Việt Nam Hacker
Nearly half the CVEs Microsoft disclosed in its September security update, including one publicly known bug, enable escalation of privileges.
0
Qantas Reduces Executive Pay Following Cyberattack
Việt Nam Hacker
The data breach, which occurred earlier this year, saw threat actors compromise a third-party platform to obtain Qantas customers' personal information.
0
Huge NPM Supply-Chain Attack Goes Out With Whimper
Việt Nam Hacker
Threat actors phished Qix's NPM account, then used their access to publish poisoned versions of 18 popular open-source packages accounting for more than 2 billion weekly downloads.
0
Salty2FA Takes Phishing Kits to Enterprise Level
Việt Nam Hacker
Cybercriminal operations use the same strategy and planning as legitimate organizations as they arm adversarial phishing kits with advanced features.
0
SentinelOne Announces Plans to Acquire Observo AI
Việt Nam Hacker
The combined company will help customers separate data ingestion from SIEM, to improve detection and performance.
0
'MostereRAT' Malware Blends In, Blocks Security Tools
Thứ Hai, 8 tháng 9, 2025
Việt Nam Hacker
A threat actor is using a sophisticated EDR-killing malware tool in a campaign to maintain long-term, persistent access on Windows systems.
0
Salesloft Breached via GitHub Account Compromise
Việt Nam Hacker
The breach kickstarted a massive supply chain attack that led to the compromise of hundreds of Salesforce instances through stolen OAuth tokens.
0
45 New Domains Linked to Salt Typhoon, UNC4841
Việt Nam Hacker
The China-backed threat actors have used the previously undiscovered infrastructure to obtain long-term, stealthy access to targeted organizations.
0
Scammers Are Using Grok to Spread Malicious Links on X
Thứ Sáu, 5 tháng 9, 2025
Việt Nam Hacker
It's called "grokking," and gives spammers a way to skirt X's ban on links in promoted posts and reach larger audiences than ever before.
0
Anyone Using Agentic AI Needs to Understand Toxic Flows
Việt Nam Hacker
The biggest vulnerabilities may lie at the boundaries of where the AI agent connects with the enterprise system.
0
ISC2 Aims to Bridge DFIR Skill Gap with New Certificate
Thứ Năm, 4 tháng 9, 2025
Việt Nam Hacker
The Nonprofit organization launched the Threat Handling Foundations Certificate amid mounting incident and breach disclosures.
0
Czech Warning Highlights China Stealing User Data
Việt Nam Hacker
Czech cyber agency NÚKIB warned of the risks of using products and software that send data back to China.
0
Blast Radius of Salesloft Drift Attacks Remains Uncertain
Việt Nam Hacker
Many high-profile Salesloft Drift customers have disclosed data breaches as a result of a recent supply-chain attack, but the extent and severity of this campaign are unclear.
0
Japan, South Korea Take Aim at North Korean IT Worker Scam
Thứ Tư, 3 tháng 9, 2025
Việt Nam Hacker
With the continued success of North Korea's IT worker scams, Asia-Pacific nations are working with private firms to blunt the scheme's effectiveness.
0
Cloudflare Holds Back the Tide on 11.5Tbps DDoS Attack
Việt Nam Hacker
It's the equivalent of watching more than 9,350 full-length HD movies or streaming 7,480 hours of high-def video nonstop in less than a minute.
0
Hacked Routers Linger on the Internet for Years, Data Shows
Việt Nam Hacker
While trawling Internet scan data for signs of compromised infrastructure, researchers found that asset owners may not know for years their devices had been hacked.
0
Amazon Stymies APT29 Credential Theft Campaign
Thứ Ba, 2 tháng 9, 2025
Việt Nam Hacker
A group linked to Russian intelligence services redirected victims to fake Cloudflare verification pages and exploited Microsoft's device code authentication flow.
0
Zscaler, Palo Alto Networks Breached via Salesloft Drift
Việt Nam Hacker
Two major security firms suffered downstream compromises as part of a large-scale supply chain attack involving Salesloft Drift, a marketing SaaS application from Salesforce.
0
Jaguar Land Rover Shuts Down in Scramble to Secure 'Cyber Incident'
Việt Nam Hacker
0
JSON Config File Leaks Azure ActiveDirectory Credentials
Việt Nam Hacker
In this type of misconfiguration, cyberattackers could use exposed secrets to authenticate directly via Microsoft’s OAuth 2.0 endpoints and infiltrate Azure cloud environments.
0
Hackers Are Sophisticated & Impatient — That Can Be Good
Việt Nam Hacker
You can't negotiate with hackers from a place of fear — but you can turn their urgency against them with the right playbook, people, and preparation.
0
NIST Enhances Security Controls for Improved Patching
Việt Nam Hacker
The U.S. National Institute of Standards and Technology released Security and Privacy Control version 5.2.0 to help organizations be more proactive regarding patching.
0
Akira, Cl0p Top List of 5 Most Active Ransomware-as-a-Service Groups
Thứ Năm, 28 tháng 8, 2025
Việt Nam Hacker
Flashpoint published its 2025 midyear ransomware report that highlighted the top five most prolific groups currently in operation.
0
1,000+ Devs Lose Their Secrets to an AI-Powered Stealer
Việt Nam Hacker
One of the most sophisticated supply chain attacks to date caused immense amounts of data to leak to the Web in a matter of hours.
0
Dark Reading Confidential: A Guided Tour of Today's Dark Web
Việt Nam Hacker
Dark Reading Confidential Episode 9: Join us for a look around today's Dark Web, and find out how law enforcement, AI, nation-state activities, and more are reshaping the way cybercriminals conduct their dirty business online. Keith Jarvis, senior security researcher at Sophos' Counter Threat Unit joins Dark Reading's Alex Culafi for a conversation you don't want to miss.
0
'ZipLine' Phishers Flip Script as Victims Email First
Thứ Tư, 27 tháng 8, 2025
Việt Nam Hacker
"ZipLine" appears to be a sophisticated and carefully planned campaign that has already affected dozens of small, medium, and large organizations across multiple industry sectors.
0
China Hijacks Captive Portals to Spy on Asian Diplomats
Việt Nam Hacker
The Mustang Panda APT is hijacking Google Chrome browsers when they attempt to connect to new networks and redirecting them to phishing sites.
0
Google: Salesforce Attacks Stemmed From Third-Party App
Việt Nam Hacker
A group tracked as UNC6395 engaged in "widespread data theft" via compromised OAuth tokens from a third-party app called Salesloft Drift.
0
Malicious Scanning Waves Slam Remote Desktop Services
Thứ Ba, 26 tháng 8, 2025
Việt Nam Hacker
Researchers say the huge spike of coordinated scanning for Microsoft RDP services could indicate the existence of a new, as-yet-undisclosed vulnerability.
0
Data I/O Becomes Latest Ransomware Attack Victim
Việt Nam Hacker
The "incident" led to outages affecting a variety of the tech company's operations, though the full scope of the breach is unknown.
0
Hook Android Trojan Now Delivers Ransomware-Style Attacks
Việt Nam Hacker
New features to take over smartphones and monitor user activity demonstrate the continued evolution of the malware, which is now being spread on GitHub.
0
Hackers Lay In Wait, Then Knocked Out Iran Ship Comms
Thứ Hai, 25 tháng 8, 2025
Việt Nam Hacker
Lab-Dookhtegen claims major attack on more than 60 cargo ships and oil tankers belonging to two Iranian companies on US sanctions list.
0
ClickFix Attack Tricks AI Summaries Into Pushing Malware
Việt Nam Hacker
Because instructions appear to come from AI-generated content summaries and not an external source, the victim is more likely to follow them without suspicion.
0
Fast-Spreading, Complex Phishing Campaign Installs RATs
Việt Nam Hacker
Attackers not only steal credentials but also can maintain long-term, persistent access to corporate networks through the global campaign.
0
Securing the Cloud in an Age of Escalating Cyber Threats
Việt Nam Hacker
As threats intensify and cloud adoption expands, organizations must leave outdated security models behind.
0
Silk Typhoon Attacks North American Orgs in the Cloud
Thứ Sáu, 22 tháng 8, 2025
Việt Nam Hacker
A Chinese APT is going where most APTs don't: deep into the cloud, compromising supply chains and deploying uncommon malware.
0
Apple Intelligence Is Picking Up More User Data Than Expected, Researcher Finds
Việt Nam Hacker
Music tastes, location information, even encrypted messages — Apple's servers are gathering a "surprising" amount of personal data through Apple Intelligence, Lumia Security's Yoav Magid warns in his new analysis.
0
Interpol Arrests Over 1K Cybercriminals in 'Operation Serengeti 2.0'
Việt Nam Hacker
The operation disrupted countless scams, and authorities seized a significant amount of evidence and recovered nearly $100 million in lost funds.
0
Why Video Game Anti-Cheat Systems Are a Cybersecurity Goldmine
Thứ Năm, 21 tháng 8, 2025
Việt Nam Hacker
Sam Collins and Marius Muench of the University of Birmingham, UK, join the Black Hat USA 2025 News Desk to explain how anti-cheat systems in video games provide valuable lessons on defending against threat actors' techniques and strategies.
0
Hackers Abuse VPS Infrastructure for Stealth, Speed
Việt Nam Hacker
New research highlights how threat actors abuse legitimate virtual private server offerings in order to spin up infrastructure cheaply, quietly, and fast.
0
Tree of AST: A Bug-Hunting Framework Powered by LLMs
Việt Nam Hacker
Teenaged security researchers Sasha Zyuzin and Ruikai Peng discuss how their new vulnerability discovery framework leverages LLMs to address limitations of the past.
0
FBI, Cisco Warn of Russian Attacks on 7-Year-Old Flaw
Thứ Tư, 20 tháng 8, 2025
Việt Nam Hacker
In the past year, "Static Tundra," aka "Energetic Bear," has breached thousands of end-of-life Cisco devices unpatched against a 2018 flaw, in a campaign targeting enterprises and critical infrastructure.
0
Hacker Finds Flaws in McDonald’s Staff, Partner Hubs
Việt Nam Hacker
Exposure of APIs, sensitive data, and corporate documents are just some of the security issues that the purveyor of Big Macs was cooking up.
0
'RingReaper' Sneaks Right Past Linux EDRs
Thứ Ba, 19 tháng 8, 2025
Việt Nam Hacker
The highly sophisticated post-compromise tool abuses the Linux kernel's io_uring interface to remain hidden from endpoint detection and response systems.
0
AI Agents Access Everything, Fall to Zero-Click Exploit
Việt Nam Hacker
Zenity CTO Michael Bargury joins the Black Hat USA 2025 News Desk to discuss research on a dangerous exploit, how generative AI technology has "grown arms and legs" —and what that means for cyber risk.
0
Millions Allegedly Affected in Allianz Insurance Breach
Việt Nam Hacker
Have I Been Pwned claims that the compromised data includes physical addresses, dates of birth, phone numbers, and more, for life insurance customers.
0
PipeMagic Backdoor Resurfaces as Part of Play Ransomware Attack Chain
Việt Nam Hacker
Attackers are wielding the sophisticated modular malware while exploiting CVE-2025-29824, a previously zero-day flaw in Windows Common Log File System (CLFS) that allows attackers to gain system-level privileges on compromised systems.
0
'DripDropper' Hackers Patch Their Own Exploit
Việt Nam Hacker
An attacker is breaking into Linux systems via a widely abused 2-year-old vulnerability in Apache ActiveMQ, installing malware and then patching the flaw.
0
Secure AI Use Without the Blind Spots
Việt Nam Hacker
0
Noodlophile Stealer Hides Behind Bogus Copyright Complaints
Thứ Hai, 18 tháng 8, 2025
Việt Nam Hacker
Noodlophile is targeting enterprises in spear-phishing attacks using copyright claims as phishing lures.
0
Workday Breach Likely Linked to ShinyHunters Salesforce Attacks
Việt Nam Hacker
The HR giant said hackers mounted a socially engineered cyberattack on its third-party CRM system, but did not gain access to customer information; only 'commonly available' business contact info was exposed.
0
Internet-wide Vulnerability Enables Giant DDoS Attacks
Việt Nam Hacker
A good chunk of all websites today have been affected by the biggest DDoS risk on the Web since 2023.
0
Defending Against Cloud Threats Across Multicloud Environments
Việt Nam Hacker
The vast majority of companies are using more than one cloud platform, yet struggle to establish and monitor security across different environments giving attackers an opening.
0
New Quantum-Safe Alliance Aims to Accelerate PQC Implementation
Việt Nam Hacker
The new Quantum-Safe 360 Alliance will provide road maps, technology, and services to help organizations navigate the post-quantum cryptography transition before the 2030 deadline.
0
New Crypto24 Ransomware Attacks Bypass EDR
Thứ Sáu, 15 tháng 8, 2025
Việt Nam Hacker
While several cybercrime groups have embraced "EDR killers," researchers say the deep knowledge and technical skills demonstrated by Crypto24 signify a dangerous escalation.
0
Colt Telecommunications Struggles in Wake of Cyber Incident
Việt Nam Hacker
The UK telco said it temporarily took some systems offline as a "protective" measure in its investigation.
0
How Maclaren Racing Gets From the Browser to the Track
Thứ Năm, 14 tháng 8, 2025
Việt Nam Hacker
In a conversation with Dark Reading's Terry Sweeney, Dr. Lisa Jarman from McLaren Racing says cutting-edge innovation must coexist with rigorous security protocols.
0
Cybersecurity Spending Slows & Security Teams Shrink
Việt Nam Hacker
Security budgets are lowest in healthcare, professional and business services, retail, and hospitality, but budget growth remained above 5% in financial services, insurance, and tech.
0
Google Chrome Enterprise: Keeping Businesses Safe From Threats on the Web
Việt Nam Hacker
Dark Reading's Terry Sweeney and Google Cloud Security's Jason Kemmerer discuss how organizations can secure the modern workplace with zero trust browser protection for remote and hybrid teams.
0
Whispers of XZ Utils Backdoor Live on in Old Docker Images
Thứ Tư, 13 tháng 8, 2025
Việt Nam Hacker
Developers maintaining the images made the "intentional choice" to leave the artifacts available as "a historical curiosity," given the improbability they'd be exploited.
0
How an AI-Based 'Pen Tester' Became a Top Bug Hunter on HackerOne
Việt Nam Hacker
AI researcher explains how an automated penetration-testing tool became the first non-human member on HackerOne to reach the top of the platform's US leaderboard.
0
Patch Now: Attackers Target OT Networks via Critical RCE Flaw
Việt Nam Hacker
Researchers observed exploitation attempts against a vulnerability with a CVSS score of 10 in a popular Erlang-based platform for critical infrastructure and OT development.
0
What the LockBit 4.0 Leak Reveals About RaaS Groups
Việt Nam Hacker
The leak serves as a wake-up call: Being prepared is the cornerstone of a successful defense, and those who don't prepare are going to face uncertainty caused by the lack of attackers' accountability.
0
China Questions Security of AI Chips From Nvidia, AMD
Thứ Ba, 12 tháng 8, 2025
Việt Nam Hacker
The US banned the sale of AI chips to China and then backed off. Now, Chinese sources are calling on NVIDIA to prove its AI chips have no backdoors.
0
Elevation-of-Privilege Vulns Dominate Microsoft's Patch Tuesday
Việt Nam Hacker
The company's August security update consisted of patches for 111 unique Common Vulnerabilities and Exposures (CVEs).
0
Black Hat NOC Expands AI Implementation Across Security Operations
Việt Nam Hacker
Corelight's James Pope gave Dark Reading an inside look at this year's Black Hat Network Operations Center, detailing security challenges and rising trends — many related to increased AI use.
0
BlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement
Thứ Hai, 11 tháng 8, 2025
Việt Nam Hacker
A swarm of US agencies joined with international partners to take down servers and domains and seize more than $1 million associated with BlackSuit (Royal) ransomware operations, a group that has been a chronic, persistent threat against critical infrastructure.
0
REvil Actor Accuses Russia of Planning 2021 Kaseya Attack
Việt Nam Hacker
REvil affiliate Yaroslav Vasinskyi, who was convicted last year for his role in the 2021 Kaseya ransomware supply chain attack, said the Russian government was instrumental to the attack's execution.
0
Echo Chamber, Prompts Used to Jailbreak GPT-5 in 24 Hours
Việt Nam Hacker
Researchers paired the jailbreaking technique with storytelling in an attack flow that used no inappropriate language to guide the LLM into producing directions for making a Molotov cocktail.
0
Utilities, Factories at Risk From Encryption Holes in Industrial Protocol
Việt Nam Hacker
The OPC UA communication protocol is widely used in industrial settings, but despite its complex cryptography, the open source protocol appears to be vulnerable in a number of different ways.
0
Will Secure AI Be the Hottest Career Path in Cybersecurity?
Việt Nam Hacker
Securing AI systems represents cybersecurity's next frontier, creating specialized career paths as organizations grapple with novel vulnerabilities, regulatory requirements, and cross-functional demands.
0
860K Compromised in Columbia University Data Breach
Thứ Sáu, 8 tháng 8, 2025
Việt Nam Hacker
While no data has yet to be misused, the university doesn't rule out the possibility of that occurring in the future, prompting it to warn affected individuals to remain vigilant in the wake of the breach.
0
BigID Launches Shadow AI Discovery to Uncover Rogue Models and Risky AI Data
Việt Nam Hacker
0
Ransomware Attacks Fall by Almost Half in Q2
Việt Nam Hacker
0
Privilege Escalation Issue in Amazon ECS Leads to IAM Hijacking
Thứ Năm, 7 tháng 8, 2025
Việt Nam Hacker
A software developer discovered a way to abuse an undocumented protocol in Amazon's Elastic Container Service to escalate privileges, cross boundaries and gain access to other cloud resources.
0
Citizen Lab Founder Flags Rise of US Authoritarianism
Việt Nam Hacker
Citizen Lab director and founder Ron Deibert explained how civil society is locked in "vicious cycle," and human rights are being abused as a result, covering Israeli spyware, the Khashoggi killing, and an erosion of democratic norms in the US.
0
Payback: 'ShinyHunters' Clocks Google via Salesforce
Việt Nam Hacker
In 2024, it was Snowflake. In 2025, it's Salesforce. ShinyHunters is back, with low-tech hacks that nonetheless manage to bring down international megaliths like Google, Cisco, and Adidas.
0
Critical Zero-Day Bugs Crack Open CyberArk, HashiCorp Password Vaults
Thứ Tư, 6 tháng 8, 2025
Việt Nam Hacker
Secrets managers hold all the keys to an enterprise's kingdom. Two popular ones had longstanding, critical, unauthenticated RCE vulnerabilities.
0
'ReVault' Security Flaws Impact Millions of Dell Laptops
Việt Nam Hacker
The now-patched vulnerabilities exist at the firmware level and enable deep persistence on compromised systems.
0
Google Gemini AI Bot Hijacks Smart Homes, Turns Off the Lights
Việt Nam Hacker
Using invisible prompts, the attacks demonstrate a physical risk that could soon become reality as the world increasingly becomes more interconnected with artificial intelligence.
0
Pandora Confirms Third-Party Data Breach, Warns of Phishing Attempts
Thứ Ba, 5 tháng 8, 2025
Việt Nam Hacker
0
Cisco User Data Stolen in Vishing Attack
Việt Nam Hacker
The networking giant said this week that an employee suffered a voice phishing attack that resulted in the compromise of select user data, including email addresses and phone numbers.
0
Google Chrome Enterprise: More Than an Access Point to the Web
Việt Nam Hacker
In a conversation with Dark Reading's Terry Sweeney, Lauren Miskelly from Google explains that Chrome Enterprise is the same Chrome browser that consumers use, but with additional enterprise-grade controls, reporting capabilities, and administrative features.
0
Threat Actors Increasingly Leaning on GenAI Tools
Thứ Hai, 4 tháng 8, 2025
Việt Nam Hacker
From "eCrime" actors to fake IT tech workers, CrowdStrike researchers found that adversaries are using AI to enhance their offensive cyber operations.
0
42% of Developers Using AI Say Their Codebase is Now Mostly AI-Generated
Việt Nam Hacker
0
Akira Ramps Up Assault on SonicWall Firewalls, Suggesting Zero-Day
Việt Nam Hacker
An uptick of ransomware activity by the group in late July that uses the vendor's SSL VPN devices for initial intrusion shows evidence of an as-yet-undisclosed flaw under exploitation.
0
Turning Human Vulnerability Into Organizational Strength
Việt Nam Hacker
Investing in building a human-centric defense involves a combination of adaptive security awareness training, a vigilant and skeptical culture, and the deployment of layered technical controls.
0
What Is the Role of Provable Randomness in Cybersecurity?
Việt Nam Hacker
Random numbers are the cornerstone of cryptographic security — cryptography depends on generating random keys. As organizations adopt quantum-resistant algorithms, it's equally important to examine the randomness underpinning them
0
Dark Reading News Desk Turns 10, Back at Black Hat USA for 2025
Thứ Sáu, 1 tháng 8, 2025
Việt Nam Hacker
Dark Reading's 2025 News Desk marks a decade of Black Hat USA memories. We're making our return with a slate of interviews that help you stay up on the latest research from Black Hat — no trip to Las Vegas required.
0
ISC2 Launches New Security Certificate for AI Expertise
Việt Nam Hacker
ISC2 is launching a 6-course certification program to address the growing demand for AI security expertise. Courses cover topics such as AI fundamentals, ethics, and risks.
0
Gen Z Falls for Scams 2x More Than Older Generations
Thứ Năm, 31 tháng 7, 2025
Việt Nam Hacker
Forget gullible old people — Gen Z is the most at-risk age group on the Web. Older folks might want to ignore it, but employers are likely to feel the brunt.
0
DragonForce Ransom Cartel Profits Off Rivals' Demise
Việt Nam Hacker
The fall of RansomHub led to a major consolidation of the ransomware ecosystem last quarter, which was a boon for the DragonForce and Qilin gangs.
0
SafePay Claims Ingram Micro Breach, Sets Ransom Deadline
Việt Nam Hacker
The ransomware gang claims to have stolen 3.5TB of data, and told the technology distributor to pay up or suffer a data breach.
0
3 Things CFOs Need to Know About Mitigating Threats
Việt Nam Hacker
To reposition cybersecurity as a strategic, business-critical investment, CFOs and CISOs play a critical role in articulating the significant ROI that robust security measures can deliver.
0
Inside the FBI's Strategy for Prosecuting Ransomware
Việt Nam Hacker
The US government is throwing the book at even mid-level cybercriminals. Is it just, and is it working?
0
Koreans Hacked, Blackmailed by 250+ Fake Mobile Apps
Thứ Tư, 30 tháng 7, 2025
Việt Nam Hacker
A swath of copycat Korean apps are hiding spyware, occasionally leading to highly personal, disturbing extortions.
0
Silk Typhoon Linked to Powerful Offensive Tools, PRC-Backed Companies
Việt Nam Hacker
An unsealed indictment associated with the Chinese threat group shows its members worked for companies closely aligned with the PRC as part of a larger contractor ecosystem.
0
The CrowdStrike Outage Was Bad, but It Could Have Been Worse
Việt Nam Hacker
A year after the largest outage in IT history, organizations need to make an active effort to diversify their technology and software vendors and create a more resilient cyber ecosystem moving forward.
0
Attackers Can Use Browser Extensions to Inject AI Prompts
Việt Nam Hacker
A proof-of-concept attack shows how threat actors can use a poisoned browser extension to inject malicious prompts into a generative AI tool.
0
African Orgs Fall to Mass Microsoft SharePoint Exploits
Việt Nam Hacker
The National Treasury of South Africa is among the half-dozen known victims in South Africa — along with other nations — of the mass compromise of on-premises Microsoft SharePoint servers.
0
Nimble 'Gunra' Ransomware Evolves With Linux Variant
Thứ Ba, 29 tháng 7, 2025
Việt Nam Hacker
The emerging cybercriminal gang, which initially targeted Microsoft Windows systems, is looking to go cross-platform using sophisticated, multithread encryption.
0
New Risk Index Helps Organizations Tackle Cloud Security Chaos
Việt Nam Hacker
Enterprises can use the IaC Risk Index to identify vulnerable cloud resources in their infrastructure-as-code environment which are not managed or governed.
0
Insurance Giant Allianz Life Grapples With Breach Affecting 'Majority' of Customers
Thứ Hai, 28 tháng 7, 2025
Việt Nam Hacker
The company has yet to report an exact number of how many individuals were impacted by the breach and plans to start the notification process around Aug. 1.
0
Chaos Ransomware Rises as BlackSuit Gang Falls
Việt Nam Hacker
Researchers detailed a newer double-extortion ransomware group made up of former members of BlackSuit, which was recently disrupted by international law enforcement.
0
Sophisticated Shuyal Stealer Targets 19 Browsers, Demonstrates Advanced Evasion
Việt Nam Hacker
A new infostealing malware making the rounds can exfiltrate credentials and other system data even from browsing software considered more privacy-focused than mainstream options.
0
How to Spot Malicious AI Agents Before They Strike
Việt Nam Hacker
The rise of agentic AI means the battle of the machines is just beginning. To win, we'll need our own agents — human and machine — working together.
0
Cyber Career Opportunities: Weighing Certifications vs. Degrees
Thứ Sáu, 25 tháng 7, 2025
Việt Nam Hacker
Longtime CISO Melina Scotto joins Dark Reading to discuss career advice gleaned from her 30 years in the cyber industry.
0
'Fire Ant' Cyber Spies Compromise Siloed VMware Systems
Việt Nam Hacker
Suspected China-nexus threat actors targeted virtual environments and used several tools and techniques to bypass security barriers and reach isolated portions of victims' networks.
0
AI-Generated Linux Miner 'Koske' Beats Human Malware
Việt Nam Hacker
AI malware is becoming less of a gimmick, with features that meet or exceed what traditional human-developed malware typically can do.
0
North Korea's IT Worker Rampage Continues Amid DoJ Action
Việt Nam Hacker
Arrests and indictments keep coming, but the North Korean fake IT worker scheme is only snowballing, and businesses can't afford to assume their applicant-screening processes are up to the task of weeding the imposters out.
0
The Young and the Restless: Young Cybercriminals Raise Concerns
Việt Nam Hacker
National governments warn that many hacker groups attract young people through a sense of community, fame, or the promise of money and the perception of a lack of risk of prosecution.
0
Can Security Culture Be Taught? AWS Says Yes
Việt Nam Hacker
Newly appointed Amazon Web Services CISO Amy Herzog believes security culture goes beyond frameworks and executive structures. Having the right philosophy throughout the organization is key.
0
Ransomware Actors Pile on 'ToolShell' SharePoint Bugs
Thứ Năm, 24 tháng 7, 2025
Việt Nam Hacker
Storm-2603, a China-based threat actor, is targeting SharePoint customers in an ongoing ransomware campaign.
0
Department of Education Site Mimicked in Phishing Scheme
Thứ Tư, 23 tháng 7, 2025
Việt Nam Hacker
An ongoing phishing campaign is using fake versions of the department's G5 grant portal, taking advantage of political turmoil associated with the DoE's 1,400 layoffs.
0
US Nuclear Agency Hacked in Microsoft SharePoint Frenzy
Việt Nam Hacker
Threat actors are piling on the zero-day vulnerabilities in SharePoint, including at least three Chinese nation-state cyberespionage groups.
0
Microsoft Integrates Data Lake With Sentinel SIEM
Việt Nam Hacker
Microsoft Sentinel Data Lake aims to provide inexpensive storage for large volumes of telemetry, while threat intelligence will be included with Defender XDR at no extra cost.
0
CISO Conversations: How IT and OT Security Worlds Are Converging
Việt Nam Hacker
Dark Reading's Kelly Jackson Higgins interviews Carmine Valente, Deputy CISO at Con Edison, about his role at the New York-based electric utility and the state of IT and OT security. Valente highlights current threats like ransomware and supply chain attacks, as well as the impact of AI on both defense and threats.
0
China Introduces National Cyber ID Amid Privacy Concerns
Thứ Ba, 22 tháng 7, 2025
Việt Nam Hacker
China officially rolled out a voluntary Internet identity system to protect citizens' online identities and personal information, but critics worry about privacy and surveillance.
0
3 China Nation-State Actors Target SharePoint Bugs
Việt Nam Hacker
Hackers and cybercrime groups are part of a virtual feeding frenzy, after Microsoft's recent disclosure of new vulnerabilities in on-premises editions of SharePoint Server.
0
Human Digital Twins Could Give Attackers a Dangerous Advantage
Việt Nam Hacker
While this emerging technology offers many benefits, digital twins also have several drawbacks, as these convincing impersonations can be used in social engineering attacks.
0
China-Backed APT41 Cyberattack Surfaces in Africa
Việt Nam Hacker
Up to now, the prolific China-sponsored cyber-espionage group has been mostly absent from the region, but a sophisticated and highly targeted attack on an African IT company shows Beijing is branching out.
0
Malicious Implants Are Coming to AI Components, Applications
Thứ Hai, 21 tháng 7, 2025
Việt Nam Hacker
A red teamer is publishing research next month about how weaknesses in modern security products lay the groundwork for stealthy implants in AI-powered applications.
0
Europol Sting Leaves Russian Cybercrime's 'NoName057(16)' Group Fractured
Việt Nam Hacker
National authorities have issued seven arrest warrants in total relating to the cybercrime collective known as NoName057(16), which recruits followers to carry out DDoS attacks on perceived enemies of Russia.
0
Containment as a Core Security Strategy
Việt Nam Hacker
We cannot keep reacting to vulnerabilities as they emerge. We must assume the presence of unknown threats and reduce the blast radius that they can affect.
0
'PoisonSeed' Attacker Skates Around FIDO Keys
Thứ Sáu, 18 tháng 7, 2025
Việt Nam Hacker
Researchers discovered a novel phishing attack that serves the victim a QR code as part of supposed multifactor authentication (MFA), in order to get around FIDO-based protections.
0
Printer Security Gaps: A Broad, Leafy Avenue to Compromise
Thứ Năm, 17 tháng 7, 2025
Việt Nam Hacker
Security teams aren't patching firmware promptly, no one's vetting the endpoints before purchase, and visibility into potential dangers is limited — despite more and more cyberattackers targeting printers as a matter of course.
0
Armenian Extradited to US Over Ryuk Ransomware
Việt Nam Hacker
The suspect faces three charges for his alleged crimes that could earn him up to five years in federal prison, and a heap of fines.
0
Why Cybersecurity Still Matters for America's Schools
Việt Nam Hacker
Cyberattacks on educational institutions are growing. But with budget constraints and funding shortfalls, leadership teams are questioning whether — and how — they can keep their institutions safe.
0
ISC2 Finds Orgs Are Increasingly Leaning on AI
Thứ Tư, 16 tháng 7, 2025
Việt Nam Hacker
While many organizations are eagerly integrating AI into their workflows and cybersecurity practices, some remain undecided and even concerned about potential drawbacks of AI deployment.
0
Women Who 'Hacked the Status Quo' Aim to Inspire Cybersecurity Careers
Việt Nam Hacker
A group of female cybersecurity pioneers will share what they've learned about navigating a field dominated by men, in order to help other women empower themselves and pursue successful cybersecurity careers.
0
AI Is Reshaping How Attorneys Practice Law
Thứ Ba, 15 tháng 7, 2025
Việt Nam Hacker
Experts recommend enhanced AI literacy, training around the ethics of using AI, and verification protocols to maintain credibility in an increasingly AI-influenced courtroom.
0
AsyncRAT Spawns Concerning Labyrinth of Forks
Việt Nam Hacker
Since surfacing on GitHub in 2019, AsyncRAT has become a poster child for how open source malware can democratize cybercrime, with a mazelike footprint of variants available across the spectrum of functionality.
0
Attackers Abuse AWS Cloud to Target Southeast Asian Governments
Việt Nam Hacker
The intelligence-gathering cyber campaign introduces the novel HazyBeacon backdoor and uses legitimate cloud communication channels for command-and-control (C2) and exfiltration to hide its malicious activities.
0
MITRE Launches AADAPT Framework for Financial Systems
Việt Nam Hacker
The new framework is modeled after and meant to complement the MITRE ATT&CK framework, and it is aimed at detecting and responding to cyberattacks on cryptocurrency assets and other financial targets.
0
Web-Inject Campaign Debuts Fresh Interlock RAT Variant
Thứ Hai, 14 tháng 7, 2025
Việt Nam Hacker
A cyber-threat campaign is using legitimate websites to inject victims with remote access Trojans belonging to the Interlock ransomware group, in order to gain control of devices.
0
Military Veterans May Be What Cybersecurity Is Looking For
Việt Nam Hacker
As the field struggles with a shortage, programs that aim to provide veterans with the technical skills needed to succeed in cybersecurity may be the solution for everyone.
0
Google Gemini AI Bug Allows Invisible, Malicious Prompts
Việt Nam Hacker
A prompt-injection vulnerability in the AI assistant allows attackers to create messages that appear to be legitimate Google Security alerts but instead can be used to target users across various Google products with vishing and phishing.
0
The Dark Side of Global Power Shifts & Demographic Decline
Việt Nam Hacker
As global power realigns and economies falter, the rise in cybercrime is no longer hypothetical — it's inevitable.
0
350M Cars, 1B Devices Exposed to 1-Click Bluetooth RCE
Thứ Sáu, 11 tháng 7, 2025
Việt Nam Hacker
Mercedes, Skoda, and Volkswagen vehicles, as well as untold industrial, medical, mobile, and consumer devices, may be exposed to a vulnerable Bluetooth implementation called "PerfektBlue."
0
eSIM Bug in Millions of Phones Enables Spying, Takeover
Thứ Năm, 10 tháng 7, 2025
Việt Nam Hacker
eSIMs around the world may be fundamentally vulnerable to physical and network attacks because of a 6-year-old Oracle vulnerability in technology that underlies billions of cards.
0
Ingram Micro Up and Running After Ransomware Attack
Việt Nam Hacker
Customers were the first to notice the disruption on the distributor's website when they couldn't place orders online.
0
4 Arrested in UK Over M&S, Co-op, Harrods Hacks
Việt Nam Hacker
The UK's National Crime Agency arrested four people, who some experts believe are connected to the notorious cybercriminal collective known as Scattered Spider.
0
AirMDR Tackles Security Burdens for SMBs With AI
Việt Nam Hacker
This security startup provides managed detection and response services for small-to-midsized businesses to detect and address modern threats such as ransomware, phishing attacks, and malicious insiders.
0
North American APT Uses Exchange Zero-Day to Attack China
Thứ Tư, 9 tháng 7, 2025
Việt Nam Hacker
Stories about Chinese APTs attacking the US and Canada are plentiful. In a turnabout, researchers found what they believe is a North American entity attacking a Chinese entity, thanks to a mysterious issue in Microsoft Exchange.
0
A NVIDIA Container Bug & Chance to Harden Kubernetes
Việt Nam Hacker
A container escape flaw involving the NVIDIA Container Toolkit could have enabled a threat actor to access AI datasets across tenants.
0
New AI Malware PoC Reliably Evades Microsoft Defender
Việt Nam Hacker
Worried about hackers employing LLMs to write powerful malware? Using targeted reinforcement learning (RL) to train open source models in specific tasks has yielded the capability to do just that.
0
South Korean Government Imposes Penalties on SK Telecom for Breach
Thứ Ba, 8 tháng 7, 2025
Việt Nam Hacker
Following a breach at the country's top mobile provider that exposed 27 million records, the South Korean government imposed a small monetary penalty but stiff regulatory requirements.
0
Malicious Open Source Packages Spike 188% YoY
Việt Nam Hacker
Data exfiltration was the most common malware in Sonatype report, with more than 4,400 packages designed to steal secrets, personally identifiable information, credentials, and API tokens.
0
Suspected Hacker Linked to Silk Typhoon Arrested in Milan
Việt Nam Hacker
The alleged Chinese state-sponsored hacker faces multiple charges, including wire fraud, aggravated identity theft, and unauthorized access to protected computers.
0
DPRK macOS 'NimDoor' Malware Targets Web3, Crypto Platforms
Thứ Hai, 7 tháng 7, 2025
Việt Nam Hacker
Researchers observed North Korean threat actors targeting cryptocurrency and Web3 platforms on Telegram using malicious Zoom meeting requests.
0
Ransomware Attack Triggers Widespread Outage at Ingram Micro
Việt Nam Hacker
The outage began shortly before the July 4 holiday weekend and caused disruptions for customer ordering and other services provided by the IT distributor.
0
'Hunters International' RaaS Group Closes Its Doors
Việt Nam Hacker
The announcement comes just months after security researchers observed that the group was making the transition to rebrand to World Leaks, a data theft outfit.
0
Chrome Store Features Extension Poisoned With Sophisticated Spyware
Việt Nam Hacker
A color picker for Google's browser with more than 100,000 downloads hijacks sessions every time a user navigates to a new webpage and also redirects them to malicious sites.
0
US Treasury Sanctions BPH Provider Aeza Group
Thứ Tư, 2 tháng 7, 2025
Việt Nam Hacker
In the past, the bulletproof group has been affiliated with many well-known ransomware and malware groups, such as BianLian and Lumma Stealer.
0
Russian APT 'Gamaredon' Hits Ukraine With Fierce Phishing
Việt Nam Hacker
A Russian APT known as "Gamaredon" is using spear-phishing attacks and network-drive weaponization to target government entities in Ukraine.
0
ClickFix Spin-off Attack Bypasses Key Browser Safeguards
Việt Nam Hacker
A new threat vector exploits how modern browsers save HTML files, bypassing Mark of the Web and giving attackers another social-engineering attack for delivering malware.
0
1 Year Later: Lessons Learned From the CrowdStrike Outage
Việt Nam Hacker
The ever-growing volume of vulnerabilities and threats requires organizations to remain resilient and anti-fragile — that is, to be able to proactively respond to issues and continuously improve.
0
Scope, Scale of Spurious North Korean IT Workers Emerges
Thứ Ba, 1 tháng 7, 2025
Việt Nam Hacker
Microsoft warns thousands of North Korean workers have infiltrated tech, manufacturing, and transportation sectors to steal money and data.
0
We've All Been Wrong: Phishing Training Doesn't Work
Việt Nam Hacker
Teaching employees to detect malicious emails isn't really having an impact. What other options do organizations have?
0
DoJ Disrupts North Korean IT Worker Scheme Across Multiple US States
Việt Nam Hacker
The US also conducted searches of 29 "laptop farms" across 16 states and seized 29 financial accounts used to launder funds.
0
Scattered Spider Hacking Spree Continues With Airline Sector Attacks
Thứ Hai, 30 tháng 6, 2025
Việt Nam Hacker
0
Chinese Company Hikvision Banned By Canadian Government
Việt Nam Hacker
Though the company's video surveillance products will be prohibited for government use, individuals and private businesses can still buy the vendor's products.
0
Airoha Chip Vulns Put Sony, Bose Earbuds & Headphones at Risk
Việt Nam Hacker
The vulnerabilities, which have yet to be published, could allow a threat actor to hijack not only Bluetooth earbuds and headphones but also the devices connected to them.
0
AI-Themed SEO Poisoning Attacks Spread Info, Crypto Stealers
Việt Nam Hacker
Malicious websites designed to rank high in Google search results for ChatGPT and Luma AI deliver the Lumma and Vidar infostealers and other malware.
0
Why Cybersecurity Should Come Before AI in Schools
Việt Nam Hacker
The sooner we integrate cybersecurity basics into school curriculum, the stronger and more resilient our children — and their futures — will be.
0
Top Apple, Google VPN Apps May Help China Spy on Users
Thứ Sáu, 27 tháng 6, 2025
Việt Nam Hacker
Apple and Google espouse strong values about data privacy, but they allow programs from a Big Brother state to thrive on their app stores, researchers allege.
0
'CitrixBleed 2' Shows Signs of Active Exploitation
Việt Nam Hacker
If exploited, the critical vulnerability allows attackers to maintain access for longer periods of time than the original CitrixBleed flaw, all while remaining undetected.
0
Scattered Spider Taps CFO Credentials in 'Scorched Earth' Attack
Việt Nam Hacker
In a recent intrusion, the notorious cybercriminal collective accessed CyberArk vaults and obtained more 1,400 secrets, subverted Azure, VMware, and Snowflake environments, and for the first known time, actively fought back against incident response teams.
0
Vulnerability Debt: How Do You Put a Price on What to Fix?
Việt Nam Hacker
Putting a vulnerability debt figure together involves work, but having vulnerability debt figures lets you measure real-world values against your overall security posture.
0
US Falling Behind China in Exploit Production
Việt Nam Hacker
Cyber operations have become critical to national security, but the United States has fallen behind in one significant area — exploit production — while China has built up a significant lead.
0
'Cyber Fattah' Hacktivist Group Leaks Saudi Games Data
Thứ Năm, 26 tháng 6, 2025
Việt Nam Hacker
As tensions in the Middle East rise, hacktivist groups are coming out of the woodwork with their own agendas, leading to notable shifts in the hacktivist threat landscape.
0
'IntelBroker' Suspect Arrested, Charged in High-Profile Breaches
Việt Nam Hacker
A British national arrested earlier this year in France was charged by the US Department of Justice in connection with a string of major cyberattacks.
0
Charming Kitten APT Tries Spying on Israeli Cybersecurity Experts
Thứ Tư, 25 tháng 6, 2025
Việt Nam Hacker
Israel's cyber pros are having to put theory into practice, as a notorious nation-state APT sponsored by Iran targets them with spear-phishing attacks.
0
And Now Malware That Tells AI to Ignore It?
Việt Nam Hacker
Though rudimentary and largely non-functional, the wryly named "Skynet" binary could be a harbinger of things to come on the malware front.
0
Millions of Brother Printers Hit by Critical, Unpatchable Bug
Việt Nam Hacker
A slew of vulnerabilities, including a critical CVSS 9.8 that enables an attacker to generate the default admin password, affect hundreds of printer, scanner, and label-maker models made by manufacturer Brother.
0
CISA is Shrinking: What Does it Mean for Cyber?
Việt Nam Hacker
Dark Reading Confidential Episode 7: Cyber experts Tom Parker and Jake Williams offer their views on the practical impact of cuts to the US Cybersecurity and Infrastructure Security Agency.
0
Africa Sees Surge in Cybercrime as Law Enforcement Struggles
Thứ Ba, 24 tháng 6, 2025
Việt Nam Hacker
Cybercrime accounts for more than 30% of all reported crime in East Africa and West Africa, with online scams, ransomware, business email compromise, and digital sextortion taking off.
0
Threat Actor Trojanizes Copy of SonicWall NetExtender VPN App
Việt Nam Hacker
A threat actor hacked a version of SonicWall's NetExtender SSL VPN application in an effort to trick users into installing a Trojanized version of the product.
0
China-Nexus 'LapDogs' Network Thrives on Backdoored SOHO Devices
Việt Nam Hacker
The campaign infected devices in the US and Southeast Asia to build an operational relay box (ORB) network for use as an extensive cyber-espionage infrastructure.
0
Steel Giant Nucor Confirms Data Stolen in Cyberattack
Việt Nam Hacker
America's largest steel producer initially disclosed the breach in May and took potentially affected systems offline to investigation the intrusion and contain any malicious activity.
0
Citrix Patches Critical Vulns in NetScaler ADC and Gateway
Thứ Hai, 23 tháng 6, 2025
Việt Nam Hacker
Citrix is recommending its customers upgrade their appliances to mitigate potential exploitation of the vulnerabilities.
0
'Echo Chamber' Attack Blows Past AI Guardrails
Việt Nam Hacker
An AI security researcher has developed a proof of concept that uses subtle, seemingly benign prompts to get GPT and Gemini to generate inappropriate content.
0
DHS Warns of Rise in Cyberattacks in Light of US-Iran Conflict
Việt Nam Hacker
After President's Trump decision to enter the US into the conflict in the Middle East, the Department of Homeland Security expects there to be an uptick in Iranian hacktivists and state-sponsored actors targeting US systems.
0
Attackers Use Docker APIs, Tor Anonymity in Stealthy Crypto Heist
Việt Nam Hacker
The attack is similar to previous campaigns by an actor called Commando Cat to use misconfigured APIs to compromise containers and deploy cryptocurrency miners.
0
A CISO's AI Playbook
Việt Nam Hacker
In a market where security budgets flatten while threats accelerate, improving analyst throughput is fiscal stewardship.
0
AWS Enhances Cloud Security With Better Visibility Features
Thứ Sáu, 20 tháng 6, 2025
Việt Nam Hacker
At this week's re:Inforce 2025 conference, the cloud giant introduced new capabilities to several core security products to provide customers with better visibility and more context on potential threats.
0
Hackers Post Dozens of Malicious Copycat Repos to GitHub
Việt Nam Hacker
As package registries find better ways to combat cyberattacks, threat actors are finding other methods for spreading their malware to developers.
0
How Cyberwarfare Changes the Face of Geopolitical Conflict
Việt Nam Hacker
As geopolitical tensions rise, the use of cyber operations and hacktivists continues to grow, with the current conflict between Israel and Iran showing the new face of cyber-augmented war.
0
Telecom Giant Viasat Is Latest Salt Typhoon Victim
Việt Nam Hacker
The communications company shared the discoveries of its investigation with government partners, but there is little information they can publicly disclose other than that there seems to be no impact to customers.
0
How to Lock Down the No-Code Supply Chain Attack Surface
Việt Nam Hacker
Securing the no-code supply chain isn't just about mitigating risks — it's about enabling the business to innovate with confidence.
0
OpenAI Awarded $200M Contract to Work With DoD
Thứ Tư, 18 tháng 6, 2025
Việt Nam Hacker
OpenAI intends to help streamline the Defense Department's administrative processes using artificial intelligence.
0
New Tool Traps Jitters to Detect Beacons
Việt Nam Hacker
Concerned by rapidly evolving evasion tactics, the new Jitter-Trap tool from Varonis aims to help organizations detect beacons that help attackers establish communication inside a victim network.
0
The Triple Threat of Burnout: Overworked, Unsatisfied, Trapped
Việt Nam Hacker
Many cybersecurity professionals still don't feel comfortable admitting when they need a break. And the impact goes beyond being overworked.
0
GodFather Banking Trojan Debuts Virtualization Tactic
Việt Nam Hacker
The Android malware is targeting Turkish financial institutions, completely taking over legitimate banking and crypto apps by creating an isolated virtualized environment on a device.
0
Serpentine#Cloud Uses Cloudflare Tunnels in Sneak Attacks
Việt Nam Hacker
An unidentified threat actor is using .lnk Windows shortcut files in a series of sophisticated attacks utilizing in-memory code execution and living-off-the-land cyberattack strategies.
0
Indian Car-Sharing Firm Zoomcar Latest to Suffer Breach
Thứ Ba, 17 tháng 6, 2025
Việt Nam Hacker
The company acknowledged that cybercriminals had taken sensitive information on more than 8 million users, including names, phone numbers, car registration numbers, addresses, and emails.
0
'HoldingHands' Acts Like a Pickpocket With Taiwan Orgs
Việt Nam Hacker
Since at least January, the threat actor has been employing multiple malware tools to steal information for potential future attacks against Taiwanese businesses and government agencies.
0
Malicious Chimera Turns Larcenous on Python Package Index
Thứ Hai, 16 tháng 6, 2025
Việt Nam Hacker
Unlike typical data-stealing malware, this attack tool targets data specific to corporate and cloud infrastructures in order to execute supply chain attacks.
0
Anubis Ransomware-as-a-Service Kit Adds Data Wiper
Việt Nam Hacker
The threat of wiping files and servers clean gives Anubis affiliates yet another way to leverage ransomware victims who may be hesitant to pay to get their data back, Trend Micro said.
0
Washington Post Staffer Emails Targeted in Cyber Breach
Việt Nam Hacker
Journalists' Microsoft accounts were breached, which would have given attackers access to emails of staff reporters covering national security, economic policy, and China.
0
'Water Curse' Targets Infosec Pros Via Poisoned GitHub Repositories
Việt Nam Hacker
The emerging threat group attacks the supply chain via weaponized repositories posing as legitimate pen-testing suites and other tools that are poisoned with malware.
0
Security Is Only as Strong as the Weakest Third-Party Link
Việt Nam Hacker
Third-party risks are increasing dramatically, requiring CISOs to evolve from periodic assessments to continuous monitoring and treating partner vulnerabilities as their own to enhance organizational resilience.
0
NIST Outlines Real-World Zero-Trust Examples
Việt Nam Hacker
SP 1800-35 offers 19 examples of how to implement zero-trust architecture (ZTA) using off-the-shelf commercial technologies.
0
CISA Reveals 'Pattern' of Ransomware Attacks Against SimpleHelp RMM
Thứ Sáu, 13 tháng 6, 2025
Việt Nam Hacker
A new Cybersecurity and Infrastructure Security Agency (CISA) advisory warned ransomware actors have been actively exploiting a critical SimpleHelp flaw since January.
0
Cyberattacks on Humanitarian Orgs Jump Worldwide
Việt Nam Hacker
These groups suffered three times the cyberattacks as the year previous, with DDoS attacks dominating and vulnerability scans and SQL injection also more common.
0
New COPPA Rules to Take Effect Over Child Data Privacy Concerns
Thứ Năm, 12 tháng 6, 2025
Việt Nam Hacker
New regulations and compliance standards for the Children's Online Privacy Protection Act reflect how much technology has grown since the Federal Trade Commission last updated it in 2013.
0
Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'
Việt Nam Hacker
Researchers at Aim Security disclosed a Microsoft Copilot vulnerability of critical severity this week that could have enabled sensitive data exfiltration via prompt injection attacks.
0
Hacking the Hackers: When Bad Guys Let Their Guard Down
Việt Nam Hacker
A string of threat-actor OpSec failures have yielded unexpected windfalls for security researchers and defenders.
0
ConnectWise to Rotate Code-Signing Certificates
Thứ Tư, 11 tháng 6, 2025
Việt Nam Hacker
The move is unrelated to a recent nation-state attack the vendor endured but stems from a report by a third-party researcher.
0
Agentic AI Takes Over Gartner's SRM Summit
Việt Nam Hacker
Agentic AI was everywhere at Gartner's Security & Risk Management Summit in Washington, DC, this year, as the AI security product engine chugs ahead at full speed.
0
Google Bug Allowed Brute-Forcing of Any User Phone Number
Việt Nam Hacker
The weakness in Google's password-recovery page, discovered by a researcher called Brutecat, exposed private user contact information to attackers, opening the door to phishing, SIM-swapping, and other attacks.
0
PoC Code Escalates Roundcube Vuln Threat
Thứ Ba, 10 tháng 6, 2025
Việt Nam Hacker
0
GitHub: How Code Provenance Can Prevent Supply Chain Attacks
Việt Nam Hacker
Through artifact attestation and the SLSA framework, GitHub's Jennifer Schelkopf argues that at least some supply chain attacks can be stopped in their tracks.
0
United Natural Food's Operations Limp Through Cybersecurity Incident
Việt Nam Hacker
It's unclear what kind of cyberattack occurred, but UNFI proactively took certain systems offline, which has disrupted the company's operations.
0
Gartner: How Security Teams Can Turn Hype Into Opportunity
Thứ Hai, 9 tháng 6, 2025
Việt Nam Hacker
During the opening keynote at Gartner Security & Risk Management Summit 2025, analysts weighed in on how CISOs and security teams can use security fervor around AI and other tech to the betterment of their security posture.
0
SIEMs Missing the Mark on MITRE ATT&CK Techniques
Việt Nam Hacker
CardinalOps' report shows that organizations are struggling to keep up with the evolution of the latest threats while a significant number of detection rules remain non-functional.
0
China-Backed Hackers Target SentinelOne in 'PurpleHaze' Attack Spree
Việt Nam Hacker
Known threat groups APT15 and UNC5174 unleashed attacks against SentinelOne and more than 70 other high-value targets, as part of ongoing cyber-espionage and other malicious activity involving ShadowPad malware.
0
Docuseries Explores Mental, Physical Hardships of CISOs
Thứ Sáu, 6 tháng 6, 2025
Việt Nam Hacker
During "CISO: The Worst Job I Ever Wanted," several chief information security officers reveal how difficult it is to be in a role that, despite being around for decades, remains undefined.
0
BADBOX 2.0 Targets Home Networks in Botnet Campaign, FBI Warns
Việt Nam Hacker
Though the operation was partially disrupted earlier this year, the botnet remains active and continues to target connected Android devices.
0
'PathWiper' Attack Hits Critical Infrastructure In Ukraine
Thứ Năm, 5 tháng 6, 2025
Việt Nam Hacker
Cisco Talos researchers observed the new wiper malware in a destructive attack against an unnamed critical infrastructure organization.
0
Cisco Warns of Credential Vuln on AWS, Azure, Oracle Cloud
Việt Nam Hacker
The vulnerability, with a 9.9 CVSS score on a 10-point scale, results in different Cisco ISE deployments all sharing the same credentials as long as the software release and cloud platform remain the same.
0
Backdoored Malware Reels in Newbie Cybercriminals
Việt Nam Hacker
Sophos researchers found this operation has similarities or connections to many other campaigns targeting GitHub repositories dating back to August 2022.
0
35K Solar Devices Vulnerable to Potential Hijacking
Thứ Tư, 4 tháng 6, 2025
Việt Nam Hacker
A little more than three-quarters of these exposed devices are located in Europe, followed by Asia, with 17%.
0
Vishing Crew Targets Salesforce Data
Việt Nam Hacker
A group Google is tracking as UNC6040 has been tricking users into installing a malicious version of a Salesforce app to gain access to and steal data from the platform.
0
How Neuroscience Can Help Us Battle 'Alert Fatigue'
Việt Nam Hacker
By understanding the neurological realities of human attention, organizations can build more sustainable security operations that protect not only their digital assets but also the well-being of those who defend them.
0
Researchers Bypass Deepfake Detection With Replay Attacks
Việt Nam Hacker
An international group of researchers found that simply rerecording deepfake audio with natural acoustics in the background allows it to bypass detection models at a higher-than-expected rate.
0
Chrome Drops Trust for Chunghwa, Netlock Certificates
Thứ Ba, 3 tháng 6, 2025
Việt Nam Hacker
Digital certificates authorized by the authorities will no longer have trust by default in the browser starting in August, over what Google said is a loss of integrity in actions by the respective companies.
0
LummaC2 Fractures as Acreed Malware Becomes Top Dog
Việt Nam Hacker
LummaC2 formerly accounted for almost 92% of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.
0
LummaC2 Fractures as Acreed Malware Becomes Top Dog
Việt Nam Hacker
LummaC2 formerly accounted for almost 92% of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.
0
Beyond the Broken Wall: Why the Security Perimeter Is Not Enough
Thứ Hai, 2 tháng 6, 2025
Việt Nam Hacker
Organizations need to abandon perimeter-based security for data-centric protection strategies in today's distributed IT environments.
0
EMR-ISAC Shuts Down: What Happens Now?
Việt Nam Hacker
The Emergency Management and Response - Information Sharing and Analysis Center provided essential information to the emergency services sector on physical and cyber threats and its closure leaves an information vacuum for these organizations.
0
Exploitation Risk Grows for Critical Cisco Bug
Việt Nam Hacker
New details on the Cisco IOS XE vulnerability could help attackers develop a working exploit soon, researchers say.
0
Trickbot, Conti Ransomware Operator Unmasked Amid Huge Ops Leak
Việt Nam Hacker
An anonymous whistleblower has leaked large amounts of data tied to the alleged operator behind Trickbot and Conti ransomware.
0
Critical Bugs Could Spark Takeover of Widely Used Fire Safety OT/ICS Platform
Việt Nam Hacker
The unpatched security vulnerabilities in Consilium Safety's CS5000 Fire Panel could create "serious safety issues" in environments where fire suppression and safety are paramount, according to a CISA advisory.
0
In the AI Race With China, Don't Forget About Security
Việt Nam Hacker
The US needs to establish a clear framework to provide reasonable guardrails to protect its interests — the quicker, the better.
0
'Earth Lamia' Exploits Known SQL, RCE Bugs Across Asia
Thứ Sáu, 30 tháng 5, 2025
Việt Nam Hacker
A "highly active" Chinese threat group is taking proverbial candy from babies, exploiting known bugs in exposed servers to steal data from organizations in sensitive sectors.
0
FBI Warns of Filipino Tech Company Running Sprawling Crypto Scams
Việt Nam Hacker
The US Treasury said cryptocurrency investment schemes like the ones facilitated by Funnull Technology Inc. have cost Americans billions of dollars annually.
0
SentinelOne Reports Services Are Back Online After Global Outage
Thứ Năm, 29 tháng 5, 2025
Việt Nam Hacker
The outage reportedly hit 10 commercial customer consoles for SentinelOne's Singularity platform, including Singularity Endpoint, XDR, Cloud Security, Identity, Data Lake, RemoteOps, and more.
0
Zscaler's Buyout of Red Canary Shows Telemetry's Value
Việt Nam Hacker
Red Canary's MDR portfolio complements Zscaler's purchase last year of Israeli startup Avalor, which automates collection, curation, and enrichment of security data.
0
LexisNexis Informs 360K+ Customers of Third-Party Data Leak
Việt Nam Hacker
While the leak affected customer data, LexisNexis said in a notification letter that its products and systems were not compromised.
0
PumaBot Targets Linux Devices in Latest Botnet Campaign
Việt Nam Hacker
While the botnet may not be completely automated, it uses certain tactics when targeting devices that indicate that it may, at the very least, be semiautomated.
0
CISA Issues SOAR, SIEM Implementation Guidance
Việt Nam Hacker
The Cybersecurity and Infrastructure Security Agency (CISA) and Australian Cyber Security Centre (ACSC) recommend that organizations conduct thorough testing and manage costs, which can be hefty, before implementing the platforms.
0
'Haozi' Gang Sells Turnkey Phishing Tools to Amateurs
Việt Nam Hacker
The phishing operation is using Telegram groups to sell a phishing-as-a-service kit with customer service, a mascot, and infrastructure that requires little technical knowledge to install.
0
Hundreds of Web Apps Have Full Access to OneDrive Files
Thứ Tư, 28 tháng 5, 2025
Việt Nam Hacker
Researchers at Oasis Security say the problem has to do with OneDrive File Picker having overly broad permissions.
0
Implementing Secure by Design Principles for AI
Việt Nam Hacker
Harnessing AI's full transformative potential safely and securely requires more than an incremental enhancement of existing cybersecurity practices. A Secure by Design approach represents the best path forward.
0
MathWorks, Creator of MATLAB, Confirms Ransomware Attack
Thứ Ba, 27 tháng 5, 2025
Việt Nam Hacker
The attack dirsupted MathWorks' systems and online applications, but it remains unclear which ransomware group targeted the software company and whether they stole any data.
0
Danabot Takedown Deals Blow to Russian Cybercrime
Việt Nam Hacker
A multiyear investigation by a public-private partnership has resulted in the seizure of the botnet's US-based infrastructure and indictments for its key players, significantly disrupting a vast cybercriminal enterprise.
0
CVE Uncertainty Underlines Importance of Cyber Resilience
Việt Nam Hacker
Organizations need to broaden their strategy to manage vulnerabilities more effectively and strengthen network cyber resilience.
0
Russian Threat Actor TAG-110 Goes Phishing in Tajikistan
Thứ Năm, 22 tháng 5, 2025
Việt Nam Hacker
While Ukraine remains Russia's major target for cyberattacks, TAG-110 is part of a strategy to preserve "a post-Soviet sphere of influence" by embedding itself in other countries' infrastructures.
0
3am Ransomware Adopts Email Bombing, Vishing Combo Attack
Việt Nam Hacker
The emerging threat group is the latest to adopt the combo attack tactic, which Black Basta and other groups already are using to gain initial access for ransomware deployment.
0
Blurring Lines Between Scattered Spider and Russian Cybercrime
Việt Nam Hacker
The loosely affiliated hacking group has shifted closer to ransomware gangs, raising questions about Scattered Spider's ties to the Russian cybercrime underground.
0
CISA: Russia's Fancy Bear Targeting Logistics, IT Firms
Việt Nam Hacker
0
Pandas Galore: Chinese Hackers Boost Attacks in Latin America
Thứ Tư, 21 tháng 5, 2025
Việt Nam Hacker
Vixen Panda, Aquatic Panda — both Beijing-sponsored APTs and financially motivated criminal groups continued to pose the biggest threat to organizations in Central and South America last year, says CrowdStrike.
0
Unimicron, Presto Attacks Mark Industrial Ransomware Surge
Việt Nam Hacker
A number of major industrial organizations suffered ransomware attacks last quarter, such as PCB manufacturer Unimicron, appliance maker Presto, and more — a harbinger of a rapidly developing and diversifying threat landscape.
0
Coinbase Breach Compromises Nearly 70K Customers' Information
Việt Nam Hacker
Coinbase asserts that this number is only a small fraction of the number of its verified users, though its still offering a $20 million reward to catch the criminals.
0
Fake Kling AI Malvertisements Lure Victims With False Promises
Thứ Ba, 20 tháng 5, 2025
Việt Nam Hacker
Researchers noted that they found several similar websites, two of which are still operating and require the same kind of behavior on behalf of the victim.
0
Virgin Media 02 Vuln Exposes Call Recipient Location
Việt Nam Hacker
A hacker exploiting the security flaw in the mobile provider's network could have potentially located a call recipient with accuracy of up to 100 square meters.
0
Tenable Adds Third-Party Connectors to Exposure Management Platform
Việt Nam Hacker
TenableOne now pulls in data from AWS, Microsoft, and competitors to provide a holistic security view of the organization's attack surface.
0
Regeneron Pledges Privacy Protection in $256M Bid for 23andMe
Việt Nam Hacker
Regeneron's acquisition of 23andMe raises significant privacy concerns as experts warn about the lack of comprehensive federal regulations governing the transfer of genetic information.
0
Why Rigid Security Programs Keep Failing
Việt Nam Hacker
Organizations that stay ahead of attacks won't be the most compliant ones — they'll be the ones most honest about what actually works.
0
'Operation RoundPress' Targets Ukraine in XSS Webmail Attacks
Thứ Hai, 19 tháng 5, 2025
Việt Nam Hacker
A cyber-espionage campaign is targeting Ukrainian government entities with a series of sophisticated spear-phishing attacks that exploit XSS vulnerabilities.
0
Legal Aid Agency Warns Lawyers, Defendants on Data Breach
Việt Nam Hacker
The online service has since been shut down as the agency grapples with the cyberattack, though it assures the public that those most in need of legal assistance will still be able to access help.
0
CVE Disruption Threatens Foundations of Defensive Security
Việt Nam Hacker
If the Common Vulnerabilities and Exposures system continues to face uncertainty, the repercussions will build slowly, and eventually the cracks will become harder to contain.
Đăng ký:
Nhận xét (Atom)
