A "highly active" Chinese threat group is taking proverbial candy from babies, exploiting known bugs in exposed servers to steal data from organizations in sensitive sectors.
0
'Earth Lamia' Exploits Known SQL, RCE Bugs Across Asia
Thứ Sáu, 30 tháng 5, 2025
Việt Nam Hacker
0
FBI Warns of Filipino Tech Company Running Sprawling Crypto Scams
Việt Nam Hacker
The US Treasury said cryptocurrency investment schemes like the ones facilitated by Funnull Technology Inc. have cost Americans billions of dollars annually.
0
SentinelOne Reports Services Are Back Online After Global Outage
Thứ Năm, 29 tháng 5, 2025
Việt Nam Hacker
The outage reportedly hit 10 commercial customer consoles for SentinelOne's Singularity platform, including Singularity Endpoint, XDR, Cloud Security, Identity, Data Lake, RemoteOps, and more.
0
Zscaler's Buyout of Red Canary Shows Telemetry's Value
Việt Nam Hacker
Red Canary's MDR portfolio complements Zscaler's purchase last year of Israeli startup Avalor, which automates collection, curation, and enrichment of security data.
0
LexisNexis Informs 360K+ Customers of Third-Party Data Leak
Việt Nam Hacker
While the leak affected customer data, LexisNexis said in a notification letter that its products and systems were not compromised.
0
PumaBot Targets Linux Devices in Latest Botnet Campaign
Việt Nam Hacker
While the botnet may not be completely automated, it uses certain tactics when targeting devices that indicate that it may, at the very least, be semiautomated.
0
CISA Issues SOAR, SIEM Implementation Guidance
Việt Nam Hacker
The Cybersecurity and Infrastructure Security Agency (CISA) and Australian Cyber Security Centre (ACSC) recommend that organizations conduct thorough testing and manage costs, which can be hefty, before implementing the platforms.
0
'Haozi' Gang Sells Turnkey Phishing Tools to Amateurs
Việt Nam Hacker
The phishing operation is using Telegram groups to sell a phishing-as-a-service kit with customer service, a mascot, and infrastructure that requires little technical knowledge to install.
0
Hundreds of Web Apps Have Full Access to OneDrive Files
Thứ Tư, 28 tháng 5, 2025
Việt Nam Hacker
Researchers at Oasis Security say the problem has to do with OneDrive File Picker having overly broad permissions.
0
Implementing Secure by Design Principles for AI
Việt Nam Hacker
Harnessing AI's full transformative potential safely and securely requires more than an incremental enhancement of existing cybersecurity practices. A Secure by Design approach represents the best path forward.
0
MathWorks, Creator of MATLAB, Confirms Ransomware Attack
Thứ Ba, 27 tháng 5, 2025
Việt Nam Hacker
The attack dirsupted MathWorks' systems and online applications, but it remains unclear which ransomware group targeted the software company and whether they stole any data.
0
Danabot Takedown Deals Blow to Russian Cybercrime
Việt Nam Hacker
A multiyear investigation by a public-private partnership has resulted in the seizure of the botnet's US-based infrastructure and indictments for its key players, significantly disrupting a vast cybercriminal enterprise.
0
CVE Uncertainty Underlines Importance of Cyber Resilience
Việt Nam Hacker
Organizations need to broaden their strategy to manage vulnerabilities more effectively and strengthen network cyber resilience.
0
Russian Threat Actor TAG-110 Goes Phishing in Tajikistan
Thứ Năm, 22 tháng 5, 2025
Việt Nam Hacker
While Ukraine remains Russia's major target for cyberattacks, TAG-110 is part of a strategy to preserve "a post-Soviet sphere of influence" by embedding itself in other countries' infrastructures.
0
3am Ransomware Adopts Email Bombing, Vishing Combo Attack
Việt Nam Hacker
The emerging threat group is the latest to adopt the combo attack tactic, which Black Basta and other groups already are using to gain initial access for ransomware deployment.
0
Blurring Lines Between Scattered Spider and Russian Cybercrime
Việt Nam Hacker
The loosely affiliated hacking group has shifted closer to ransomware gangs, raising questions about Scattered Spider's ties to the Russian cybercrime underground.
0
CISA: Russia's Fancy Bear Targeting Logistics, IT Firms
Việt Nam Hacker
0
Pandas Galore: Chinese Hackers Boost Attacks in Latin America
Thứ Tư, 21 tháng 5, 2025
Việt Nam Hacker
Vixen Panda, Aquatic Panda — both Beijing-sponsored APTs and financially motivated criminal groups continued to pose the biggest threat to organizations in Central and South America last year, says CrowdStrike.
0
Unimicron, Presto Attacks Mark Industrial Ransomware Surge
Việt Nam Hacker
A number of major industrial organizations suffered ransomware attacks last quarter, such as PCB manufacturer Unimicron, appliance maker Presto, and more — a harbinger of a rapidly developing and diversifying threat landscape.
0
Coinbase Breach Compromises Nearly 70K Customers' Information
Việt Nam Hacker
Coinbase asserts that this number is only a small fraction of the number of its verified users, though its still offering a $20 million reward to catch the criminals.
0
Fake Kling AI Malvertisements Lure Victims With False Promises
Thứ Ba, 20 tháng 5, 2025
Việt Nam Hacker
Researchers noted that they found several similar websites, two of which are still operating and require the same kind of behavior on behalf of the victim.
0
Virgin Media 02 Vuln Exposes Call Recipient Location
Việt Nam Hacker
A hacker exploiting the security flaw in the mobile provider's network could have potentially located a call recipient with accuracy of up to 100 square meters.
0
Tenable Adds Third-Party Connectors to Exposure Management Platform
Việt Nam Hacker
TenableOne now pulls in data from AWS, Microsoft, and competitors to provide a holistic security view of the organization's attack surface.
0
Regeneron Pledges Privacy Protection in $256M Bid for 23andMe
Việt Nam Hacker
Regeneron's acquisition of 23andMe raises significant privacy concerns as experts warn about the lack of comprehensive federal regulations governing the transfer of genetic information.
0
Why Rigid Security Programs Keep Failing
Việt Nam Hacker
Organizations that stay ahead of attacks won't be the most compliant ones — they'll be the ones most honest about what actually works.
0
'Operation RoundPress' Targets Ukraine in XSS Webmail Attacks
Thứ Hai, 19 tháng 5, 2025
Việt Nam Hacker
A cyber-espionage campaign is targeting Ukrainian government entities with a series of sophisticated spear-phishing attacks that exploit XSS vulnerabilities.
0
Legal Aid Agency Warns Lawyers, Defendants on Data Breach
Việt Nam Hacker
The online service has since been shut down as the agency grapples with the cyberattack, though it assures the public that those most in need of legal assistance will still be able to access help.
0
CVE Disruption Threatens Foundations of Defensive Security
Việt Nam Hacker
If the Common Vulnerabilities and Exposures system continues to face uncertainty, the repercussions will build slowly, and eventually the cracks will become harder to contain.
0
Australian Human Rights Commission Leaks Docs in Data Breach
Thứ Sáu, 16 tháng 5, 2025
Việt Nam Hacker
An internal error led to public disclosure of reams of sensitive data that could be co-opted for follow-on cyberattacks.
0
Attacker Specialization Puts Threat Modeling on Defensive
Việt Nam Hacker
Specialization among threat groups poses challenges for defenders, who now must distinguish between different actors responsible for different facets of an attack.
0
Big Steelmaker Halts Operations After Cyber Incident
Thứ Năm, 15 tháng 5, 2025
Việt Nam Hacker
Nucor made it clear its investigation is still in the early stages and didn't specify the nature or scope of the breach, nor who the threat actor might be.
0
International Crime Rings Defraud US Gov't Out of Billions
Việt Nam Hacker
Fraudsters worldwide apply for money from the US government using stolen and forged identities, making off with hundreds of billions of dollars annually.
0
Attackers Target Samsung MagicINFO Server Bug, Patch Now
Việt Nam Hacker
CVE-2025-4632, a patch bypass for a Samsung MagicInfo 9 Server vulnerability disclosed last year, has been exploited by threat actors in the wild.
0
Critical SAP NetWeaver Vuln Faces Barrage of Cyberattacks
Việt Nam Hacker
As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.
0
Using a Calculator to Take Guesswork Out of Measuring Cyber-Risk
Việt Nam Hacker
Organizations face the complex challenge of accurately measuring their cyber-risk across multiple variables. Resilience's risk calculator tool can help organizations measure their cyber-risk based on their own factors so that they can make informed decisions about their security posture.
0
AI Agents May Have a Memory Problem
Thứ Tư, 14 tháng 5, 2025
Việt Nam Hacker
A new study by researchers at Princeton University and Sentient shows it's surprisingly easy to trigger malicious behavior from AI agents by implanting fake "memories" into the data they rely on for making decisions.
0
Ivanti EPMM Zero-Day Flaws Exploited in Chained Attack
Việt Nam Hacker
The security software maker said the vulnerabilities in Endpoint Manager Mobile have been exploited in the wild against "a very limited number of customers" — for now — and stem from open source libraries.
0
Chinese Actor Hit Taiwanese Drone Makers, Supply Chains
Thứ Ba, 13 tháng 5, 2025
Việt Nam Hacker
Tidrone concentrated on military entities and the satellite sector, using their associated service providers and ERP software to infect not just drones but all the entities that are part of their supply chains.
0
What Does EU's Bug Database Mean for Vulnerability Tracking?
Việt Nam Hacker
The EU cyber agency ENISA has launched its vulnerability database, the EUVD; security experts shared their thoughts regarding what this means for CVEs, as well as the larger conversation around how bugs are tracked.
0
CISA Warns of TeleMessage Vuln Despite Low CVSS Score
Việt Nam Hacker
Though the app claims to use end-to-end encryption, hackers have reportedly accessed archived data on the app's servers via a new vulnerability.
0
North Korea's TA406 Targets Ukraine for Intel
Việt Nam Hacker
The threat group's goal is to help Pyongyang assess risk to its troops deployed in Ukraine and to figure out if Moscow might want more.
0
Attackers Lace Fake Generative AI Tools With 'Noodlophile' Malware
Thứ Hai, 12 tháng 5, 2025
Việt Nam Hacker
Threat actors are scamming users by advertising legitimate-looking generative AI websites that, when visited, install credential-stealing malware onto the victim's computer.
0
4 Hackers Arrested After Millions Made in Global Botnet Business
Việt Nam Hacker
The cybercriminals infected older wireless Internet routers with Anyproxy and 5socks malware in order to reconfigure them — all without the users' knowledge.
0
Can Cybersecurity Keep Up In the AI Arms Race?
Việt Nam Hacker
New research shows China is quickly catching up with the US in AI innovation. Experts weigh in on what it means for cyber defenders.
0
Vulnerability Detection Tops Agentic AI at RSAC's Startup Competition
Việt Nam Hacker
Agentic-native startups threaten to reduce the zero-day problem to just a zero-hour issue. Of course, AI agents will accelerate offensive attacks as well.
0
New UK Security Guidelines Aims to Reshape Software Development
Việt Nam Hacker
The voluntary Software Security Code of Practice is the latest initiative to come out of the United Kingdom to boost best practices in application security and software development.
0
After Pahalgam Attack, Hacktivists Unite Under #OpIndia
Thứ Sáu, 9 tháng 5, 2025
Việt Nam Hacker
0
LockBit Ransomware Gang Hacked, Operations Data Leaked
Việt Nam Hacker
Exposed data from LockBit's affiliate panel includes Bitcoin addresses, private chats with victim organizations, and user information such as credentials.
0
Cyber Then & Now: Inside a 2-Decade Industry Evolution
Việt Nam Hacker
On Dark Reading's 19-year anniversary, Editor-in-Chief Kelly Jackson Higgins stops by Informa TechTarget's RSAC 2025 Broadcast Alley studio to discuss how things have changed since the early days of breaking Windows and browsers, lingering challenges, and what's next beyond AI.
0
Commvault: Vulnerability Patch Works as Intended
Việt Nam Hacker
The security researcher who questioned the effectiveness of a patch for recently disclosed bug in Commvault Command Center did not test patched version, the company says.
0
How Security Has Changed the Hacker Marketplace
Việt Nam Hacker
Your ultimate goal shouldn't be security perfection — it should be making exploitation of your organization unprofitable.
0
SonicWall Issues Patch for Exploit Chain in SMA Devices
Thứ Năm, 8 tháng 5, 2025
Việt Nam Hacker
Three vulnerabilities in SMA 100 gateways could facilitate root RCE attacks, and one of the vulnerabilities has already been exploited in the wild.
0
Email-Based Attacks Top Cyber-Insurance Claims
Việt Nam Hacker
Cyber-insurance carrier Coalition said business email compromise and funds transfer fraud accounted for 60% of claims in 2024.
0
Operation PowerOFF Takes Down 9 DDoS-for-Hire Domains
Việt Nam Hacker
Four different countries, including the United States and Germany, were included in the latest international operation alongside Europol's support.
0
Meta Wins Lawsuit Against Spyware Vendor NSO Group
Thứ Tư, 7 tháng 5, 2025
Việt Nam Hacker
The spyware company must pay the tech giant $168 million in punitive and compensatory damages after a 2019 attack targeting 1,400 devices.
0
Play Ransomware Group Used Windows Zero-Day
Việt Nam Hacker
Previously, Microsoft reported that Storm-2460 had also used the privilege escalation bug to deploy ransomware on organizations in several countries.
0
'Bring Your Own Installer' Attack Targets SentinelOne EDR
Việt Nam Hacker
Researchers from Aon's Stroz Friedberg incident response firm discovered a new attack type, known as "Bring Your Own Installer," targeting misconfigured SentinelOne EDR installs.
0
Infrastructure as Code: An IaC Guide to Cloud Security
Việt Nam Hacker
IaC is powerful. It brings speed, scale, and structure to cloud infrastructure. But none of that matters if your security can't keep up.
0
Researcher Says Patched Commvault Bug Still Exploitable
Thứ Ba, 6 tháng 5, 2025
Việt Nam Hacker
CISA added CVE-2025-34028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.
0
'Easily Exploitable' Langflow Vulnerability Requires Immediate Patching
Việt Nam Hacker
The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.
0
The Dark Side of Digital: Breaking The Silence on Youth Mental Health
Việt Nam Hacker
Industry experts at RSAC 2025 call for urgent accountability in addressing technology's negative impact on youth, highlighting concerns about internet anonymity, mental health, and the growing disconnect between generations.
0
'Venom Spider' Targets Hiring Managers in Phishing Scheme
Thứ Hai, 5 tháng 5, 2025
Việt Nam Hacker
Researchers from Arctic Wolf Labs detailed a new spear-phishing campaign that targets hiring managers and recruiters by posing as a job seeker.
0
Phony Hacktivist Pleads Guilty to Disney Data Leak
Việt Nam Hacker
After stealing sensitive data from Disney, Ryan Mitchell Kramer claimed to be part of a Russian hacktivist group protecting artists' rights and ensuring they receive fair compensation for their work.
0
How to Prevent AI Agents From Becoming the Bad Guys
Việt Nam Hacker
When designed with strong governance principles, AI can drive innovation while maintaining the people's trust and security.
0
What NYDFS Rules Mean for Businesses (in and outside of NY)
Thứ Sáu, 2 tháng 5, 2025
Việt Nam Hacker
Starting this month, finance companies operating in New York must implement a variety of protections against unauthorized access to IT systems.
0
Enterprises Need to Beware of These 5 Threats
Thứ Năm, 1 tháng 5, 2025
Việt Nam Hacker
A panelist of SANS Institute leaders detailed current threats and provided actionable steps for enterprises to consider.
0
SANS Top 5: Cyber Has Busted Out of the SOC
Việt Nam Hacker
This year's top cyber challenges include cloud authorization sprawl, ICS cyberattacks and ransomware, a lack of cloud logging, and regulatory constraints keeping defenders from fully utilizing AI's capabilities.
0
Experts Debate Real ID Security Ahead of May 7 Deadline
Việt Nam Hacker
Real IDs have been in the works since 2005. Are their security standards still rigorous enough in 2025?
0
Getting Outlook.com Ready for Bulk Email Compliance
Việt Nam Hacker
Microsoft has set May 5 as the deadline for bulk email compliance. In this Tech Tip, we show how organizations can still make the deadline.
Đăng ký:
Bài đăng (Atom)