News
-
"FishXProxy Phishing Kit Outfits Cybercriminals for Success"A new end-to-end phishing toolkit called "FishXProxy" makes it easier for cybercriminals to launch and manage malicious email attacks that bypass security.
-
"Ransomware Surges Annually Despite Law Enforcement Takedowns"Symantec reports that in the first quarter of 2024, successful ransomware attacks advertised on leak sites increased 9 percent despite high-profile law enforcement takedowns of major groups.
-
"GitLab Ships Update for Critical Pipeline Execution Vulnerability"GitLab has made security updates that address six vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE), including a critical-severity bug.
-
"Dallas County: Data of 200,000 Exposed in 2023 Ransomware Attack"Dallas County is notifying over 200,000 people that the Play ransomware attack in October 2023 exposed their personal data to cybercriminals.
-
"Advance Auto Parts Data Breach Impacts 2.3 Million People"Advance Auto Parts started to send data breach notifications to over 2.3 million people whose personal data was stolen in recent Snowflake data theft attacks.
-
"CRYSTALRAY Hacker Expands to 1,500 Breached Systems Using SSH-Snake Tool"According to researchers at Sysdig, the new threat actor called "CRYSTALRAY" now has over 1,500 victims. The threat actor has stolen credentials and deployed cryptocurrency miners.
-
"PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks"A recently disclosed PHP security flaw has been used to deliver Remote Access Trojans (RATs), cryptocurrency miners, and Distributed Denial-of-Service (DDoS) botnets.
-
"CISA, FBI Urge Immediate Action on OS Command Injection Vulnerabilities in Network Devices"The US Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released a joint alert about the exploitation of OS command injection vulnerabilities in network edge devices.
-
"Huione Guarantee Marketplace Exposed as Front for Cybercrime"Cryptocurrency investigators at Elliptic have claimed a popular online marketplace in Southeast Asia is actually being used primarily by money launderers and fraudsters.
-
"VMware Patches Critical SQL-Injection Flaw in Aria Automation"VMWare recently pushed out patches for a high-risk SQL injection vulnerability in its Aria Automation product and warned that an authenticated malicious user could target the flaw to manipulate databases.
-
"NSA Joins in Releasing Case Studies Showing PRC Tradecraft in Action"The National Security Agency (NSA) joins the Australian Signals Directorate (ASD) and other agencies in publishing a Cybersecurity Advisory (CSA) titled "PRC MSS Tradecraft in Action." It delves into the tradecraft of a cyber actor group associat
-
"Ransomware Groups Prioritize Defense Evasion for Data Exfiltration"Cisco Talos reports that ransomware attackers are increasingly focusing on defense evasion to boost dwell time in victim networks.