"New Xiu Gou Phishing Kit Targets US, Other Countries with Mascot"

"New Xiu Gou Phishing Kit Targets US, Other Countries with Mascot"

Since at least September 2024, users in the US, UK, Spain, Australia, and Japan have been targeted by a new phishing kit named "Xiu Gou," which was designed to deploy phishing attacks globally. The kit, discovered by the cybersecurity firm Netcraft, features a "doggo" mascot and has over 2,000 phishing websites targeting individuals in the public sector, postal services, digital services, and banking. This article continues to discuss findings regarding the Xiu Gou phishing kit.

Submitted by Gregory Rigby on

"Hackers Target Critical Zero-Day Vulnerability in PTZ Cameras"

"Hackers Target Critical Zero-Day Vulnerability in PTZ Cameras"

Hackers are targeting two zero-day vulnerabilities in PTZOptics pan-tilt-zoom (PTZ) live streaming cameras used in industrial, healthcare, government, and courtroom settings. Researchers at GreyNoise discovered the flaws in April 2024 after its Artificial Intelligence (AI)-powered threat detection tool called "Sift" detected unusual honeypot network activity that did not match established threats. This article continues to discuss the targeting of zero-day vulnerabilities in PTZ cameras.

Submitted by Gregory Rigby on

"New LightSpy Spyware Version Targets iPhones with Increased Surveillance Tactics"

"New LightSpy Spyware Version Targets iPhones with Increased Surveillance Tactics"

According to researchers at ThreatFabric, "LightSpy," an Apple iOS spyware, now has an improved version with destructive capabilities to prevent the compromised device from booting up. LightSpy, which was first documented in 2020 as targeting users in Hong Kong, is a modular implant that uses a plugin-based architecture to capture a wide range of sensitive from infected devices. This article continues to discuss findings regarding the new version of LightSpy.

Submitted by Gregory Rigby on

"Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware"

"Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware"

Researchers at Bitdefender Labs have discovered a malvertising campaign that abuses Meta's advertising platform and hijacks Facebook accounts to distribute the "SYS01stealer" infostealer. According to the researchers, the campaign uses about 100 malicious domains to distribute the malware and conduct live Command-and-Control (C2) operations. This article continues to discuss findings regarding the malvertising campaign aimed at spreading SYS01stealer.

Submitted by Gregory Rigby on

"Hackers Steal 15,000 Cloud Credentials From Exposed Git Config Files"

"Hackers Steal 15,000 Cloud Credentials From Exposed Git Config Files"

An operation named "EmeraldWhale" has led to the theft of over 15,000 cloud account credentials from thousands of private repositories by scanning for exposed Git configuration files. The campaign, discovered by researchers at Sysdig, uses automated tools to scan IP ranges for exposed Git configuration files, which may contain authentication tokens. Hackers behind the operation then use the tokens to download repositories stored on GitHub, GitLab, and BitBucket, which are scanned for additional credentials.

Submitted by Gregory Rigby on

"Canadian Government Data Stolen By Chinese Hackers"

"Canadian Government Data Stolen By Chinese Hackers"

According to the Canadian Centre for Cyber Security's 2025-2026 "National Cyber Threat Assessment," Chinese state-sponsored threat actors have maintained access to at least 20 Canadian government networks for four years to steal valuable data. The Cyber Centre reported that the threat actors targeted information to advance the Chinese Communist Party's (CCP) strategic, economic, and diplomatic interests as well as gain an advantage in China-Canada bilateral relations and commercial matters.

Submitted by Gregory Rigby on

"Over a Thousand Online Shops Hacked to Show Fake Product Listings"

"Over a Thousand Online Shops Hacked to Show Fake Product Listings"

Since 2019, a phishing campaign named "Phish n' Ships" has infected over 1,000 legitimate online stores to promote fake product listings for rare items. Those who click on those products are redirected to a network consisting of hundreds of fake web stores that steal their personal information and money. HUMAN's Satori Threat Intelligence discovered that the malicious campaign has affected hundreds of thousands of consumers and cost tens of millions of dollars. This article continues to discuss findings regarding the Phish n' Ships campaign.

Submitted by Gregory Rigby on

"Ransomware Hits Web Hosting Servers via Vulnerable CyberPanel Instances"

"Ransomware Hits Web Hosting Servers via Vulnerable CyberPanel Instances"

A threat actor has targeted about 22,000 vulnerable CyberPanel instances and encrypted files on the servers that run it using PSAUX and other ransomware. CyberPanel is a popular open source control panel for managing servers used to host websites. This article continues to discuss findings regarding the massive ransomware attack targeting vulnerable CyberPanel instances.

Help Net Security reports "Ransomware Hits Web Hosting Servers via Vulnerable CyberPanel Instances"

Submitted by Gregory Rigby on

"Ex-Disney Employee Charged With Hacking Menu Database"

"Ex-Disney Employee Charged With Hacking Menu Database"

The former Disney employee was arrested and charged with hacking the company's systems and changing restaurant menus. Michael Scheuer, a former Disney menu production manager, was charged with three Computer Fraud and Abuse Act (CFAA) violations. Scheuer's work credentials still functioned after his termination, allegedly allowing him to log into the Disney menu creation system contracted by a third-party company. This article continues to discuss the incident.

Submitted by Gregory Rigby on

"LiteSpeed Cache WordPress Plugin Bug Lets Hackers Get Admin Access"

"LiteSpeed Cache WordPress Plugin Bug Lets Hackers Get Admin Access"

The free version of the popular WordPress plugin LiteSpeed Cache recently fixed a dangerous privilege elevation flaw with its latest update that could allow unauthenticated site visitors to gain admin rights.  LiteSpeed Cache is a caching plugin used by over six million WordPress sites, helping to speed up and improve user browsing experience.  Security researchers at Patchstack discovered the high-severity flaw  CVE-2024-50550.

Submitted by Adam Ekwall on
Subscribe to