Skip to main content

Tag: cyber security

4316 articles

AMD Alerts on New Transient Scheduler Attacks Threatening Many CPUs

AMD Alerts on New Transient Scheduler Attacks Threatening Many CPUs

AMD has unveiled a new class of Transient Scheduler Attacks that exploit speculative execution vulnerabilities, putting a broad spectrum of CPUs—from desktops to servers—at risk of exposing sensitive data. This emerging threat highlights the escalating complexity of hardware security, urging swift implementation of mitigations as full patches remain underway.

Analyst 207
Gold Melody IAB Exploits ASP.NET Keys for Unauthorized Access

Gold Melody IAB Exploits ASP.NET Keys for Unauthorized Access

Gold Melody, an Initial Access Broker tracked as TGR-CRI-0045 by Palo Alto Networks’ Unit 42, exploits leaked ASP.NET machine keys to forge authentication tokens, enabling stealthy, unauthorized access that bypasses traditional security measures and threatens organizational networks at their core.

Analyst 207
DoNot APT Targets European Foreign Ministries with LoptikMod Malware

DoNot APT Targets European Foreign Ministries with LoptikMod Malware

A sophisticated APT group known as DoNot Team has targeted a European foreign ministry with the stealthy, modular LoptikMod malware, marking a dangerous escalation in cyber espionage that threatens national security and the confidentiality of diplomatic communications. Experts warn this persistent, adaptable intrusion exemplifies how digital espionage is reshaping international relations by enabling covert, long-term access to sensitive state secrets.

Analyst 207
Chinese Hacker Xu Zewei Arrested for Silk Typhoon Cyber Attacks

Chinese Hacker Xu Zewei Arrested for Silk Typhoon Cyber Attacks

The arrest of Xu Zewei, linked to the state-sponsored Silk Typhoon hacking group, highlights the escalating global challenge of cyber warfare and the critical need for coordinated international efforts to safeguard national security. This case underscores that combating sophisticated cyber threats demands not only law enforcement action but also sustained diplomatic and technological collaboration.

Analyst 207
Microsoft Urgently Patches 130 Vulnerabilities Including Critical SQL Flaws

Microsoft Urgently Patches 130 Vulnerabilities Including Critical SQL Flaws

Microsoft has urgently released patches for 130 vulnerabilities—including 10 critical flaws affecting SQL Server—that pose significant risks to enterprise data security, underscoring the urgent need for organizations to strengthen their defenses against evolving cyber threats.

Analyst 207
Hackers Exploit Leaked Shellter License to Spread Lumma and SectopRAT

Hackers Exploit Leaked Shellter License to Spread Lumma and SectopRAT

Hackers have exploited leaked Shellter licenses to weaponize this trusted red teaming tool, enabling the stealthy spread of Lumma and SectopRAT malware that evades detection by masquerading as legitimate penetration testing activity. This incident highlights a growing challenge in cybersecurity: safeguarding offensive security tools from misuse without hindering their essential role in strengthening defenses.

Analyst 207
Anatsa Android Trojan Infects 90,000 via Fake PDF App on Google Play

Anatsa Android Trojan Infects 90,000 via Fake PDF App on Google Play

Cybersecurity experts have uncovered Anatsa, a sophisticated Android banking trojan infecting 90,000 users via a fake “PDF Update” app on Google Play, exploiting the platform’s trust to steal sensitive banking credentials through convincing overlay attacks. This alarming campaign underscores the evolving threat landscape targeting mobile banking users in North America.

Analyst 207
Malicious Pull Request Hits 6,000 Developers Through Ethcode Extension

Malicious Pull Request Hits 6,000 Developers Through Ethcode Extension

A sophisticated supply chain attack compromised the Ethcode extension for VS Code, silently infecting over 6,000 developers with malicious code and exposing critical blockchain projects to severe security risks. This breach highlights the urgent need for vigilant verification in software supply chains, where trust can be weaponized to devastating effect.

Analyst 207
Dark command center with operators and gear, foreground shows broken satellite dish, cracked screen, and distorted radio,…

Three Critical Challenges Modern C2 Centers Face on Battlefields

“In the chaos of modern warfare, how does a commander maintain clarity?” This question has become increasingly urgent as battlefields evolve into multifaceted arenas where technology, strategy, and human judgment…

Analyst 207
Ransomware Disrupts Power Meter Readings in Nova Scotia

Ransomware Disrupts Power Meter Readings in Nova Scotia

Ransomware attack disrupts power meter readings in Nova Scotia, impacting utility operations and customer services. Urgent response underway.

Analyst 207
DoNot APT Expands Reach, Aiming at European Foreign Ministries with LoptikMod Malware

DoNot APT Expands Reach, Aiming at European Foreign Ministries with LoptikMod Malware

DoNot APT targets European foreign ministries using LoptikMod malware, expanding its reach and enhancing its cyber espionage capabilities.

Analyst 207
New Vulnerability in ServiceNow Allows Attackers to Access Restricted Data

New Vulnerability in ServiceNow Allows Attackers to Access Restricted Data

New vulnerability in ServiceNow exposes restricted data, allowing attackers potential access to sensitive information and raising security concerns.

Analyst 207
The Deceptive MFA: How Attackers Take Advantage of Your Trust

The Deceptive MFA: How Attackers Take Advantage of Your Trust

Discover how attackers exploit trust in multi-factor authentication (MFA) to compromise security and learn ways to protect yourself.

Analyst 207
Complete BYOD Security: Zero Data, Zero Risk with Cloud Protection

Complete BYOD Security: Zero Data, Zero Risk with Cloud Protection

Ensure complete BYOD security with zero data loss and zero risk through robust cloud protection solutions. Safeguard your mobile workforce effectively.

Analyst 207
Microsoft Patch Tuesday: Addressing a Zero-Day Vulnerability and a Possible ‘Wormable’ Threat

Microsoft Patch Tuesday: Addressing a Zero-Day Vulnerability and a Possible ‘Wormable’ Threat

Microsoft Patch Tuesday addresses a critical zero-day vulnerability and a potential ‘wormable’ threat, ensuring enhanced security for users.

Analyst 207
Streamlining Ticket Creation, Device Identification, and Threat Triage Using Tines Automation

Streamlining Ticket Creation, Device Identification, and Threat Triage Using Tines Automation

Enhance efficiency with Tines Automation for streamlined ticket creation, precise device identification, and effective threat triage.

Analyst 207
U.S. Imposes Sanctions on North Korean Hacker Linked to Fraudulent IT Worker Scheme

U.S. Imposes Sanctions on North Korean Hacker Linked to Fraudulent IT Worker Scheme

U.S. sanctions North Korean hacker tied to fraudulent IT worker scheme, aiming to curb cybercrime and protect financial systems.

Analyst 207
Qantas Alerts Customers of Home Address Breach by Unknown Attackers

Qantas Alerts Customers of Home Address Breach by Unknown Attackers

Qantas informs customers of a home address breach by unknown attackers, urging vigilance and offering support to affected individuals.

Analyst 207
Strava’s Ongoing Privacy Concerns: Another Leak Emerges

Strava’s Ongoing Privacy Concerns: Another Leak Emerges

Strava faces new privacy concerns as another data leak emerges, raising questions about user security and the platform’s handling of personal information.

Analyst 207
Chinese Hacker Xu Zewei Detained for Connections to Silk Typhoon Group and U.S. Cyber Offenses

Chinese Hacker Xu Zewei Detained for Connections to Silk Typhoon Group and U.S. Cyber Offenses

Chinese hacker Xu Zewei detained for ties to the Silk Typhoon group and involvement in U.S. cyber offenses, raising security concerns.

Analyst 207
Ingram Micro Resumes Orders for Select Customers After Ransomware Incident

Ingram Micro Resumes Orders for Select Customers After Ransomware Incident

Ingram Micro resumes orders for select customers following a ransomware incident, ensuring a return to normal operations and service continuity.

Analyst 207
M&S Chair Discusses Ransomware Attack, Remains Silent on Payment Status

M&S Chair Discusses Ransomware Attack, Remains Silent on Payment Status

M&S chair addresses the recent ransomware attack but does not disclose any information regarding the status of payment to the attackers.

Analyst 207
Microsoft Addresses 130 Vulnerabilities, Highlighting Critical Issues in SPNEGO and SQL Server

Microsoft Addresses 130 Vulnerabilities, Highlighting Critical Issues in SPNEGO and SQL Server

Microsoft fixes 130 vulnerabilities, focusing on critical issues in SPNEGO and SQL Server to enhance security and protect against potential threats.

Analyst 207
Iranian Ransomware Group Resurfaces, Offers Lucrative Rewards for Attacks on US and Israel

Iranian Ransomware Group Resurfaces, Offers Lucrative Rewards for Attacks on US and Israel

Iranian ransomware group re-emerges, enticing hackers with lucrative rewards for cyber attacks targeting the US and Israel.

Analyst 207