Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Researchers have confirmed that the cyber extortion group ExfilSquad has accessed and stolen sensitive data from at least 13 different organizations. This data has been published by the group through torrents, making it publicly available. The nature of the stolen information remains unspecified, but the breach underscores significant security vulnerabilities within these organizations. As the leaked data could potentially be used for further attacks or identity theft, companies need to assess their security measures and respond swiftly to mitigate any potential fallout. This incident serves as a reminder of the ongoing risks posed by cybercriminals who exploit weaknesses in security protocols.

Read Original
Actively Exploited

A recently patched vulnerability in SAP Commerce Cloud, classified as a maximum-severity remote code execution flaw, is now being actively targeted by attackers. The flaw was fixed just three days ago, and threat intelligence firm Defused has reported that cybercriminals are already exploiting it. This vulnerability puts users of SAP Commerce Cloud at risk, as it allows unauthorized code execution, potentially leading to data breaches or service disruptions. Companies using this platform need to ensure they apply the latest security updates to protect their systems. The urgency of the situation is underscored by the rapid exploitation following the announcement of the patch, making swift action essential for affected organizations.

Read Original

A new botnet called Evooo1Bot has emerged, built on the Mirai framework and featuring enhanced capabilities. This botnet is designed to convert compromised edge devices into persistent proxies, which can be exploited for various malicious activities. Researchers have noted that this could significantly impact Internet of Things (IoT) devices, making them potential tools for cybercriminals. The ability to create proxies means that attackers can mask their identity and amplify their operations, raising concerns about privacy and security. Users of affected devices need to be vigilant and improve their security measures to prevent being turned into unwitting participants in these attacks.

Read Original

Shell is currently investigating a potential security incident after the Clop ransomware group claimed to have stolen 89GB of sensitive data from the company. The group is known for targeting large organizations and demanding ransom payments to prevent the public release of stolen information. Although Shell has not confirmed the specifics of the data taken, the incident raises concerns about the security of sensitive corporate information and the potential impacts on operations and reputation. As the investigation unfolds, it remains to be seen how the company will respond and whether any sensitive information has already been compromised. This incident serves as a reminder for all organizations to bolster their cybersecurity measures against ransomware attacks.

Read Original

A recent analysis revealed that Trivy, a popular open-source vulnerability scanner, was responsible for exposing over 2,500 organizations to security risks, rather than malicious LiteLLM packages. Researchers noted that more than 95% of these companies had vulnerabilities before the LiteLLM packages were released. This incident raises concerns about the security practices surrounding the use of scanning tools and the potential for software vulnerabilities to be exploited, impacting organizations' defenses. Companies using Trivy should review their configurations and assess their vulnerability management processes to prevent similar compromises in the future. This situation serves as a reminder for organizations to stay vigilant about their security practices and regularly update their tools.

Read Original

Researchers from Group-IB have identified a new Android malware called WindRelay that poses a significant threat to users by capturing real-time payment card data via NFC (Near Field Communication). The malware works in conjunction with the SpyNote remote access trojan, enabling attackers to gain control over a victim's device and relay sensitive information directly to them. The attack typically begins with a phone call from a fraudster impersonating a bank representative, tricking victims into revealing their financial data. This malware not only compromises personal financial security but also highlights the growing sophistication of cybercriminal tactics. Users need to be vigilant about unsolicited calls and consider additional security measures to protect their payment information.

Read Original

In July, the ShinyHunters hacking group breached RingCentral, exposing personal information from approximately 1.6 million accounts. The breach was confirmed by the data breach notification service Have I Been Pwned. Users whose accounts were compromised could be at risk for identity theft and other forms of fraud, as the stolen data may include sensitive information. This incident underscores the ongoing threat posed by cybercriminals and the importance of companies to enhance their security measures. Affected users should take immediate steps to secure their accounts and monitor for any suspicious activity.

Read Original

A data breach involving RingCentral has potentially affected 1.6 million users. Hackers have publicly shared the stolen data, which includes personal information such as names, addresses, email addresses, and phone numbers. This incident raises serious concerns about user privacy and data security, as exposed personal details can lead to identity theft and phishing attacks. Companies like RingCentral must enhance their security measures to protect user data from such breaches. Users are advised to monitor their accounts for any unusual activity and consider changing their passwords to safeguard their information.

Read Original

A former data analyst contractor for Brightly Software has been sentenced to two years in prison after being convicted of stealing sensitive data and attempting to extort his employer for $2.5 million. The analyst, who worked with the company from 2019 to 2020, accessed confidential information and threatened to release it unless his demands were met. This incident not only resulted in legal consequences for the individual but also raises concerns about insider threats in organizations, particularly those handling sensitive data. Companies must be vigilant in monitoring employee access and implementing strict data protection measures to prevent similar incidents in the future.

Read Original

A significant data leak has occurred involving 7.3 million user profiles from Chess.com, which surfaced in a 15.5 GB file posted on two data-leak websites. Researchers confirm that the data is legitimate and appears to have been obtained through large-scale scraping rather than a direct breach of Chess.com's servers. This incident raises concerns about user privacy, as exposed data can include personal information and potentially sensitive account details. The fact that the data is being offered for free suggests that it was not stolen for immediate profit but rather to be shared widely, which could lead to further exploitation of the affected users. It’s crucial for Chess.com users to be aware of this leak and take steps to secure their accounts, such as changing passwords and enabling two-factor authentication.

Read Original

Ukrainian police have taken significant action against fraudulent call centers, raiding 94 locations across the country. This operation involved over 400 searches, resulting in the seizure of $2 million worth of equipment, including computers, phones, and SIM cards. The call centers were reportedly involved in scams where operators impersonated bank employees and promoted fake investment and cryptocurrency services. They also attempted to gain remote access to victims' devices by collecting personal information. This crackdown is crucial in protecting individuals from financial fraud and identity theft, as these scams can have devastating effects on victims.

Read Original

Researchers from Broadcom have linked a Chinese APT group, known as 'Jewelbug', to a hack-for-hire scheme that is reportedly involved in a significant cryptocurrency fraud operation. This group has been known for its cyber espionage activities but is now suspected of engaging in illegal financial schemes, potentially affecting individuals and organizations involved in cryptocurrency transactions. The connection to hack-for-hire operations raises concerns about the growing trend of state-sponsored groups diversifying into criminal activities for profit. This development highlights the need for enhanced vigilance among crypto users and businesses to protect against potential scams and fraud. The implications are serious, as these types of operations can undermine trust in the cryptocurrency market and lead to financial losses for victims.

Read Original

On August 13, President Trump authorized a new program allowing vetted private cybersecurity firms in the U.S. to conduct offensive cyber operations against transnational criminal networks. This national security memorandum aims to empower these companies to take proactive measures against organized crime groups under government oversight. The initiative is intended to enhance the nation's capabilities in combating cybercrime, which has been a growing concern for law enforcement and national security. By involving private firms, the government hopes to leverage their expertise and resources to disrupt criminal activities that often span multiple countries. This move could change the dynamics of how cyber threats are addressed, as it blurs the lines between public and private sector roles in cybersecurity.

Read Original
Actively Exploited

Researchers have identified a serious SQL injection vulnerability in GeoServer, a popular open-source server for sharing geospatial data. This flaw could enable attackers to execute remote code on affected systems, posing a significant risk to organizations that rely on GeoServer for managing geographic information. The vulnerability is currently unpatched, making it particularly concerning as hackers may exploit it in the wild. Organizations using GeoServer should address this issue promptly to prevent potential breaches and protect sensitive geospatial data. The urgency for users to secure their installations cannot be overstated, given the potential for widespread exploitation.

Read Original

A new macOS malware called AmnesiaStealer has been identified, which is written in Rust and targets users' sensitive data. This infostealer can extract passwords, keychain information, and data from Chromium-based browsers as well as Safari cookies. Users of macOS devices are particularly at risk, as the malware can also control browser sessions, making it potentially dangerous for online activities. The emergence of this malware is concerning for individuals who might unknowingly expose their personal information, as attackers can exploit this data for fraudulent purposes. It's important for macOS users to be vigilant about their security practices to protect against such threats.

Read Original
Page 1 of 341Next