Key TakeawaysData Exposure: The University of Phoenix has disclosed that a breach of its Oracle EBS system may have compromised the data of nearly 3.5M…
Key TakeawaysInsider Threat Confirmed: Two industry professionals admitted to orchestrating ALPHV/BlackCat ransomware attacks while employed in trusted incident response roles.Significant Financial Extortion: The perpetrators successfully…
Key TakeawaysSupply Chain Vulnerability: A ransomware attack on third-party vendor Marquis Software compromised dozens of financial institutions and thousands of customers.Widespread Data Exposure: The breach…
Key TakeawaysSecurity Failures: Korea Telecom femtocells were deployed with security oversights, recent discoveries say.Customer Impact: Flaws allowed attackers to clone the devices, intercept customer communications,…
Key TakeawaysInternational Arrest: A Lithuanian national has been arrested in Georgia and extradited to South Korea for operating a massive malware campaign.Widespread Infection: The campaign…
Key TakeawaysInsider Threat: Authorities in India have arrested a former customer service agent for allegedly facilitating unauthorized access to Coinbase's internal systems.Data Exposure: The breach…
Ashish Gupta – Jammu and Kashmir Government Ashish Gupta has been designated as Chief Information Security Officer for the Department of Law, Justice and Parliamentary…
Key TakeawaysEvolved Tactics: The HoneyMyte APT group now uses a kernel-mode rootkit driver signed with a stolen digital certificate to deploy the ToneShell backdoor.Targeted Espionage:…
Key TakeawaysCritical Authentication Bypass: A major flaw could allow complete account takeover for any user with a Google login, as the API failed to validate…
Key TakeawaysCritical vulnerability: A significant security flaw has been identified in MongoDB, allowing attackers to read uninitialized heap memory from the server.Potential for data exposure:…
Key TakeawaysMassive compensation: Coupang announced $1.2 billion compensation plan for the 33.7 million customers initially said to be affected by the recent data leak.Investigation coordination:…
We see a recurring pattern across recent cybersecurity incidents where trust, and identity controls are being exploited across government systems, critical infrastructure, and financial platforms.…
Key TakeawaysVersion-specific incident: Only Trust Wallet Browser Extension version 2.68 is affected.Immediate mitigation: Users are urged to disable the extension and upgrade.Investigation: Binance founder said…
Key TakeawaysActive exploitation: Fortinet says attackers are abusing a long-standing SSL VPN flaw.Authentication protections: Misconfigurations can allow logins without completing two-factor authentication.Legacy systems at risk:…
Key TakeawaysSophisticated TTPs: The Evasive Panda APT utilizes advanced techniques, including DNS poisoning and adversary-in-the-middle (AitM) attacks.Geographic focus: The campaign has primarily targeted victims in…
Key TakeawaysDeceptive distribution: The WebRAT malware is being distributed through GitHub repositories disguised as PoC exploits for high-severity flaws.Targeted audience: Focus shifted from gamers to…
Key TakeawaysAntitrust penalty: Italy's competition authority fined Apple €98.6 million for abusing its dominant market position through the App Tracking Transparency framework.Double consent: The investigation…
Key Takeaways Service paralysis: A suspected DDoS attack disrupted La Poste's websites and mobile apps, causing significant delays in parcel delivery days before Christmas. Banking…
Key Takeaways Operation disruption: The Department of Justice seized a database containing stolen user credentials used to facilitate unauthorized bank account takeovers. Preventative action: This…
Key Takeaways Deceptive VPN service: Two extensions, active since 2017, masquerade as a legitimate VPN service, tricking users into paying for a subscription. Traffic interception:…
For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: