New “Sleepy Pickle” Attack Threatens Machine Learning Models
A new attack technique, known as the “Sleepy Pickle” attack, has been discovered, posing a significant threat to machine learning models by exploiting the Pickle serialization format.
View full story…
Google Delays Phase-Out of Third-Party Tracking Cookies in Chrome
Google announces delay in plan to phase out third-party tracking cookies in Chrome, facing criticism for potential privacy risks and use of AI in browsing history search.
View full story…
Microsoft President Brad Smith Addresses Security Shortfalls in House Committee Hearing
During a House Committee on Homeland Security hearing, Microsoft President Brad Smith addresses recent breaches by Chinese and Russian state hackers, as well as security issues related to Microsoft products used by federal agencies.
View full story…
North Korean Threat Actors Conducting Sophisticated Phishing Attacks in Brazil
UNC4899, PAEKTUSAN, Moonstone Sleet, and Kimsuky target various sectors in Brazil with malware-laced applications, fake recruiter personas, ransomware, and espionage tactics.
View full story…
Latest Cybernews
CISA Warns of Rise in Phone-Based Impersonation Fraud Campaigns
Scammers posing as government employees deceive victims into giving up personal information or money, leading to significant financial losses.
View full story…
Ukrainian Man Arrested for Involvement with Conti and LockBit Ransomware Groups
A 28-year-old man from Ukraine has been arrested for developing crypters to help the ransomware groups evade detection and for his role in a ransomware attack on a Dutch multinational company.
View full story…
Critical DNSSEC Vulnerability CVE-2023-50868 Discovered, Microsoft Releases Patch
A zero-day vulnerability in the DNSSEC protocol, impacting the NSEC3 mechanism, allows attackers to launch DoS attacks on DNS resolvers. Microsoft has issued a patch for Windows Server to address the issue.
View full story…
Cyber Insurance Claims in North America Reach Record Levels in 2023
Record levels of cyber insurance claims in North America in 2023 due to increasing sophistication of cyber-attacks, the MOVEit file transfer incident, privacy claims, and rising number of organizations purchasing cyber insurance.
View full story…
Latest Cybernews
Ransomware Group Exploits Critical PHP Vulnerability for Remote Code Execution
Threat actors, specifically the ransomware group TellYouThePass, have been exploiting a critical Remote Code Execution (RCE) vulnerability in PHP to execute arbitrary PHP code on targeted systems.
View full story…
Scattered Spider Joins RansomHub in Ransomware Collaboration
Scattered Spider, a cybercrime group previously associated with ALPHV/BlackCat, has partnered with RansomHub to conduct ransomware operations, targeting organizations like UnitedHealth Group with extortion demands.
View full story…
Chinese State-Sponsored Cyberespionage Campaign Targets Fortinet Vulnerability, Compromising Over 20,000 Devices Globally
Chinese threat actors exploit zero-day vulnerability in Fortinet’s FortiOS and FortiProxy software, deploying Coathanger RAT malware on over 14,000 devices, including government systems in the Netherlands.
View full story…
New Backdoor Malware Strain Noodle RAT Identified by Cybersecurity Experts
Chinese-speaking hacker groups use Noodle RAT for espionage and cybercrime activities, targeting countries in the Asia-Pacific region since 2020.
View full story…
Mass Exploitation of Edge Services and Infrastructure Devices on the Rise
Recent research highlights a concerning trend of cyber threat actors targeting edge services and infrastructure devices through mass exploitation incidents, exploiting vulnerabilities in software like MOVEit, CitrixBleed, and Cisco XE.
View full story…