Ransomware Attack Disrupts OneBlood’s Blood Collection and Distribution Capacity
OneBlood, a non-profit blood center serving the southeastern United States, is facing a ransomware attack that has led to a critical shortage of blood products, prompting urgent calls for donations.
View full story…
DigiCert Identifies Non-Compliance Issue with DNS-Based Validation Method
DigiCert, a prominent certificate authority, recently identified a non-compliance issue with its DNS-based validation method, resulting in the mis-issuance and revocation of thousands of certificates impacting subscribers.
View full story…
Fortune 50 Company Pays Record $75 Million Ransom to Dark Angels Group
Fortune 50 company reportedly pays $75 million ransom to Dark Angels group, setting dangerous precedent for cyber criminal groups.
View full story…
Multiple Cross-Site Scripting (XSS) Vulnerabilities Discovered in REDCap
Trustwave SpiderLabs found three XSS vulnerabilities in REDCap version 13.1.9, allowing authenticated users to inject malicious JavaScript code and posing a threat to sensitive data.
View full story…
Chinese Nation-State Threat Actor APT10 Conducts Cyber Espionage Campaign Cuckoo Spear Targeting Japanese Organizations
APT10, also known as Bronze Riverside, has been conducting persistent cyber espionage operations targeting Japanese organizations using malware families like LODEINFO and NOOPDOOR to steal sensitive information.
View full story…
Cyber Espionage Group XDSpy Targets Organizations in Russia and Moldova
XDSpy, Turla, and GhostWriter conduct phishing campaigns and deploy malware against organizations in Eastern Europe, highlighting the need for enhanced cybersecurity measures.
View full story…
Protect AI Acquires SydeLabs, Enhancing AI Security Capabilities for Large Language Models
Protect AI has acquired SydeLabs, a company specializing in automated red teaming for generative AI systems, to enhance their platform with red teaming capabilities for large language models.
View full story…
Malicious Package on PyPI Steals Discord User Data and Browser Cookies
Fortinet’s AI-driven OSS malware detection system identifies dangerous package zlibxjson version 8.2 on PyPI targeting Discord users and stealing browser cookies.
View full story…
AI-Driven Executive Impersonations Pose Significant Threat to Business Payment Processes
Finance professionals increasingly targeted by deepfake and impersonation attacks, with Trustmi offering fraud prevention technology to automate processes and enhance visibility.
View full story…
Latest Cybernews
UK Electoral Commission Suffers Security Breach Compromising 40 Million Voters’ Data
Hackers linked to the Chinese state exploit vulnerabilities in the Commission’s servers, accessing voter data from 2014 to 2022.
View full story…
Cybersixgill’s State of the Underground 2024 Report Reveals Trends in Cybercrime
Cybersixgill’s threat experts provide insights into underground activities and threat actors, highlighting trends in compromised credit cards, ransomware attacks, and wholesale access markets.
View full story…
Sophisticated Phishing Campaign Targets Microsoft OneDrive Users
Security researchers uncover advanced social engineering tactics used to compromise systems in phishing campaign targeting Microsoft OneDrive users.
View full story…
New Sidewinder Cyber Espionage Campaign Targets Ports and Maritime Facilities in Indian Ocean and Mediterranean Sea
Sidewinder, a nation-state threat actor associated with India, initiates cyber espionage campaign targeting ports and maritime facilities using phishing emails and exploiting vulnerabilities CVE-2017-0199 and CVE-2017-11882.
View full story…
Ransomware Groups Exploit Critical VMware ESXi Vulnerability for File-Encrypting Malware Deployment
Ransomware groups like Storm-0506, Storm-1175, Manatee Tempest, and Octo Tempest exploit CVE-2024-37085 in VMware ESXi hypervisors to gain elevated permissions and deploy file-encrypting malware.
View full story…