Security News

North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns
2024-09-05 01:17

Feds warn of 'highly tailored, difficult-to-detect social engineering campaigns' The FBI has warned that North Korean operatives are plotting "complex and elaborate" social engineering attacks...

Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data
2024-09-04 20:33

93GB of info feared pilfered in Montana by heartless crooks Planned Parenthood of Montana's chief exec says the org is responding to a cyber-attack on its systems, and has drafted in federal law...

Red team tool ‘MacroPack’ abused in attacks to deploy Brute Ratel
2024-09-04 20:31

The MacroPack framework, initially designed for Red Team exercises, is being abused by threat actors to deploy malicious payloads, including Havoc, Brute Ratel, and PhatomCore. [...]

New Eucleak attack lets threat actors clone YubiKey FIDO keys
2024-09-04 17:48

A new "EUCLEAK" flaw found in FIDO devices using the Infineon SLE78 security microcontroller, like Yubico's YubiKey 5 Series, allows attackers to extract Elliptic Curve Digital Signature Algorithm...

Iran Cyber Attack: Fox Kitten Facilitates Ransomware in US
2024-09-04 17:01

Read more about an attack campaign led by Iran-based cyberespionage threat actor Fox Kitten, and learn how to protect your company from this threat.

Revival Hijack supply-chain attack threatens 22,000 PyPI packages
2024-09-04 13:43

Threat actors are utilizing an attack called "Revival Hijack," where they register new PyPi projects using the names of previously deleted packages to conduct supply chain attacks. [...]

Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack
2024-09-04 05:31

A new malware campaign is spoofing Palo Alto Networks' GlobalProtect VPN software to deliver a variant of the WikiLoader (aka WailingCrab) loader by means of a search engine optimization (SEO)...

OpenBAS: Open-source breach and attack simulation platform
2024-09-04 04:00

OpenBAS is an open-source platform that enables organizations to plan, schedule, and execute crisis exercises, adversary simulations, and breach simulations. Compliant with ISO 22398 standards,...

Ransomware attacks escalate as critical sectors struggle to keep up
2024-09-04 03:00

Ransomware remains a concerning cybersecurity threat, with attacks becoming more frequent, severe, and costly. Recent reports highlight alarming trends, including increased attacks on critical...

FBI warns crypto firms of aggressive social engineering attacks
2024-09-03 17:43

The FBI warns of North Korean hackers aggressively targeting cryptocurrency companies and their employees in sophisticated social engineering attacks, aiming to deploy malware that steals their...