Security News

Kickidler employee monitoring software abused in ransomware attacks
2025-05-08 16:05

Ransomware operations are using legitimate Kickidler employee monitoring software for reconnaissance, tracking their victims' activity, and harvesting credentials after breaching their networks. [...]

SonicWall urges admins to patch VPN flaw exploited in attacks
2025-05-08 11:19

SonicWall has urged its customers to patch three security vulnerabilities affecting its Secure Mobile Access (SMA) appliances, one of them tagged as exploited in attacks [...]

Play ransomware exploited Windows logging flaw in zero-day attacks
2025-05-07 14:45

The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. [...]

NSO Group fined $167M for spyware attacks on 1,400 WhatsApp users
2025-05-07 14:09

A U.S. federal jury has ordered Israeli spyware vendor NSO Group to pay WhatsApp $167,254,000 in punitive damages and $444,719 in compensatory damages for a 2019 campaign that targeted 1,400 users...

Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks
2025-05-07 13:54

Europol has announced the takedown of distributed denial of service (DDoS)-for-hire services that were used to launch thousands of cyber-attacks across the world. In connection with the operation,...

Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
2025-05-06 17:10

Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. [...]

How cybercriminals exploit psychological triggers in social engineering attacks
2025-05-06 05:00

Most attacks don’t start with malware; they begin with a message that seems completely normal, whether it comes through email, a phone call, or a chat, and that is exactly what makes them so...

New "Bring Your Own Installer" EDR bypass used in ransomware attack
2025-05-05 20:28

A new "Bring Your Own Installer" EDR bypass technique is exploited in attacks to bypass SentinelOne's tamper protection feature, allowing threat actors to disable endpoint detection and response...

UK retailers under cyber attack: Co-op member data compromised
2025-05-05 12:07

UK-based retailers Marks & Spencer, Co-op, and Harrods have been targeted by cyber attackers in the last few weeks. Whether the attacks have been mounted by the same group is difficult to say for...

Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack
2025-05-03 14:31

Cybersecurity researchers have discovered three malicious Go modules that include obfuscated code to fetch next-stage payloads that can irrevocably overwrite a Linux system's primary disk and...