Security News
![SSH vulnerability exploitable in Terrapin attacks (CVE-2023-48795)](/static/build/img/news/ssh-vulnerability-exploitable-in-terrapin-attacks-cve-2023-48795-small.jpg)
Security researchers have discovered a vulnerability in the SSH cryptographic network protocol that could allow an attacker to downgrade the connection's security by truncating the extension negotiation message. Terrapin is a prefix truncation attack targeting the SSH protocol.
![Vans and North Face owner VF Corp hit by ransomware attack](/static/build/img/news/vans-and-north-face-owner-vf-corp-hit-by-ransomware-attack-small.jpg)
American global apparel and footwear giant VF Corporation, the owner of brands like Supreme, Vans, Timberland, and The North Face, has disclosed a security incident that caused operational disruptions. In response to the detected unauthorized access on its network, the company shut down some of its systems and brought in external experts to help contain the attack.
![Kraft Heinz suggests we simmer down about Snatch ransomware attack claims](/static/build/img/news/kraft-heinz-suggests-we-simmer-down-about-snatch-ransomware-attack-claims-small.jpg)
The Kraft Heinz Company says its systems are all up and running as usual as it probes claims that some of its data was stolen by ransomware crooks. Kraft Heinz, which owns a ton of food and beverage brands including Oscar Meyer, Kool-Aid, Jell-O, Maxwell House, and Grey Poupon, declined to answer our specific questions about the Snatch extortion gang's boasts that it had compromised the manufacturer and obtained internal information.
![New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks](/static/build/img/news/new-kv-botnet-targeting-cisco-draytek-and-fortinet-devices-for-stealthy-attacks-small.jpg)
A new botnet consisting of firewalls and routers from Cisco, DrayTek, Fortinet, and NETGEAR is being used as a covert data transfer network for advanced persistent threat actors, including the...
![New NKAbuse Malware Exploits NKN Blockchain Tech for DDoS Attacks](/static/build/img/news/new-nkabuse-malware-exploits-nkn-blockchain-tech-for-ddos-attacks-small.jpg)
A novel multi-platform threat called NKAbuse has been discovered using a decentralized, peer-to-peer network connectivity protocol known as NKN (short for New Kind of Network) as a communications...
![Ledger dApp supply chain attack steals $600K from crypto wallets](/static/build/img/news/ledger-dapp-supply-chain-attack-steals-600k-from-crypto-wallets-small.jpg)
Ledger is warnings users not to use web3 dApps after a supply chain attack on the 'Ledger dApp Connect Kit' library was found pushing a JavaScript wallet drainer that stole $600,000 in crypto and NFTs. Ledger is a hardware wallet that lets users buy, manage, and securely store their digital assets offline, supporting multiple cryptocurrencies, including Bitcoin and Ethereum. The company offers a library called the "Ledger dApps Connect Kit" that allows web3 apps to connect to Ledger hardware wallets.
![Russian SVR-Linked APT29 Targets JetBrains TeamCity Servers in Ongoing Attacks](/static/build/img/news/russian-svr-linked-apt29-targets-jetbrains-teamcity-servers-in-ongoing-attacks-small.jpg)
Threat actors affiliated with the Russian Foreign Intelligence Service (SVR) have targeted unpatched JetBrains TeamCity servers in widespread attacks since September 2023. The activity has been...
![New Hacker Group 'GambleForce' Tageting APAC Firms Using SQL Injection Attacks](/static/build/img/news/new-hacker-group-gambleforce-tageting-apac-firms-using-sql-injection-attacks-small.jpg)
A previously unknown hacker outfit called GambleForce has been attributed to a series of SQL injection attacks against companies primarily in the Asia-Pacific (APAC) region since at least...
![BazarCall attacks abuse Google Forms to legitimize phishing emails](/static/build/img/news/bazarcall-attacks-abuse-google-forms-to-legitimize-phishing-emails-small.jpg)
A new wave of BazarCall attacks uses Google Forms to generate and send payment receipts to victims, attempting to make the phishing attempt appear more legitimate. BazarCall, first documented in 2021, is a phishing attack utilizing an email resembling a payment notification or subscription confirmation to security software, computer support, streaming platforms, and other well-known brands.
![Major Cyber Attack Paralyzes Kyivstar - Ukraine's Largest Telecom Operator](/static/build/img/news/major-cyber-attack-paralyzes-kyivstar-ukraine-s-largest-telecom-operator-small.jpg)
Ukraine's biggest telecom operator Kyivstar has become the victim of a cyber attack, disrupting customer access to mobile and internet services. "The cyberattack on Ukraine's #Kyivstar telecoms...