Security News

Threat actors are using legitimate Microsoft feature to compromise M365 accounts
2025-02-14 14:16

Suspected Russian threat actors have been taking advantage of Microsoft Device Code Authentication to trick targets into granting them access to their Microsoft 365 (M365) accounts. “While Device...

Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys
2025-02-07 12:11

A ViewState code injection attack spotted by Microsoft threat researchers in December 2024 could be easily replicated by other attackers, the company warned. “In the course of investigating,...

China-aligned PlushDaemon APT compromises supply chain of Korean VPN
2025-01-22 06:00

ESET researchers have uncovered a supply chain attack targeting a South Korean VPN provider, carried out by PlushDaemon, a newly identified China-aligned APT group. In this cyberespionage...

US sanctions Chinese cybersecurity company for firewall compromise, ransomware attacks
2024-12-10 20:34

The Department of the Treasury is sanctioning Chinese cybersecurity company Sichuan Silence, and one of its employees, Guan Tianfeng, for their roles in the April 2020 compromise of tens of...

Solana’s popular web3.js library backdoored in supply chain compromise
2024-12-04 15:50

A software supply chain attack has lead to the publication of malicious versions of Solana’s web3.js library on the npm registry. Just like the recent Lottie Player supply chain compromise, this...

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise
2024-12-03 10:17

Cybersecurity researchers have disclosed a set of flaws impacting Palo Alto Networks and SonicWall virtual private network (VPN) clients that could be potentially exploited to gain remote code...

Overreliance on GenAI to develop software compromises security
2024-11-20 04:00

GenAI is quickly changing the software development process by automating tasks that once took developers hours, if not days, to complete, bolstering efficiency and productivity, according to Legit...

North Korean hackers employ new tactics to compromise crypto-related businesses
2024-11-07 11:47

North Korean hackers are targeting crypto-related businesses with phishing emails and novel macOS-specific malware. The crypto-related phishing campaign Since July 2024, phishing emails seemingly...

Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups
2024-10-31 12:35

A supply chain compromise involving Lottie Player, a widely used web component for playing site and app animations, has made popular decentralized finance apps show pop-ups urging users to connect...

Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks
2024-10-09 04:22

Microsoft is warning of cyber attack campaigns that abuse legitimate file hosting services such as SharePoint, OneDrive, and Dropbox that are widely used in enterprise environments as a defense...