Security News

Unpatched AVTECH IP Camera Flaw Exploited by Hackers for Botnet Attacks
2024-08-29 11:05

A years-old high-severity flaw impacting AVTECH IP cameras has been weaponized by malicious actors as a zero-day to rope them into a botnet. CVE-2024-7029 (CVSS score: 8.7), the vulnerability in...

South Korean hackers exploited WPS Office zero-day to deploy malware
2024-08-28 22:50

The South Korea-aligned cyberespionage group APT-C-60 has been leveraging a zero-day code execution vulnerability in the Windows version of WPS Office to install the SpyGlace backdoor on East...

US offers $2.5 million reward for hacker linked to Angler Exploit Kit
2024-08-28 21:12

The U.S. Department of State and the Secret Service have announced a reward of $2,500,000 for information leading to Belarusian national Volodymyr Kadariya (Владимир Кадария) for cybercrime...

Iranian hackers work with ransomware gangs to extort breached orgs
2024-08-28 17:22

An Iran-based hacking group known as Pioneer Kitten is breaching defense, education, finance, and healthcare organizations across the United States and working with affiliates of several...

Pioneer Kitten: Iranian hackers partnering with ransomware affiliates
2024-08-28 16:43

A group of Iranian hackers – dubbed Pioneer Kitten by cybersecurity researchers – is straddling the line between state-contracted cyber espionage group and initial access provider (and partner in...

Chinese Volt Typhoon hackers exploited Versa zero-day to breach ISPs, MSPs
2024-08-27 14:00

The Chinese state-backed hacking group Volt Typhoon is behind attacks that exploited a zero-day flaw in Versa Director to upload a custom webshell to steal credentials and breach corporate networks. [...]

Meta Exposes Iranian Hacker Group Targeting Global Political Figures on WhatsApp
2024-08-24 06:55

Meta Platforms on Friday became the latest company after Microsoft, Google, and OpenAI to expose the activities of an Iranian state-sponsored threat actor, who it said used a set of WhatsApp...

Hackers now use AppDomain Injection to drop CobaltStrike beacons
2024-08-23 16:31

A wave of attacks that started in July 2024 rely on a less common technique called AppDomain Manager Injection, which can weaponize any Microsoft .NET application on Windows. [...]

Russian laundering millions for Lazarus hackers arrested in Argentina
2024-08-23 13:59

The federal police in Argentina (PFA) have arrested a 29-year-old Russian national in Buenos Aires, who is facing money laundering charges related to cryptocurrency proceeds of the notorious North...

Latvian Hacker Extradited to U.S. for Role in Karakurt Cybercrime Group
2024-08-23 04:38

A 33-year-old Latvian national living in Moscow, Russia, has been charged in the U.S. for allegedly stealing data, extorting victims, and laundering ransom payments since August 2021. Deniss...