Security News

Russian ISP confirms Ukrainian hackers "destroyed" its network
2025-01-08 19:26

Russian internet service provider Nodex confirmed on Tuesday that its network was "destroyed" in a cyberattack claimed by Ukrainian hacktivists part of the Ukrainian Cyber Alliance [...]

New EAGERBEE Variant Targets ISPs and Governments with Advanced Backdoor Capabilities
2025-01-07 09:46

Internet service providers (ISPs) and governmental entities in the Middle East have been targeted using an updated variant of the EAGERBEE malware framework. The new variant of EAGERBEE (aka...

Eagerbee backdoor deployed against Middle Eastern govt orgs, ISPs
2025-01-06 14:54

New variants of the Eagerbee malware framework are being deployed against government organizations and internet service providers (ISPs) in the Middle East. [...]

Free, France’s second largest ISP, confirms data breach after leak
2024-10-28 17:45

Free, a major internet service provider (ISP) in France, confirmed over the weekend that hackers breached its systems and stole customer personal information. [...]

China's Salt Typhoon cyber spies are deep inside US ISPs
2024-09-25 21:46

Expecting a longer storm season this year? Another Beijing-linked cyberspy crew, this one dubbed Salt Typhoon, has reportedly been spotted on networks belonging to US internet service providers in...

Volt Typhoon Hackers Exploit Zero-Day Vulnerability in Versa Director Servers Used by MSPs, ISPs
2024-08-29 15:17

There are approximately 163 devices worldwide that are still exposed to attack via the CVE-2024-39717 vulnerability.

Versa Director zero-day exploited to compromise ISPs, MSPs (CVE-2024-39717)
2024-08-27 15:47

Advanced, persistent attackers have exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director to compromise US-based managed service providers with a custom-made web shell dubbed...

Chinese Volt Typhoon hackers exploited Versa zero-day to breach ISPs, MSPs
2024-08-27 14:00

The Chinese state-backed hacking group Volt Typhoon is behind attacks that exploited a zero-day flaw in Versa Director to upload a custom webshell to steal credentials and breach corporate networks. [...]

StormBamboo Compromises ISP, Spreads Malware
2024-08-09 13:42

New research from cybersecurity company Volexity revealed details about a highly sophisticated attack deployed by a Chinese-speaking cyberespionage threat actor named StormBamboo. StormBamboo compromised an ISP to modify some DNS answers to queries from systems requesting legitimate software updates.

Chinese hackers compromised an ISP to deliver malicious software updates
2024-08-05 10:46

APT StormBamboo compromised a undisclosed internet service provider to poison DNS queries and thus deliver malware to target organizations, Volexity researchers have shared. In April 2023, ESET researchers documented the threat actor targeting an international NGO in China with malicious updates, but weren't able to pinpoint whether these updates were delivered through supply-chain compromise or adversary-in-the-middle attacks.