Security News

M&S takes systems offline as 'cyber incident' lingers
2025-04-24 10:18

Customers told to expect further delays as contactless payments still down UK high street retailer Marks & Spencer says contactless payments are still down following its "cyber incident" and order...

Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
2025-04-21 16:42

Cybersecurity researchers have flagged a new malicious campaign related to the North Korean state-sponsored threat actor known as Kimsuky that exploits a now-patched vulnerability impacting...

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems
2025-04-19 15:11

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities....

Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
2025-04-15 14:06

The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect...

Hackers lurked in Treasury OCC’s systems since June 2023 breach
2025-04-08 17:29

Unknown attackers who breached the Treasury's Office of the Comptroller of the Currency (OCC) in June 2023 gained access to over 150,000 emails. [...]

CERT-UA Reports Cyberattacks Targeting Ukrainian State Systems with WRECKSTEEL Malware
2025-04-04 04:54

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that no less than three cyber attacks were recorded against state administration bodies and critical infrastructure...

FIN7 Deploys Anubis Backdoor to Hijack Windows Systems via Compromised SharePoint Sites
2025-04-02 06:52

The financially motivated threat actor known as FIN7 has been linked to a Python-based backdoor called Anubis (not to be confused with an Android banking trojan of the same name) that can grant...

Researchers Uncover 46 Critical Flaws in Solar Power Systems From Sungrow, Growatt, and SMA
2025-03-28 13:21

Cybersecurity researchers have disclosed 46 new security flaws in products from three solar power system vendors, Sungrow, Growatt, and SMA, that could be exploited by a bad actor to seize control...

NetApp SnapCenter Flaw Could Let Users Gain Remote Admin Access on Plug-In Systems
2025-03-27 06:06

A critical security flaw has been disclosed in NetApp SnapCenter that, if successfully exploited, could allow privilege escalation. SnapCenter is an enterprise-focused software that's used to...

EncryptHub linked to MMC zero-day attacks on Windows systems
2025-03-25 16:51

A threat actor known as EncryptHub has been linked to Windows zero-day attacks exploiting a Microsoft Management Console vulnerability patched this month. [...]