Information Security News Blog

Diagram demonstrating the parallel threat activity of Storm-2603 and a second hacker group within a single corporate network 0

Uncovering Parallel Threat Activity: A Dual Intrusion

A recent ransomware investigation by Microsoft yielded an astonishing revelation. Two entirely distinct and unassociated hacking syndicates were operating concurrently within the victim organization’s network. The primary group entrenched itself within the infrastructure, meticulously...

Diagram illustrating the Klue supply chain breach and compromised Salesforce OAuth tokens 0

Klue Supply Chain Breach Compromises LastPass Data

Target/Victims: Klue, LastPass, and others. Delivery Vector: Compromised integration service credentials from 2022. Key Capabilities: Unauthorized Salesforce CRM access via stolen OAuth tokens. Threat Actor: Icarus ransomware group (Suspected). Source: Klue, LastPass, and affected...

Diagram illustrating the Squidbleed vulnerability and memory leakage in Squid proxy servers 0

Squidbleed Vulnerability Exposes Legacy Proxies

A critical flaw within the File Transfer Protocol (FTP) implementation an antiquated mechanism for transmitting data between computers has resided in the Squid proxy server for nearly 29 years. This severe defect enables unauthorized...