Category: Information Security
Ordinary mergers and acquisitions are unexpectedly becoming a convenient point of entry for extortionists: operators of the Akira ransomware are infiltrating the networks of large companies through vulnerable SonicWall appliances inherited along with the...
The FBI has reported a surge in fraudulent schemes involving the takeover of financial accounts and warned that such attacks may intensify as the holiday shopping season approaches. According to the agency, more than...
Cybercriminals no longer need to coax ChatGPT or Claude Code into assisting with malware development or data-theft scripts. A whole class of specialized language models now exists expressly for offensive operations. One such system...
Malicious activity has once again surged within the npm ecosystem. This time, it is the second wave of the Shai-Hulud attack—an operation that mirrors the logic of the September campaign but unfolds with far...
Amazon has begun revealing details of its internal Autonomous Threat Analysis system, created to accelerate vulnerability detection and the development of defensive measures. Confronted with an ever-growing codebase and increasingly sophisticated attack techniques, the...
Superbox drew consumer attention with promises of access to more than 2,200 television channels and streaming services without a subscription, all for a one-time payment of roughly $400. Yet an examination of the device...
Fake Windows updates have entered a new cycle of ClickFix campaigns, according to researchers at Huntress. Attackers are increasingly replacing bot-check pages with full-screen blue windows that perfectly mimic the Windows update interface. As...
The U.S. Federal Cybersecurity Agency has issued a warning about a surge in targeted attacks involving commercial surveillance tools and remote-access software. Threat actors have increasingly focused on users of popular messaging platforms, seeking...
A recent incident involving malicious files in the 3D-graphics ecosystem has revealed how vulnerable even familiar tools can become when used alongside automated features. On popular model-sharing platforms, attackers have begun uploading Blender projects...
The escalating saga surrounding the Salesforce ecosystem data breach has taken a new turn after the group ShinyHunters publicly claimed responsibility for its role in the incident. The events, unfolding over several months, have...
A recently patched vulnerability in Microsoft’s Windows Server Update Services has triggered a wave of attacks involving one of the most notable espionage tools of recent years. The incidents underscore how swiftly adversaries move...
A new scheme for distributing malicious links through browser push notifications is rapidly gaining traction and drawing the attention of security specialists. It is built upon the Matrix Push C2 platform, designed to covertly...