Information Security News Blog
SonicWall has recorded thousands of daily attempts to exploit zero-day vulnerabilities in Apache OFBiz over nearly two weeks. The flaw was first publicized on December 26, leading to a significant increase in exploitation attempts....
Over the past 11 months, an active campaign has been underway to disseminate the malicious software AsyncRAT, targeting selective objectives. This campaign employs hundreds of unique loaders and over 100 domains. AsyncRAT is an...
A new cyber-espionage campaign is currently unfolding in the Netherlands, targeting telecommunication companies, internet service providers, IT services, and Kurdish websites. The campaign is attributed to the group known as Sea Turtle, which is...
Unknown cybercriminals hacked the official Netgear and Hyundai MEA accounts on X, which boast over 160,000 followers. The objective of the attack was to disseminate fraudulent schemes aimed at infecting victims with malware designed...
In a collaborative investigation by 404 Media and the independent analytical center Court Watch, a massive cyber-fraud scheme was uncovered, affecting over 500 users of the cryptocurrency exchange Coinbase, with losses exceeding $20 million....
Researchers have calculated that nearly 11 million SSH servers on the internet are vulnerable to Terrapin attacks, which allow data manipulation during the handshake process, ultimately compromising the integrity of the SSH channel when...
Due to restricted access to international financial markets, Iran has actively embraced cryptocurrency. Last year, Iranian cryptocurrency exchanges conducted transactions totaling nearly $3 billion. Almost all incoming cryptocurrency in Iran complies with Know Your...
The ShadowServer platform daily uncovers hundreds of IP addresses scanning or attempting to exploit Apache RocketMQ services vulnerable to Remote Code Execution (RCE), identified as CVE-2023-33246 and CVE-2023-37582. Both vulnerabilities are critical and pertain...
The United States Attorney’s Office heralded the culmination of an extensive international cybercrime investigation, targeting the nefarious activities of the darknet marketplace, xDedic. Judicial documents revealed that xDedic illegally sold access credentials to servers...
The cryptocurrency payment gateway CoinsPaid has encountered its second cyberattack in the last six months. According to the Web3 security firm Cyvers, unauthorized transactions amounting to approximately 7.5 million dollars were detected. On January...
QNAP Systems published security advisories for 15 vulnerabilities, each posing a unique challenge to the integrity of their systems. From OS command injections to SQL injections, each flaw uncovered in their operating systems and...
In 2020, Red Hat (acquired by IBM in 2019) unilaterally announced the termination of CentOS Linux’s development. Consequently, updates for the CentOS Linux 8 series concluded in December 2021, and updates for the CentOS...