The pentester's Swiss knife

Cuttlefish

Cuttlefish Malware Infects Routers, Steals Data

A new type of malware named “Cuttlefish” has been discovered in routers within major enterprises and small offices, monitoring all information passing through the infected devices and stealing credentials. Black Lotus Labs reports that...

Brazil Bank Hack ICC Cyberattack CVE-2024-21410

Finnish Hacker Faces Justice for Vastaamo Attack

Aleksanteri Kivimäki, a 26-year-old hacker, has been sentenced to six years’ imprisonment. Local media reported this, citing a court decision related to the breach of the private psychotherapeutic center Vastaamo in Helsinki. The court...

Android vulnerability rewards

Google Pays $450k for Android Vulnerabilities

Google has substantially increased the rewards for reporting vulnerabilities that allow successful remote code execution (RCE) in Android applications, raising the maximum cash payout for exceptional reports to $450,000. The updates pertain to the...

FBI monitor facebook

Ex-NSA Employee Gets 22 Years for Espionage

A former NSA employee has been sentenced to 21 years and 10 months in prison for attempting espionage on behalf of a foreign state. FBI Director Christopher Wray stated that this sentence should serve...

Wpeeper backdoor

Wpeeper Android Backdoor Hides Behind Hacked Websites

Specialists at QAX XLab have identified a new type of Android malware—a backdoor named Wpeeper, which is disseminated through APK files from unofficial app stores posing as the popular alternative marketplace Uptodown. Wpeeper is...

malware repositories

Docker Hub Under Siege: Millions of Repos Harbor Malware

Over the past several years, Docker Hub, a platform for hosting software repositories, has been targeted by three major fraudulent campaigns. Researchers from JFrog identified that approximately 20% of the 15 million hosted repositories...

Lorenz Group

Cybersecurity Breach Forces London Drugs Closures

The Canadian pharmacy chain London Drugs has closed all its retail stores following the discovery of a cybersecurity incident. The event, which affected the company’s systems, occurred on April 28. In response, the company...

CVE-2024-27322

High-Severity R Flaw (CVE-2024-27322) Puts Users at Risk

A critical vulnerability has been discovered in the R programming language, potentially exposing organizations using this popular open-source language to software supply chain attacks. The vulnerability, designated CVE-2024-27322, has been rated 8.8 out of...