cybersecurity threats
-
State-Sponsored Attack Targets Southeast Asian Telecommunications
A state-sponsored hacking group, CL-STA-0969, has targeted Southeast Asian telecommunications networks, employing sophisticated tools to establish remote access while avoiding detection. The report highlights significant overlaps with other espionage groups and emphasizes the need for robust cybersecurity measures.
-
Storm-2603 Exploits SharePoint Vulnerabilities to Deploy Ransomware
A recent analysis reveals that Storm-2603, a suspected China-based threat actor, is exploiting Microsoft SharePoint vulnerabilities using a bespoke command-and-control framework, deploying ransomware like Warlock and LockBit.
-
China Accuses US of Cyberattacks Using Microsoft Zero-Day Vulnerability
China has alleged that U.S. intelligence agencies conducted cyberattacks on Chinese military enterprises, exploiting a Microsoft zero-day vulnerability. The accusations come amid heightened tensions and increasing allegations of cyber warfare between the two nations.
-
Experts Warn of New Phishing Threats Exploiting Link Wrapping Services
Cybersecurity experts have identified a new phishing campaign that exploits link wrapping services from leading vendors to conceal malicious links, significantly raising the risk of successful attacks. The tactics involve sophisticated methods of masking URLs, allowing threat actors to redirect victims to fraudulent pages designed to capture sensitive information.
-
Russian Espionage Group Targets Diplomats Through Innovative Malware
Microsoft has uncovered that Russian espionage group Secret Blizzard has been spying on foreign diplomats in Moscow since at least 2024, utilizing sophisticated malware and surveillance tactics to maintain access to sensitive communications.
-
New Encoding Attack Accelerates SS7 Vulnerabilities in Mobile Networks
Researchers have uncovered a new method that enables attackers to bypass SS7 protections through encoding manipulation, posing significant security risks to mobile networks. This technique has already been employed by a surveillance vendor to extract sensitive mobile subscriber location data.
-
Dollar Tree Hit by Major Data Breach, INC Ransomware Claims Responsibility
The INC Ransomware group claims to have stolen 1.2TB of sensitive data from Dollar Tree, raising serious cybersecurity concerns. The company denies any involvement and attributes the claims to data originating from 99 Cents Only Stores. The incident highlights the growing threat of ransomware attacks.
-
UNC2891 Breaches ATM Networks with Covert Raspberry Pi Attack
UNC2891, a financially motivated threat actor, has executed a covert attack on ATM networks by effectively utilizing a 4G-equipped Raspberry Pi to maintain unauthorized access, raising significant security concerns.
-
Critical Vulnerabilities Found in Dahua Smart Camera Firmware
Researchers have discovered serious vulnerabilities in Dahua smart camera firmware, allowing potential remote takeovers of these devices. Security experts warn of the risks associated with exposed devices and urge users to update their firmware.
-
Emerging Gunra Ransomware Expands Threat Landscape with New Linux Variant
The Gunra ransomware family has evolved with a new Linux variant featuring advanced encryption techniques that enable attackers to run multiple parallel encryptions. This development raises new security concerns and underscores a broader trend of ransomware groups expanding their cross-platform targeting capabilities.