Microsoft detailed how Russian espionage group Secret Blizzard is leveraging infrastructure of other threat actors to target the Ukrainian military with custom malware
Fraudsters in UAE posed as Dubai Police, targeting citizens with fake fines via calls, emails and SMS
Ruby Central hired Trail of Bits to complete a security assessment and a competitive analysis of RubyGems.org, the official package management system for Ruby applications. With over 184+ billion downloads to date, RubyGems.org is critical infrastructure for the Ruby language ecosystem. This is a jo...
Krispy Kreme said the incident is likely to materially affect operations and short-term financial performance
The Korean Financial Security Institute (K-FSI) disrupted a fraudulent network that made $6.3m by stealing money from fake personal trading platforms
Author: Guus Beckers Back in 2022 Fox-IT decided to open source its proprietary incident response tooling known as Dissect. Since then it has been adopted by many different companies in their regular workflow. For those of you who are not yet familiar with Dissect, it is an incident response framewo...
Microsoft MFA flaw exposed that allowed attackers to bypass security within an hour, putting 400m Office 365 accounts at risk
Operation PowerOFF has dismantled a network of 27 DDoS platforms, leading to the arrests of three administrators and the identification of over 300 users
Author: Guus Beckers Back in 2022 Fox-IT decided to open source its proprietary incident response tooling known as Dissect. Since then it has been adopted by many different companies in their regular workflow. For those of you who are not yet familiar with Dissect, it is an incident response framewo...
The US government has sanctioned Sichuan Silence and one of its employees for the mass compromise of firewalls which led to the deployment of malware and ransomware
Microsoft has patched dozens of vulnerabilities in December, including one zero-day being exploited in the wild
Author: Guus Beckers Back in 2022 Fox-IT decided to open source its proprietary incident response tooling known as Dissect. Since then it has been adopted by many different companies in their regular workflow. For those of you who are not yet familiar with Dissect, it is an incident response framewo...
A zero-day vulnerability in Cleo file transfer software is being exploited in data theft attacks
The multi-cloud data warehousing platform said it will completely phase out single factor authentication with passwords by November 2025
A cloud attack targeting Amazon SES, persistence, and a malicious AWS account ID.
La chaîne de supermarchés Avril a été victime d'une cyberattaque dans la nuit du 11 au 12 décembre, ce qui a entraîné des perturbations dans les opérations de ses magasins. Les employés doivent actuellement entrer les codes des produits à la main et certaines caisses sont fermées, mais les supermarc...
La société finlandaise Valio a été victime d'une cyberattaque qui a compromis les données personnelles de plus de 5 000 employés et membres du personnel, notamment des informations d'identité, des détails de salaire et des informations bancaires. L'attaque a été menée via les informations d'accès d'...
Posted by Greg Mucci, Product Manager, Artifact Analysis, Oliver Chang, Senior Staff Engineering, OSV, and Charl de Nysschen, Product Manager OSVDevOps teams dedicated to securing their supply chain and predicting potential risks consistently face novel threats. Fortunately, they can now improve the...
Le groupe de prêt hypothécaire Mortgage Investors Group (MIG) basé au Tennessee a confirmé avoir été victime d'une cyberattaque en décembre, exposant des informations personnelles et financières de nombreux clients. L'attaque, revendiquée par le groupe de ransomware Black Basta, a commencé le 11 déc...
Le 11 décembre 2024, la Potomac and Rappahannock Transportation Commission a découvert qu’elle avait été victime d’une attaque par rançongiciel. L’équipe dirigeante, le service informatique et des experts en cybersécurité ont immédiatement lancé une enquête, sécurisé les données personnelles et prot...