Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

A Nine-Year Long Con: Russian Company Sites Cloned to Steal Advance Payments from Unsuspecting Victims A staggering nine-year-long cybercrime campaign has been exposed, where hackers have been cloning websites of legitimate Russian companies to trick unsuspecting victims into making advance payments. The brazen scheme, which has been ongoing since 2017, has resulted in significant financial … Read more

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

A massive coordinated cyberattack has brought down multiple water treatment plants and systems across Minnesota, highlighting the alarming vulnerability of critical infrastructure to cyber threats. The attack, which is still unfolding, has affected at least 32 water facilities, with one major plant forced offline due to a deliberate disruption of its operations. The targeted systems … Read more

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

A trio of critical vulnerabilities in VMware’s popular virtualization software has left thousands of organizations vulnerable to cyber attacks, allowing hackers to bypass authentication, execute malicious code, and even escape from virtual machines. VMware is a widely-used platform for creating and managing virtual environments, which allows multiple operating systems to run on a single physical … Read more

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A Critical Flaw in Ruflo MCP Exposes Systems to Unauthenticated Attacks A severe security vulnerability has been discovered in the Ruflo Microprocessor Control Protocol (MCP), a low-level communication interface used by various industrial control systems and IoT devices. The flaw, which allows unauthenticated attackers to run arbitrary commands and even poison AI memory, poses a … Read more

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

A Critical Flaw in Ruby on Rails Puts Millions of Websites at Risk of Unauthenticated Data Exposure A severe vulnerability in the popular web application framework Ruby on Rails could allow attackers to bypass authentication and read sensitive server files, potentially putting millions of websites at risk. The flaw, which affects versions 7.0.x and prior, … Read more

Mythos Asks the Right Question. It Doesn’t Answer It.

As of late, researchers have been experimenting with using artificial intelligence (AI) to identify software vulnerabilities that human experts might miss. A recent example comes from Mythos, a company that’s leveraging AI-powered tools to sniff out potential weaknesses in code. However, their latest exercise raises more questions than answers about the role of AI in … Read more

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

A Coordinated Cyberattack on Minnesota’s Water Systems Raises Alarms About National Security and Infrastructure Vulnerability In a shocking display of coordinated cyber aggression, hackers have successfully targeted over 30 water treatment plants across Minnesota, leaving one facility offline. This brazen attack serves as a stark reminder that our nation’s critical infrastructure is woefully unprepared for … Read more

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

A trio of critical vulnerabilities has been discovered in VMware’s widely-used virtualization software, allowing attackers to bypass authentication, execute arbitrary code, and even escape from virtual machines altogether. The flaws, identified by researchers at security firm RedLock, affect various versions of VMware vSphere, a platform used by millions of organizations worldwide. The vulnerabilities, which were … Read more

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A Critical Flaw in Ruflo MCP Exposes Systems to Remote Attacks and AI Manipulation A severe vulnerability has been discovered in Ruflo’s Machine-Check Point (MCP) software, allowing unauthenticated attackers to execute arbitrary commands and manipulate artificial intelligence (AI) memory. The issue affects numerous organizations that rely on Ruflo’s MCP for network security and monitoring. The … Read more