Massive DDoS attack disrupts Norway’s government digital services

Norway’s Government Digital Services Brought Down by Massive DDoS Attack A massive distributed denial-of-service (DDoS) attack has struck Norway’s shared government digital infrastructure, disrupting services used by the public sector. The attack started on Monday at 03:38 CEST and targeted the infrastructure supporting various government services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and … Read more

Frontier AI: Vulnerability Management’s Systemic Revolution

A groundbreaking vulnerability management system has been unveiled, one that promises to revolutionize the way organizations protect themselves from cyber threats. At its core is a novel approach to mapping out potential attack paths, leveraging AI-driven identity exposure analysis to pinpoint vulnerabilities and sever breach routes at strategic choke points. Frontier AI’s innovative system has … Read more

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Cybersecurity Researchers Expose Sophisticated FTP Banner Exploitation Technique A sophisticated threat actor has been using a novel technique to turn seemingly innocuous File Transfer Protocol (FTP) banners into covert channels for malware commands, exposing thousands of organizations worldwide to potential attacks. The revelation highlights the dangers of underestimating even the most mundane aspects of network … Read more

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

The US government has taken a significant step in combating state-sponsored cyber threats, imposing sanctions on Iranian-linked hackers believed to be behind several high-profile breaches targeting critical infrastructure. The move aims to disrupt and deter these actors from carrying out further attacks that could have devastating consequences for national security and the global economy. At … Read more

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Malware Spreads Through npm Packages, Targeting Cloudflare Users A disturbing trend has emerged in the world of cybersecurity, as hackers have exploited a vulnerability in the popular package manager npm to spread malware through 24 compromised packages. The malicious code uses a clever trick to impersonate Cloudflare’s CAPTCHA pages, potentially putting thousands of users at … Read more

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A massive wave of attacks, dubbed “Mirage2FA,” has struck over 4,500 companies in the US and EU, compromising sensitive login credentials and leaving a trail of exposed identities in its wake. The campaign’s operators have leveraged a clever manipulation of Microsoft 365 login flows to bypass multi-factor authentication (MFA) protections, allowing them to gain unauthorized … Read more

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Cybersecurity researchers have uncovered a critical flaw in the Marimo Notebook app that could allow attackers to execute malicious commands on users’ devices even when they are editing sensitive files. The vulnerability, which affects both Android and iOS versions of the app, highlights the importance of prioritizing security in popular productivity tools. The issue arises … Read more

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Cybersecurity giants WhatsApp have rolled out a significant update to its mobile app, introducing multiple passkeys for phishing-resistant sign-ins on both iOS and Android devices. This move comes as part of an ongoing effort to protect users from increasingly sophisticated cyber threats. The new feature allows users to generate and store multiple passkeys – essentially … Read more

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A malicious webpage can secretly feed fake data into local AI models, compromising their accuracy and potentially leading to catastrophic consequences. This alarming vulnerability affects any system running NVIDIA’s NemoClaw framework, which is used in various applications, including healthcare, finance, and autonomous vehicles. The attack works by manipulating a user’s browser into submitting malicious input … Read more

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

A Wave of Phishing Attacks Exploits npm Package Vulnerability, Putting Users’ Data at Risk A concerning trend has emerged in the cybersecurity landscape, as hackers are exploiting a vulnerability in the npm package ecosystem to host fake Cloudflare CAPTCHA pages on unpkg mirrors. This clever tactic is designed to bypass security measures and trick users … Read more