Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Cybersecurity threats have taken a new turn, with ransomware groups exploiting vulnerabilities in Citrix software, using Bring Your Own Vulnerable Dependencies (BYOVD), and leveraging supply chain credentials to gain access to networks. The rise of these tactics highlights the need for organizations to reassess their security strategies and focus on proactive measures to prevent attacks. … Read more

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI has dealt a significant blow to the cybercrime community with the seizure of hundreds of domains associated with NetNut, a residential proxy service operated by Alarum Technologies. This move comes after multiple security firms revealed that NetNut was linked to the Popa botnet, a collection of at least two million compromised devices used … Read more

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Cyberattackers have developed a new tactic that allows them to hijack Microsoft 365 accounts in as little as three seconds, using a technique called ConsentFix. This method exploits the trust users place in legitimate-looking authentication screens, making it difficult for even the most vigilant individuals to detect. The attack begins with a phishing lure sent … Read more

Google loses final appeal to overturn €4.1 billion EU fine

A landmark antitrust ruling has dealt a significant blow to Google’s business practices, with the Court of Justice of the European Union (CJEU) upholding a €4.1 billion fine levied against the tech giant in 2018. The case centers on Google’s use of its Android operating system to promote its own products and services, specifically Chrome … Read more

Identity Lifecycle Management Wasn’t Built for AI Agents

Cybersecurity teams are scrambling to address a critical vulnerability exposed by artificial intelligence (AI) models, highlighting a glaring oversight in identity lifecycle management systems. These systems, designed to grant and revoke access to sensitive resources based on user identities, were not built with AI agents in mind. As a result, organizations worldwide are at risk … Read more

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

A New Wave of Malware Exploits OAuth Vulnerability to Infiltrate Gmail Accounts via Google API A sophisticated malware campaign linked to the ToddyCat threat group has been uncovered, leveraging a previously unknown vulnerability in Google’s OAuth authentication system to gain unauthorized access to Gmail accounts. This alarming development highlights the ongoing cat-and-mouse game between cybercriminals … Read more

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Microsoft 365 Accounts Hijacked in 3 Seconds: The Stealthy Threat of ConsentFix and ClickFix Attacks In a chilling example of modern cybercrime, threat actors are exploiting everyday online habits to hijack Microsoft 365 accounts in just three seconds. This brazen tactic involves manipulating users into surrendering OAuth tokens, granting attackers session access to email and … Read more

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

Cybersecurity experts have recently sounded the alarm about a new and insidious threat, one that could potentially compromise even the most secure systems. It starts with artificial intelligence (AI) models being used to detect software vulnerabilities, but with a twist: these AI models are also being exploited by malicious actors to hijack compute resources. The … Read more

Google loses final appeal to overturn €4.1 billion EU fine

The European Union has reaffirmed its stance on Google’s business practices, dismissing the company’s final appeal against a €4.1 billion antitrust fine. This decision is a significant blow to Google, as it confirms that the tech giant abused its dominant market position by promoting its Chrome browser and search service through Android agreements. At the … Read more