Outdated Cybercrime Laws Put Security Researchers at Risk

Cybersecurity Researchers Face Prison Time Due to Outdated Laws A growing concern in the cybersecurity community is the outdated laws that put security researchers at risk. In some countries, including the United Kingdom, security researchers who responsibly disclose vulnerabilities can face imprisonment or fines under laws that don’t differentiate between malicious hackers and those working … Read more

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains that were previously reserved for nation-state actors have suddenly and alarmingly spread to organized cybercrime groups around the globe. The complex malware frameworks, known as Coruna and DarkSword, are being used by a wide range of malicious actors, from advanced persistent threat (APT) groups to run-of-the-mill hackers. According to research firm … Read more

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

Cybersecurity teams are facing a daunting challenge in the form of a “patch gap,” where attackers are increasingly exploiting vulnerabilities before patches are even available, leaving defenders scrambling to keep up. This issue is not just about patching faster or prioritizing high-severity vulnerabilities, but rather about fundamentally changing how we approach vulnerability management. The recent … Read more

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A Zero-Day SQL Injection Vulnerability in Metabase Cloud Threatens Widespread Consequences A critical vulnerability has been discovered in Metabase Cloud, a business analytics platform used by numerous organizations worldwide. The zero-day SQL injection flaw allows attackers to gain remote administrator access to affected instances, compromising sensitive data and potentially leading to further attacks on downstream … Read more

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains once limited to nation-states are spreading rapidly to organized cybercrime groups, posing a significant threat to global security. Two advanced iOS exploit chains, Coruna and DarkSword, have been making headlines in recent months due to their complex nature and widespread adoption. Initially used by nation-state actors and commercial surveillance vendors, these … Read more

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

The Patch Gap: Why Traditional Vulnerability Management Won’t Cut It in Today’s Threat Landscape Imagine being told that, on average, it takes just four hours for attackers to exploit a newly discovered vulnerability after it’s publicly disclosed. Sounds alarming? That’s exactly what’s happening right now. The rate at which vulnerabilities are being exploited has increased … Read more

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A critical zero-day vulnerability has been discovered in the Metabase Cloud business-analytics platform, allowing malicious attackers to gain remote administrator access and potentially compromise downstream organizations. The maximum-severity flaw, which has not yet been assigned a CVE identifier, affects versions 1.58 of the platform and above. According to an advisory posted on GitHub by Metabase, … Read more

Multistate Water System Attacks Widen, Iran Suspected

Cyberattacks on US Water Systems Continue to Spread, with Iran Suspected as Culprit A wave of cyberattacks targeting water and wastewater systems has been sweeping across the United States, leaving a trail of vulnerable industrial controllers in its wake. At least a dozen states have reported attacks, with the latest victims including Alabama and New … Read more

Hackers breached a small Polish energy plant via private APN last year

A Second Polish Energy Plant Falls Victim to Sophisticated Cyber Attackers, Exposing a Novel Attack Path Last year’s devastating cyber attacks on Poland’s energy sector have revealed an alarming new threat vector. A small combined heat-and-power (CHP) plant in Poland was compromised by hackers who exploited a private Access Point Name (APN) network, demonstrating a … Read more

Multistate Water System Attacks Widen, Iran Suspected

Cyberattacks on US Water Systems Widen, with Iran Suspected Behind the Threats A growing number of states across the US have fallen victim to a wave of cyberattacks targeting their water and wastewater systems. The attacks, which have been linked to Iranian threat actors, have exposed weaknesses in the country’s critical infrastructure, leaving experts warning … Read more