Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift

Russian-backed hackers have been busy updating their arsenal of malware tools, with a particular focus on refining a sophisticated downloader known as MatchBoil. This malware strain has been used in a series of targeted attacks against Ukrainian organizations across various industries, including transportation, manufacturing, and energy. The group behind these attacks, tracked by security researchers … Read more

Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting

A notorious cybercrime leader from Venezuela’s Tren de Aragua cartel has been arrested and arraigned by US authorities for his role in a massive “jackpotting” scheme that compromised ATMs with malware and dispensed tens of thousands of dollars in cash. Anibal Alexander Canelon Aguirre, also known as “Prometheus” and “The Engineer,” is the first cybercriminal … Read more

‘AgentCorruption’ Puts AWS Environments At Risk With Single Prompt

A newly patched vulnerability in AWS Bedrock AgentCore has left organizations with a potentially devastating cybersecurity risk. Dubbed “AgentCorruption,” this flaw allows an attacker to use just one AI chatbot to take control of an entire fleet of agents within an AWS environment, effectively gaining access to sensitive data and wreaking havoc on the organization’s … Read more

Owner of Empire cybercrime market gets 40 years in prison

Raheim Hamilton, the co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been handed a 40-year prison sentence for facilitating over $430 million in illicit transactions between 2018 and 2020. The massive online black market was notorious for selling everything from counterfeit currency to stolen account credentials, computer hacking … Read more

OAuth grants pile up faster than you can review them. Here’s how to keep up.

As IT teams struggle to keep up with the ever-growing number of OAuth grants, a ticking time bomb is quietly accumulating in many organizations’ security profiles. Every day, employees click “Allow” on consent screens, creating new trust relationships between apps that can access corporate data. While these decisions take mere seconds, reviewing them properly requires … Read more

Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift

Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift A sophisticated malware downloader, dubbed “MatchBoil,” has been given a significant makeover by a likely Russia-affiliated cyber-espionage group. The malware, used in campaigns targeting Ukrainian organizations across the transportation, manufacturing, and energy sectors, now boasts stronger obfuscation, sandbox checks, and evolving persistence mechanisms. UAC-0099, the threat actor … Read more

Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting

Venezuelan Cartel’s Malware Expert Brought Down for ATM Heists In a significant blow to transnational cybercrime, US authorities have arrested and arraigned Anibal Alexander Canelon Aguirre, a 50-year-old Venezuelan member of the notorious Tren de Aragua (TdA) cartel. Canelon Aguirre is accused of masterminding a sophisticated “jackpotting” scheme that compromised ATMs with malware, causing them … Read more

‘AgentCorruption’ Puts AWS Environments At Risk With Single Prompt

AWS Environments Left Exposed by AI-Driven Vulnerability A recently patched vulnerability in Amazon Web Services’ (AWS) Bedrock AgentCore has left organizations using the platform at risk of a full-scale takeover. Researchers from Zenity Labs discovered that an attacker could use a single prompt to a public-facing chatbot to gain control over an entire fleet of … Read more

FakeGit malware campaign returns with 17,610 malicious GitHub repos

The FakeGit malware campaign has made a comeback, with over 17,610 malicious repositories on GitHub distributing the SmartLoader malware. This resurgence marks a significant increase in activity, with the operators pushing out nearly 13,000 new repos in just 34 hours. Researchers at Apiiro, a software supply-chain security platform, have been tracking this operation and report … Read more

FBI disrupts Chinese hacking tools used to breach critical infrastructure

FBI Disrupts Chinese Hacking Tools Used to Breach Critical Infrastructure Worldwide The Federal Bureau of Investigation (FBI) has made a significant breakthrough in disrupting two Chinese state-sponsored hacking tools used to breach critical infrastructure and organizations globally. The FBI seized seven domains, including those supporting the MicroScan and FishHub platforms, allegedly operated by China-based Integrity … Read more