Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

A devastating series of open-source software supply chain attacks has been linked by Amazon to North Korean hackers, who exploited vulnerabilities in widely used packages on the Node Package Manager (npm) ecosystem. The cloud computing giant has attributed multiple high-profile compromises, including those affecting popular libraries like Debug, Chalk, and Axios, to a single threat … Read more

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A wave of AI-powered hacking tools has recently been discovered, putting millions of organizations at risk of software vulnerability exploitation. Meanwhile, Google Chrome users are facing a staggering 370 known vulnerabilities, while SonicWall security appliances have been compromised in a targeted attack. To make matters worse, DNS hijacking is on the rise, threatening the integrity … Read more

Read This Before You Buy That TV Streaming Stick

Cybersecurity experts have been warning about the risks of generic TV boxes for years. These devices promise unlimited content streaming for a one-time fee, but secretly rent out users’ Internet connections to strangers. Now, a groundbreaking new analysis has uncovered another alarming threat. Not only do these devices rent out your connection, but they also … Read more

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat Actors Use Microsoft Teams Calls to Deliver Chaos Ransomware, Compromise Dozens of Organizations in North America A sophisticated cyber threat campaign has been unfolding in North America, with threat actors impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy the highly destructive Chaos ransomware. The attacks, … Read more

The Network Has Become the Control Plane for AI Security

Cybersecurity teams are facing a daunting new threat: AI-powered attacks that exploit vulnerabilities discovered by artificial intelligence models themselves. In what’s being hailed as a paradigm shift, networks have become the de facto control plane for AI security, with these intelligent systems probing and exploiting weaknesses in software. This development has left many organizations scrambling … Read more

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A critical vulnerability in Azure Cosmos DB, a popular cloud-based database service provided by Microsoft, has been disclosed, allowing potential attackers to access any database on the platform using a single, hardcoded key. This flaw, discovered by cybersecurity researchers, exposes millions of organizations and individuals who rely on Azure Cosmos DB for their online data … Read more

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

As hackers increasingly turn to artificial intelligence (AI) to discover and exploit software vulnerabilities, organizations must adapt their defenses to stay ahead of this emerging threat. The latest development in AI-powered hacking involves sophisticated models that can identify previously unknown weaknesses in complex software systems, rendering traditional patching methods ineffective. One of the most significant … Read more

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

A sophisticated cyberattack, dubbed SilverFox, has compromised a major Japanese manufacturer’s network using a novel combination of attack techniques. The attackers exploited a three-stage “Bring Your Own Vulnerability” (BYOVD) chain and deployed the notorious ValleyRAT malware to gain unauthorized access to sensitive data. At the center of the attack is an AI-powered vulnerability discovery tool, … Read more

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

A series of compromised Korean websites is serving up malware-laced downloads that install backdoors on unsuspecting users’ computers, all thanks to a vulnerability in a popular software tool called AnySign4PC. The hacking campaign, which appears to be ongoing, has already caught the attention of cybersecurity experts who warn that anyone visiting these hacked sites risks … Read more