Malicious sites use JavaScript to build malware in browser memory

A Sneaky Malware Campaign Exploits Browser Memory to Evade Detection Malicious websites are using a clever tactic to assemble malware directly in browser memory, evading detection and making it harder for security experts to analyze. The campaign, dubbed SourTrade, has been active since late 2024 and targets retail traders and crypto investors in Asia Pacific … Read more

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Fastjson, a popular Java library used for JSON parsing and serialization, has been hit with a critical Remote Code Execution (RCE) vulnerability that’s being actively exploited by attackers. The bug, which affects versions 1.x of Fastjson, allows hackers to inject malicious code on vulnerable systems, putting countless organizations at risk. Fastjson is widely used in … Read more

OpenAI confirms ChatGPT is down worldwide

A major outage has crippled access to ChatGPT worldwide, leaving users unable to load chats or send messages. The disruption, which began at around 5 AM ET, affected not only those in the US and Europe but also users across the globe. For nearly an hour, chat enthusiasts and developers were locked out of the … Read more

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

A Centralized Ransomware-as-a-Service (RaaS) Portal Puts Thousands at Risk of Devastating Cyberattacks A recent discovery has shed light on a sophisticated ransomware-as-a-service (RaaS) portal, codenamed “DevMan,” that’s been quietly wreaking havoc on unsuspecting victims. Dubbed the “Amazon of Ransomware” by cybersecurity experts, this centralized platform enables malicious actors to create, distribute, and manage their own … Read more

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p Gang’s Latest Tactic Exposes Companies Using PTC Windchill and FlexPLM Software A new wave of attacks has been spotted targeting organizations using software from PTC (Parametric Technology Corporation) – specifically, those running versions of PTC Windchill and FlexPLM that haven’t implemented the latest security patches. The Cl0p gang, a notorious group known for its … Read more

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

A New Wave of Account Hijacking Threats Loom Large, As Insurance Phishing Evolves into Real-Time Attacks Insurance phishing scams have been a persistent menace for individuals and businesses alike, preying on vulnerabilities in email security. However, researchers at CTM360 have uncovered a disturbing evolution in these tactics – from mere phishing attempts to real-time account … Read more

OpenAI confirms ChatGPT is down worldwide

ChatGPT Users Worldwide Hit by Widespread Outage as OpenAI Investigates Cause OpenAI’s popular chatbot, ChatGPT, has been taken offline for millions of users worldwide in a major outage that is causing widespread disruption. The outage, which started at around 5 AM ET on July 25th, is affecting users across the globe, including those in the … Read more

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

A new threat landscape has emerged with the launch of DevMan RaaS, a centralized portal that streamlines payload builds, victim management, and affiliate payouts for ransomware operators. This sophisticated platform is designed to simplify the process of launching and managing large-scale ransomware attacks, making it easier than ever for malicious actors to extort money from … Read more

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cybersecurity experts are warning of a new wave of attacks targeting companies that expose their Product Lifecycle Management (PLM) software to the internet. Cl0p, a notorious cybercrime group, has been exploiting unauthenticated Remote Code Execution (RCE) vulnerabilities in PTC Windchill and FlexPLM systems, granting attackers unfettered access to sensitive data and systems. The affected companies … Read more

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Cyberthieves have taken insurance phishing scams to a new level, leveraging sophisticated artificial intelligence (AI) models to hijack online accounts in real-time. According to a recent study by CTM360 Research, these attackers are using AI-powered tools to automate the process of infiltrating victims’ accounts, making it increasingly difficult for individuals and businesses to stay one … Read more