US charges alleged operators of Russian bulletproof hosting service

The US government has taken a significant step in its ongoing fight against cybercrime, charging three Russian nationals with operating a bulletproof hosting (BPH) service that provided infrastructure to ransomware gangs responsible for over $62 million in damages worldwide. The indictment unsealed on Tuesday targets Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin, who allegedly owned … Read more

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

A pair of zero-day vulnerabilities, discovered in SonicWall’s SMA 1000 series of secure remote access appliances, have been exploited in the wild, potentially allowing attackers to execute arbitrary system commands with admin privileges. The news has significant implications for organizations that rely on these devices for secure access to their networks. The two flaws, identified … Read more

You Don’t Have to Run an Exploit to Know If You’re Vulnerable

Cybersecurity’s Great Unevenness: Why Patching Just Isn’t Enough Anymore Imagine having to deal with a never-ending flood of new vulnerabilities, each one potentially threatening your organization’s security. That’s the reality for cybersecurity teams today, thanks to the explosive growth in newly disclosed flaws and the lightning-fast pace at which attackers can turn them into working … Read more

LastPass, Bitwarden users targeted with fake security alerts

A sophisticated phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to trick them into divulging sensitive information. The attackers are using email notifications that appear to be from the password management services, but actually lead to malicious websites that prompt victims to download files or enter their credentials. LastPass has … Read more

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

A High-Severity Vulnerability Forces ShareFile to Shut Down Storage Zone Controllers, Urges Customers to Patch Immediately Progress Software has confirmed that a high-severity zero-day vulnerability is behind the sudden shutdown of ShareFile Storage Zone Controllers last week. The company acted out of caution after receiving information from a credible source about a potential threat and … Read more

Windows 11 KB5101650 & KB5099414 cumulative updates released

Windows 11 Receives Mandatory Security Updates, Alongside Long-Awaited Features and Fixes Microsoft has rolled out two critical cumulative updates for Windows 11, KB5101650 and KB5099414, which address a staggering 571 security vulnerabilities discovered over the past few months. These patches are mandatory, as they include the latest July Patch Tuesday fixes. If you’re running Windows … Read more

Microsoft Entra ID gets passkeys default authentication starting September

In a significant move to bolster account security and reduce reliance on vulnerable authentication methods, Microsoft has announced that passkeys will become the default authentication method for its Entra ID enterprise identity service starting September this year. This change is expected to impact millions of users worldwide who currently rely on phone-based SMS and voice … Read more

You Don’t Have to Run an Exploit to Know If You’re Vulnerable

A Perfect Storm of Vulnerabilities and AI-Driven Attacks Leaves Defenders Reeling The cybersecurity landscape has undergone a seismic shift in recent years, with vulnerability management facing an unprecedented challenge. The traditional timeline of weeks or months between a flaw becoming public and attackers developing working exploits has been reduced to mere hours. Two key factors … Read more

LastPass, Bitwarden users targeted with fake security alerts

LastPass and Bitwarden users are being targeted by a sophisticated phishing campaign that uses fake security alerts to trick victims into handing over sensitive information. The malicious emails, which have been sent to both LastPass and Bitwarden users, appear to be legitimate corporate communications from the password management companies. The emails claim to notify recipients … Read more