GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

A Novel Malware Allows Attackers to Choose Their Own Destructive Path Cybersecurity researchers have discovered a sophisticated malware that lets attackers choose how they want to destroy a targeted system. Dubbed GigaWiper, this modular implant combines elements from various malware families to provide both backdoor and wiper capabilities. The implications are significant, as GigaWiper’s flexibility … Read more

‘Yellow Teams’ Are Defining the Future of AI Security

The Future of AI Security is Being Shaped by “Yellow Teams” Behind the Scenes In a bid to stay ahead of the curve, a growing number of organizations are quietly building defense and attack tools using artificial intelligence (AI) to test their cybersecurity. These secretive engineering teams, dubbed “yellow teams,” are not only developing defenses … Read more

Weak Security Continues to Fuel Russian Cyberattacks

Russian State-Sponsored Hackers Continuously Exploit Weak Security Practices Globally A joint advisory issued by US cybersecurity agencies and their international counterparts has shed light on an ongoing issue where Russian state-sponsored hackers are compromising routers and other networking equipment to gain access to critical infrastructure networks worldwide. The advisory, which marks a significant development in … Read more

US and allies warn of Russian critical infrastructure attacks

Russian State Hackers Target Critical Infrastructure, Warns Global Cybersecurity Community A joint warning issued by cybersecurity agencies from the US and eight other countries has sounded the alarm on a sophisticated hacking campaign targeting critical infrastructure networks worldwide. The attackers, attributed to Russia’s Federal Security Service (FSB) Center 16, are exploiting poorly configured routers to … Read more

UK charges suspects linked to Russian Coms call spoofing platform

UK Authorities Crack Down on Russian Coms Call Spoofing Platform, Charging Five Suspects Linked to Tens of Millions in Financial Losses A significant blow has been dealt to organized crime groups that used a sophisticated caller ID spoofing platform to defraud victims worldwide. UK authorities have charged five individuals linked to the Russian Coms platform, … Read more

Breach at the Beach: Play the Ultimate Entra ID CTF

**Varonis Researchers Create Challenging Entra ID Training Experience to Help Defenders Stay Ahead of Modern Threats** Imagine being on a tranquil beach vacation when suddenly you receive word of a breach in the identity management system used by your organization. Sounds like a scenario from a cybersecurity thriller, right? But for Doron Kapah and Mark … Read more

Breach at the Beach: Play the Ultimate Entra ID CTF

Cybersecurity practitioners are often warned about the dangers lurking beneath the surface. But what happens when that threat turns out to be real? Varonis Threat Labs researchers Doron Kapah and Mark Vaitsman have faced this reality firsthand, dealing with data exfiltration in cloud-native environments. Their experience inspired them to create Breach at the Beach, a … Read more

Japan’s largest taxi operator shuts systems after cyberattack

Japan’s largest taxi operator, Nihon Kotsu, has fallen victim to a cyberattack that forced the company to shut down part of its infrastructure. The incident occurred over the weekend, impacting operations including the company’s taxi dispatch system, which remains offline as of today. Nihon Kotsu is Japan’s largest taxi and chauffeur operator by group revenue, … Read more

Lidl discloses online shop breach after service provider hack

Lidl Discloses Online Shop Breach After Service Provider Hack, Warns Customers of Potential Phishing Attacks German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that their personal information was stolen in a breach at a service provider. The company’s online shop was not directly affected by the attack, but customer … Read more

CISA warns of actively exploited RCE flaws in Joomla extensions

Cybersecurity experts are sounding the alarm over a pair of critical vulnerabilities affecting popular Joomla extensions, iCagenda and Balbooa Forms. These flaws have been actively exploited by attackers, compromising websites and putting sensitive data at risk. The US Cybersecurity and Infrastructure Security Agency (CISA) has categorized these vulnerabilities as “maximum priority,” urging federal agencies to … Read more