Australia warns of global campaign targeting vulnerable CMS platforms

A Global Campaign of Cyber Attacks Targeting Vulnerable CMS Platforms Has Been Unleashed, Warns Australia’s Cyber Security Centre Australian businesses are being warned about a massive global campaign targeting vulnerable content management systems (CMS) and plugins. The Australian Cyber Security Centre (ACSC) has issued an alert stating that many small to medium-sized enterprises in the … Read more

‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism

A New Attack Vector Emerges: ‘HalluSquatting’ Turns AI Hallucinations into Botnet Delivery Mechanism Researchers have uncovered a novel attack technique that exploits the tendency of artificial intelligence (AI) assistants to “hallucinate” or generate false information. Dubbed “HalluSquatting,” this method leverages the ability of AI tools to create fake resources and packages, allowing attackers to create … Read more

GigaWiper Combines Multiple Malware for System-Level Sabotage

A Sophisticated Threat Actor’s Tool of Choice: GigaWiper Microsoft has been tracking a highly destructive malware, dubbed GigaWiper, that has been wreaking havoc on Windows systems for over eight months. This sophisticated threat combines multiple malware families and boasts robust command-and-control (C&C) capabilities, making it a powerful tool in the hands of a skilled threat … Read more

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta Warns of Sophisticated Vishing Campaign Targeting Microsoft 365 Customers A highly targeted vishing campaign is underway, with hackers using social engineering tactics to trick Microsoft 365 users into divulging their login credentials. The attacks, which began in April, have been observed by Okta and are being tracked as O-UNC-066. The hacking group behind the … Read more

China, India-Linked Hackers Both Targeted Same Pakistani Police Force

Cyberspies from China and India Caught Snooping on Pakistani Police Networks In a shocking revelation, researchers at SentinelOne have uncovered a two-year-long cyberespionage campaign targeting Pakistani law enforcement networks, with both Chinese and Indian-linked hackers sneaking into the same police force’s systems. The Balochistan Police, which has been caught in the middle of the rivalries … Read more

‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets

**Malicious Image Exploit Leaks Secrets from AI-Coded Repositories** Researchers at the University of Missouri-Kansas City’s ASSET Research Group have unveiled a novel technique for stealing sensitive information from code repositories. Dubbed “Ghostcommit,” this exploit takes advantage of a review gap in popular coding agents to inject malicious instructions into images, which are then executed by … Read more

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta Sounds Alarm on Sophisticated Vishing Attacks Targeting Microsoft 365 Users A wave of highly targeted and sophisticated vishing attacks is currently sweeping through various industries, with threat actors aiming to harvest sensitive information from unsuspecting Microsoft 365 users. The campaign, which kicked off in April, has been linked to a hacking group known as … Read more

China, India-Linked Hackers Both Targeted Same Pakistani Police Force

Pakistani Police Networks Breached by China and India-Linked Hackers A recent investigation has uncovered a sophisticated cyberespionage campaign that targeted the Balochistan Police force in Pakistan, with hackers linked to both China and India quietly breaching their networks over a period of two years. The attackers gained access to sensitive data, including biometric databases, criminal … Read more

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang

A third US cybersecurity expert, Angelo Martino, has been sentenced to 70 months in prison for helping a ransomware gang while working as a ransomware negotiator. This latest development highlights the increasing threat of insider threats and underscores the need for robust measures to prevent such collaborations. Martino, 41, from Florida, was accused of working … Read more

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops

A Trio of Threats Exposed: Ransomware Affiliate Pleads Guilty, QuimaRAT Spreads Across Platforms, and More A spate of disturbing cybersecurity incidents has come to light in recent days, showcasing the ever-evolving tactics employed by threat actors. From a ransomware affiliate’s guilty plea to a subscription-based remote access trojan (RAT) platform being advertised on dark web … Read more