URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Tells ShareFile Customers to Halt Storage Zone Controllers Over Critical Security Threat A critical security vulnerability has been discovered in Progress’s ShareFile, a cloud-based file-sharing service used by millions of users worldwide. In an urgent notice sent out yesterday, the company instructed its customers to immediately shut down their Storage Zone Controllers (SZCs) due … Read more

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

A massive study of free Android VPN apps has revealed shocking security lapses, compromising user data and exposing them to potential threats. Researchers analyzed 281 popular VPN applications available on Google Play Store, discovering that many of these apps are leaking sensitive information, storing unencrypted data, and engaging in tracking activities. The researchers found that … Read more

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched

A Sophisticated Cyber Attack Exploits Unpatchable Wallet Cards, Resetting User Passwords In a concerning incident that highlights the vulnerabilities of even the most secure systems, hackers have successfully exploited unpatchable wallet cards issued by Tangem, a Swiss-based company known for its high-security digital wallets. The attackers used a technique called a “laser attack” to reset … Read more

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

A newly discovered set of vulnerabilities in U-Boot, a popular open-source bootloader used in millions of devices worldwide, could allow attackers to crash or hijack devices during boot-up. The six flaws were uncovered by researchers using artificial intelligence (AI) models, highlighting the growing importance of AI-driven security testing. The affected devices include a wide range … Read more

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

A Malicious Operation Unfolds on GitHub: Wallet-Key-Stealing npm Packages Exposed Researchers have discovered a sophisticated operation on GitHub, where malicious actors exploited the platform’s weaknesses to push wallet-key-stealing packages to unsuspecting developers. The compromised accounts belong to Injective Labs, a blockchain development company, and the affected users are likely those who have installed the tainted … Read more

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress, the software giant behind the ShareFile file-sharing platform, is urging its customers to shut down Storage Zone Controllers (SZCs) due to a critical security threat. This move affects thousands of businesses worldwide, emphasizing the need for swift action to prevent potential data breaches and system compromises. ShareFile’s SZCs are essentially on-premises servers that act … Read more

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A notorious ransomware negotiator, who made headlines for facilitating lucrative attacks on behalf of the BlackCat gang, has been sentenced to 70 months in prison. The individual’s conviction serves as a stark reminder that the underworld of cybercrime is not just a distant threat, but a tangible reality with real-world consequences. The accused, a self-proclaimed … Read more

Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

A sophisticated cyberattack has left cryptocurrency enthusiasts reeling, with over $5 million drained from wallets due to an exploit of the “Ill Bloom” vulnerability. The attack targets users of several popular cryptocurrency exchanges and wallets, leaving a trail of financial losses in its wake. The Ill Bloom vulnerability is a type of software bug that … Read more

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

**RAT with gRPC Streaming Threatens Organizations Globally** A new Remote Access Trojan (RAT) called MODBEACON has been spotted in the wild, leveraging advanced technologies like gRPC streaming to evade detection and maintain encrypted command and control (C2) traffic. This sophisticated malware variant is a significant threat to organizations worldwide, putting sensitive data at risk of … Read more

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Researchers have uncovered a sophisticated attack chain that leverages three previously unknown vulnerabilities in WhatsApp, allowing hackers to remotely execute malicious code on targeted devices with complete control over the host system. Dubbed “OpenClaw,” this alarming discovery highlights the escalating threat landscape of AI-driven attacks. The OpenClaw exploit chain hinges on a combination of three … Read more