SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Cybercrime gangs have been exploiting a vulnerability in ScreenConnect, a widely-used remote access software, to deploy AsyncRAT malware on unsuspecting victims’ computers. This sophisticated scheme involves manipulating search engine optimization (SEO) techniques to poison software websites with malicious code, effectively turning legitimate sites into vectors for cyber attacks. The nefarious operation relies on compromised software … Read more

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

A 19-year-old accused of using advanced hacking techniques to breach multiple high-profile companies has been extradited from the UK to face charges in the United States. The suspect, whose name is not being disclosed due to ongoing legal proceedings, was allegedly involved in a sophisticated cyber campaign that exploited vulnerabilities in software systems. According to … Read more

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

A critical vulnerability discovered in Argo CD’s repository server could potentially allow attackers to gain unauthorized access to Kubernetes clusters, compromising sensitive data and disrupting business operations. Argo CD is an open-source continuous delivery tool used by many organizations to manage their cloud-native applications. A recent discovery revealed a flaw in the repository server component … Read more

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

As AI-powered tools increasingly infiltrate the world of cybersecurity, researchers have made a groundbreaking discovery that could either bolster or undermine an organization’s defenses – depending on its approach. A recent assessment highlights a staggering gap between awareness and resilience when it comes to addressing software vulnerabilities discovered by AI models. At the heart of … Read more

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Malware Chain Exploits Blogger Platform, Steals Sensitive Data from Thousands of Victims A sophisticated malware chain known as VEIL#DROP has been uncovered, leveraging a popular blogging platform to spread a notorious data-stealing tool called PureLogs. The attack vector exploits vulnerabilities in the platform’s infrastructure, compromising thousands of users’ sensitive information. At its core, VEIL#DROP is … Read more

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Malicious Actors Exploit ScreenConnect, AsyncRAT for Massively Scalable Attacks A disturbing trend has emerged, where software sites compromised with search engine optimization (SEO) poisoning techniques are leveraging ScreenConnect and AsyncRAT malware to carry out large-scale attacks. The affected parties include a significant number of small to medium-sized businesses (SMBs), whose websites have been hijacked for … Read more

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

A teenage suspect, allegedly involved in high-profile hacking cases, has been extradited from Singapore to face federal charges in the United States. The 19-year-old’s extradition marks a significant development in the ongoing cat-and-mouse game between cyber attackers and law enforcement agencies. The individual, who used the alias “Spider,” is believed to have orchestrated an array … Read more

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

A Critical Vulnerability in Argo CD’s Repository Server Exposes Kubernetes Clusters to Remote Takeover Attacks A severe, unpatched vulnerability in the repository server component of popular Kubernetes application delivery tool Argo CD has been uncovered, putting millions of users at risk. The flaw, discovered by security researchers and not publicly disclosed until now, allows attackers … Read more

AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

A new form of browser-based ransomware, leveraging artificial intelligence (AI) and Chromium API vulnerabilities on Windows and Android devices, has been spotted in the wild. This malicious software uses AI-generated phishing campaigns to spread its payload, making it a particularly challenging threat for security teams to contain. The ransomware, which has not been named by … Read more

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

A critical vulnerability in Progress Kemp LoadMaster, a load balancing solution used by many organizations worldwide, is being actively exploited by attackers. The pre-authentication remote code execution (RCE) flaw, discovered by researchers at CyberNews, can be exploited without requiring any credentials or authentication, making it particularly concerning. The vulnerability, tracked as CVE-2023-3837, affects Kemp LoadMaster … Read more