US charges Iranian hackers over $3.4 billion intellectual property theft

The US has taken a major step in combating state-sponsored hacking with the indictment of 17 Iranian nationals accused of stealing intellectual property worth $3.4 billion from American organizations. The charges, announced by the US Department of Justice (DoJ), target members of a hacking-for-hire group known as the Mabna Institute, which allegedly worked on behalf … Read more

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

Cybersecurity agencies in the US have issued a joint warning about AI-powered attacks on Siemens PLCs in critical infrastructure. The threat is real and ongoing, with potential consequences that go far beyond mere disruption. Siemens PLCs are industrial computers used to automate and control machinery and physical processes in factories, power plants, water treatment facilities, … Read more

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

A massive campaign of cyberattacks has compromised over 14,500 Dahua web cameras across Ukraine and Russia in a 35-day operation that has left owners scrambling to secure their devices. Dubbed CameraSwarm by researchers at Hunt.io, the attack highlights the vulnerabilities inherent in internet-connected devices and the need for robust security measures. The attackers, who used … Read more

Password spraying attacks surge 155x as hackers exploit MFA gaps

Cyberattackers have unleashed a massive wave of password spraying attacks, flooding networks with over 81 million login attempts in just two weeks alone. What’s more, these attacks are not your run-of-the-mill brute-force efforts – they’re leveraging gaps in multi-factor authentication (MFA) to gain a foothold. The surge in password spraying attacks is a staggering 155 … Read more

US charges Iranian hackers over $3.4 billion intellectual property theft

A massive cyber-heist orchestrated by Iranian hackers has come to light, with US authorities charging 17 individuals over the theft of intellectual property and academic research worth a staggering $3.4 billion. The operation, which spanned several years and involved multiple organizations, highlights the ongoing threat posed by state-sponsored hacking groups. According to the US Justice … Read more

Phishing 3.0: The Fight Moves to Agent Versus Agent

**Cybersecurity Threats Take a New Turn as Phishing Evolves** A sophisticated new threat is sweeping through the cybersecurity landscape, marking a significant shift in the way hackers operate. Dubbed “Phishing 3.0,” this latest wave of attacks leverages advanced techniques to infiltrate even the most secure networks. The tactic involves exploiting identity exposure to unlock active … Read more

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Dahua Security Cameras Exposed to Mass Hacking Due to Lax Password Policies and Flaws in Authentication Protocols A staggering 14,500+ Dahua surveillance cameras have been compromised by hackers using a combination of credential attacks, authentication bypasses, and peer-to-peer (P2P) exploits. The vulnerability lies in the lax password policies implemented by Dahua’s customers, which allowed attackers … Read more

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

Central Asian Governments Hit by Sophisticated Espionage Campaign Using Custom-Built Rats A highly targeted and sophisticated cyber espionage campaign has been uncovered, targeting governments in Central Asia with an arsenal of five custom-built Remote Access Trojans (RATs). Dubbed “SilkParasite,” the operation is believed to have started at least a year ago, with attackers using social … Read more

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

A trio of high-severity vulnerabilities, affecting multiple popular software platforms, has been spotted in active exploitation by threat actors. The flaws, impacting macOS, SharePoint, vCenter, and Microsoft’s Internet Key Exchange (IKE), pose a significant risk to organizations and individuals who rely on these systems. These vulnerabilities, while distinct, share a common thread: they all revolve … Read more

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

A Sophisticated Malware Campaign Exploits Hacked WordPress Sites, Threatening Thousands of Users A disturbing cybersecurity trend has emerged in recent weeks, with a malicious campaign using nearly 2,000 compromised WordPress sites to spread malware and steal sensitive data. The campaign, dubbed “StopAndProtect,” has been spotted targeting users across various industries, from small businesses to large … Read more