Phishing 3.0: The Fight Moves to Agent Versus Agent

**Cybersecurity Threats Take a New Turn as Phishing Evolves** A sophisticated new threat is sweeping through the cybersecurity landscape, marking a significant shift in the way hackers operate. Dubbed “Phishing 3.0,” this latest wave of attacks leverages advanced techniques to infiltrate even the most secure networks. The tactic involves exploiting identity exposure to unlock active … Read more

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Dahua Security Cameras Exposed to Mass Hacking Due to Lax Password Policies and Flaws in Authentication Protocols A staggering 14,500+ Dahua surveillance cameras have been compromised by hackers using a combination of credential attacks, authentication bypasses, and peer-to-peer (P2P) exploits. The vulnerability lies in the lax password policies implemented by Dahua’s customers, which allowed attackers … Read more

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

Central Asian Governments Hit by Sophisticated Espionage Campaign Using Custom-Built Rats A highly targeted and sophisticated cyber espionage campaign has been uncovered, targeting governments in Central Asia with an arsenal of five custom-built Remote Access Trojans (RATs). Dubbed “SilkParasite,” the operation is believed to have started at least a year ago, with attackers using social … Read more

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

A trio of high-severity vulnerabilities, affecting multiple popular software platforms, has been spotted in active exploitation by threat actors. The flaws, impacting macOS, SharePoint, vCenter, and Microsoft’s Internet Key Exchange (IKE), pose a significant risk to organizations and individuals who rely on these systems. These vulnerabilities, while distinct, share a common thread: they all revolve … Read more

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

A Sophisticated Malware Campaign Exploits Hacked WordPress Sites, Threatening Thousands of Users A disturbing cybersecurity trend has emerged in recent weeks, with a malicious campaign using nearly 2,000 compromised WordPress sites to spread malware and steal sensitive data. The campaign, dubbed “StopAndProtect,” has been spotted targeting users across various industries, from small businesses to large … Read more

Phishing 3.0: The Fight Moves to Agent Versus Agent

A New Era of Cyber Warfare: Phishing 3.0 Puts Humans in the Crosshairs In a disturbing escalation of cyber threats, hackers have begun exploiting identity exposure to bypass traditional security measures and launch active attacks on unsuspecting users. Dubbed “Phishing 3.0,” this new wave of attacks sees malicious actors using compromised identities to infiltrate even … Read more

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Dahua Devices Compromised in Large-Scale Credential-Based Attack, Exposing Thousands of Users to Potential Risk A staggering 14,500+ Dahua security cameras and recorders have been compromised by hackers using a combination of credential attacks, authentication bypasses, and peer-to-peer (P2P) protocols. The breach is particularly concerning due to the widespread nature of the affected devices, which are … Read more

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

A sophisticated espionage campaign, dubbed SilkParasite, has been uncovered targeting central Asian governments with a suite of five custom-built Remote Access Trojans (RATs). The malware operation is believed to be state-sponsored and has been active since at least 2020. The attackers have honed in on high-value targets within the region’s governments, exploiting vulnerabilities in software … Read more

Microsoft fixes known issue causing Windows Defender crashes

A Critical Bug in Windows Defender Has Been Fixed, but What Does it Mean? A widespread issue with Microsoft’s Windows Defender security software has been resolved, following a string of problems that left users struggling to protect their devices from malware and viruses. The bug, which caused the program to crash on some systems, was … Read more

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A Clop-linked web shell, known as Windchill, has been discovered to not only decrypt credentials but also map sensitive engineering data on compromised networks. The malware’s capabilities have raised concerns about its potential use in active attack paths, putting enterprises and organizations at risk of severe breaches. The discovery was made after researchers identified a … Read more