FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI’s Takedown of NetNut Proxy Platform Exposes Widespread Abuse of Residential Proxies In a significant blow to cybercrime, the Federal Bureau of Investigation (FBI) has worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by Alarum Technologies. The action comes after multiple security firms revealed … Read more

Alleged Scattered Spider hacker extradited to the United States

Peter Stokes, a dual US and Estonian citizen, has been extradited to the United States to face charges related to his alleged involvement with the notorious Scattered Spider hacking collective. According to court documents, Stokes was involved in at least four high-profile breaches that resulted in millions of dollars being extorted from companies worldwide. Stokes, … Read more

Microsoft fixes bug that removed Copilot buttons in Outlook

A critical bug in Microsoft Outlook has been fixed, but not before it caused widespread disruption for users of the Copilot Chat feature. The issue, which was reported to have affected users with the Copilot Chat (Basic) license, saw the Copilot buttons disappear from Classic Outlook on Windows devices. This meant that users were unable … Read more

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Cybersecurity threats have taken a new turn, with ransomware groups exploiting vulnerabilities in Citrix software, using Bring Your Own Vulnerable Dependencies (BYOVD), and leveraging supply chain credentials to gain access to networks. The rise of these tactics highlights the need for organizations to reassess their security strategies and focus on proactive measures to prevent attacks. … Read more

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI has dealt a significant blow to the cybercrime community with the seizure of hundreds of domains associated with NetNut, a residential proxy service operated by Alarum Technologies. This move comes after multiple security firms revealed that NetNut was linked to the Popa botnet, a collection of at least two million compromised devices used … Read more

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Cyberattackers have developed a new tactic that allows them to hijack Microsoft 365 accounts in as little as three seconds, using a technique called ConsentFix. This method exploits the trust users place in legitimate-looking authentication screens, making it difficult for even the most vigilant individuals to detect. The attack begins with a phishing lure sent … Read more

Google loses final appeal to overturn €4.1 billion EU fine

A landmark antitrust ruling has dealt a significant blow to Google’s business practices, with the Court of Justice of the European Union (CJEU) upholding a €4.1 billion fine levied against the tech giant in 2018. The case centers on Google’s use of its Android operating system to promote its own products and services, specifically Chrome … Read more

Identity Lifecycle Management Wasn’t Built for AI Agents

Cybersecurity teams are scrambling to address a critical vulnerability exposed by artificial intelligence (AI) models, highlighting a glaring oversight in identity lifecycle management systems. These systems, designed to grant and revoke access to sensitive resources based on user identities, were not built with AI agents in mind. As a result, organizations worldwide are at risk … Read more

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

A New Wave of Malware Exploits OAuth Vulnerability to Infiltrate Gmail Accounts via Google API A sophisticated malware campaign linked to the ToddyCat threat group has been uncovered, leveraging a previously unknown vulnerability in Google’s OAuth authentication system to gain unauthorized access to Gmail accounts. This alarming development highlights the ongoing cat-and-mouse game between cybercriminals … Read more