Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A group of hackers calling themselves “Ransom Busters” has claimed responsibility for infiltrating servers used by ransomware operators, and is now demanding payment from those same victims in exchange for not revealing their sensitive information. The move has left many experts scratching their heads, wondering how this could happen and what it means for the … Read more

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets, Leaving Thousands Vulnerable A severe vulnerability in the popular open-source machine learning platform MLflow has been exploited by attackers to steal cloud credentials and sensitive secrets from thousands of organizations. The flaw, which enables cross-domain privilege escalation, allows hackers to bypass security controls and … Read more

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

**Critical Flaw in Microsoft Copilot Personal Exposes Data from Connected Apps** A newly discovered vulnerability in Microsoft’s Copilot Personal has been found to allow a single click to exfiltrate sensitive data from connected applications, putting millions of users at risk. The issue lies in the way Copilot Personal handles user permissions and access control, allowing … Read more

CISOs Break Their Silence in ‘Declassified’ Docuseries

Behind Closed Doors: Cybersecurity’s Darkest Secrets Exposed in Groundbreaking Docuseries In a bold move, 11 high-profile Chief Information Security Officers (CISOs) from top organizations have opened up about their most intimate and often painful experiences with breaches, burnout, and personal struggles. The “Declassified” docuseries, launched by Red Mirror Studios, is changing the narrative around cybersecurity … Read more

Clop created custom web shell for Windchill data theft attacks

Cybersecurity Threat Actors Create Custom Web Shell to Steal Data from PTC Windchill Servers A sophisticated cyber threat has been uncovered, with hackers leveraging a custom-built web shell to steal sensitive data from PTC Windchill servers. The web shell, linked to the notorious Clop ransomware gang, is specifically designed to exploit vulnerabilities in these servers … Read more

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A group of self-proclaimed “ransom busters” has claimed responsibility for hacking into servers used by notorious ransomware gangs, but their motives have raised more questions than answers. The hackers, who operate under the name Ransom Busters, are seeking to extort substantial sums from victims they claim were previously targeted by these same ransomware groups. Ransomware … Read more

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Cloud Security Breach Exposes Sensitive Data as Attackers Exploit MLflow SSRF Flaw A critical vulnerability in the popular machine learning (ML) platform MLflow has been exploited by attackers, compromising sensitive data stored on cloud services. The flaw, a Server-Side Request Forgery (SSRF) bug, allows malicious actors to access and steal cloud credentials and secrets, potentially … Read more

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Microsoft’s AI-powered assistant, Copilot Personal, has a vulnerability that could allow hackers to extract sensitive data from connected applications with just one click. This flaw, discovered by researchers, is particularly concerning as it exploits a common issue in identity exposure – where an attacker gains access to a user’s digital identity and uses it to … Read more

Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud

Microsoft’s Cloud Services Hijacked by Stealthy ‘TwinLoot’ Malware Framework A sinister malware framework, dubbed “TwinLoot” by its discoverers, has been found operating entirely from within Microsoft’s cloud services. This Python-based framework uses various Microsoft tools to disguise its malicious activity as legitimate traffic, making it a masterclass in stealth and sophistication. Researchers at Ontinue Cyber … Read more

‘Ransom Busters’: Ransomware Actor Poses as Incident-Recovery Service

Ransomware Affiliate Poses as Incident-Recovery Service, Luring Victims with False Promises of Data Recovery A sophisticated and brazen tactic has been uncovered by cybersecurity researchers, where a ransomware affiliate is posing as an incident-recovery service to lure victims into paying them for help in recovering their stolen data. Dubbed “Ransom Busters,” this malicious entity claims … Read more