Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

A sophisticated attack has been discovered, where malicious actors are exploiting vulnerabilities in AhsayCBS backup software to secretly deploy cryptocurrency mining malware on compromised systems. The attackers have been using this method to install XMRig miners disguised as Microsoft Edge updates, further compromising victim machines and draining their resources. The affected systems are running the … Read more

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

A new free AI-powered vulnerability scanner has been launched by Anthropic, a leading artificial intelligence research organization. The tool is specifically designed for open-source projects and promises to help developers identify potential security vulnerabilities before they can be exploited by hackers. The technology behind the scanner uses advanced machine learning algorithms to analyze codebases and … Read more

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

A Critical Linux Vulnerability Exposed: AnyDesk Flaw Allows Root Access In a disturbing revelation, researchers have published a working exploit for a previously unknown vulnerability in the popular remote desktop software AnyDesk, specifically targeting Linux systems. The flaw, which allows an attacker to gain root access without authentication, has left many organizations scrambling to patch … Read more

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

A new wave of lawsuits has hit TP-Link, a leading router manufacturer, with four more U.S. states joining the growing list of plaintiffs accusing the company of prioritizing profits over security and potentially colluding with Chinese authorities. The latest developments add fuel to an ongoing fire that highlights the critical need for consumers to scrutinize … Read more

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Cybersecurity experts have detected a worrying update to the P7 DarkSword iOS exploit kit, which has added two new features that significantly enhance its capabilities. The updated malware can now target not only user credentials but also cryptocurrency wallet data, making it an even more formidable threat for Apple device owners. Moreover, the new version … Read more

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The Flax Typhoon threat actor has been exploiting five critical vulnerabilities in various software systems, leaving federal agencies and private organizations scrambling to patch their defenses. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a deadline of October 11 for all affected federal agencies to address the security holes before they become exploited … Read more

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Hackers have exploited vulnerabilities in AhsayCBS, a cloud backup and disaster recovery software used by over 150,000 businesses worldwide. The attackers compromised systems to secretly deploy Monero cryptocurrency miners disguised as Microsoft Edge browser updates. This sophisticated campaign highlights the ongoing threat of supply chain attacks and the importance of robust security measures. AhsayCBS is … Read more

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

A new AI-powered vulnerability scanner has been launched by Anthropic, a leading developer of artificial intelligence technologies. The tool, designed specifically for open-source projects, promises to revolutionize the way developers identify and fix security vulnerabilities in their code. But what’s really at stake here, and why should users care? The free scanner is a game-changer … Read more

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

A Critical Linux Vulnerability Has Been Exploited, Putting Thousands of Systems at Risk Researchers have published a working exploit for a previously unknown vulnerability in the AnyDesk remote desktop software on Linux systems. The flaw allows attackers to gain root access without authentication, giving them complete control over affected machines. The vulnerability affects all versions … Read more

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Four more US states have filed lawsuits against TP-Link, a leading router manufacturer, alleging that the company’s products contain critical security vulnerabilities and pose a significant risk to user data. The lawsuits join several others already pending against TP-Link, highlighting growing concerns about the cybersecurity of internet-connected devices. At the heart of these allegations is … Read more