Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

A Highly Sophisticated Phishing Campaign Exploits Job Seekers, Exposing Them to Malware-Ridden VPNs A recent investigation has uncovered a complex phishing scheme linked to the notorious threat actor Sandworm, which has been using fake job interviews as a ruse to trick unsuspecting individuals into installing malware-infested virtual private networks (VPNs). This cunning tactic not only … Read more

Microsoft releases Windows 10 KB5120249 extended security update

Microsoft has released a crucial Extended Security Update (ESU) for Windows 10, addressing critical vulnerabilities and bugs that could leave systems exposed to attacks. The update, marked as KB5120249, is mandatory for all affected versions of Windows 10 – specifically 22H2 and 21H2 – and includes the August 2026 Patch Tuesday security updates. To install … Read more

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

A New Low for Ransomware: DeadLock Exploits Polygon Smart Contracts, Making Extortion Even More Challenging to Disrupt Ransomware operators have always been adept at exploiting vulnerabilities and staying one step ahead of security measures. However, a recent development in the world of cybercrime takes the cake. The DeadLock ransomware has integrated with Polygon smart contracts, … Read more

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Cybersecurity researchers have uncovered a sophisticated exploit chain that leverages AI-assisted attacks to gain unauthenticated remote code execution (RCE) on Microsoft SharePoint servers. The findings, disclosed in a recent report, expose a vulnerable pathway for attackers to breach corporate networks and compromise sensitive data. The exploit chain relies on a combination of social engineering tactics … Read more

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

A New Twist in Social Engineering Attacks: Sandworm-Linked Group Uses Fake Job Interviews to Spread Malware A sophisticated group linked to the notorious Sandworm hacking collective has been using fake job interviews as a ruse to trick unsuspecting victims into installing malware on their devices. According to reports, this new tactic involves pushing a VPN … Read more

Wesco confirms security incident after ExfilSquad claims data theft

Wesco, a global giant in supply chain and distribution, has confirmed that it is investigating a cybersecurity incident after a notorious data extortion group claimed to have stolen sensitive information from its systems. The company’s cloud Customer Relationship Management (CRM) environment was allegedly compromised by ExfilSquad, which leaked the stolen data online. The breach reportedly … Read more

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Researchers Expose North Korean IT Workers’ Role in Crypto Heist, Highlighting Vulnerabilities in Identity Verification A group of researchers has made a startling discovery, building a fake cryptocurrency startup and successfully hiring three individuals suspected of being part of North Korea’s cyber warfare program. This bold experiment sheds light on the ease with which malicious … Read more

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla’s Surprise Move: Revoking Firefox and Thunderbird Linux Signing Key Raises Questions on Security Practices In a sudden and unexpected move, Mozilla has revoked its Linux signing key, used to verify the authenticity of software updates for its popular Firefox and Thunderbird browsers. The decision comes after it was discovered that the private key had … Read more

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A Security Vulnerability in Cellular IoT Devices Exposes Millions of Users to Malicious Activity A recent discovery has shed light on a previously unknown vulnerability in cellular Internet of Things (IoT) devices, which could allow attackers to inject malicious code into the modems that power these devices. This exploit takes advantage of a weakness in … Read more