BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A Sneaky Supply Chain Attack Hits WordPress Sites, Leaving a Trail of Rogue Admins in Its Wake A sophisticated cyber attack has been discovered targeting BdThemes, a popular WordPress theme provider. The malicious scheme involves injecting poisoned JSON files into the supply chain, which ultimately creates rogue administrators on compromised sites. This brazen attack not … Read more

Sherlock Holmes was the “OG” Social Engineer

Sherlock Holmes: The Original Social Engineer In a fascinating display of how timeless social engineering techniques remain, Professor Elizabeth Rasnick has drawn parallels between the fictional detective Sherlock Holmes and modern-day tactics used by threat actors. Her session at DEF CON 34 highlighted the importance of prioritizing human element security awareness training in organizations. Holmes’s … Read more

Outdated Cybercrime Laws Put Security Researchers at Risk

Cybersecurity Researchers Face Prison Time Due to Outdated Laws A growing concern in the cybersecurity community is the outdated laws that put security researchers at risk. In some countries, including the United Kingdom, security researchers who responsibly disclose vulnerabilities can face imprisonment or fines under laws that don’t differentiate between malicious hackers and those working … Read more

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains that were previously reserved for nation-state actors have suddenly and alarmingly spread to organized cybercrime groups around the globe. The complex malware frameworks, known as Coruna and DarkSword, are being used by a wide range of malicious actors, from advanced persistent threat (APT) groups to run-of-the-mill hackers. According to research firm … Read more

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

Cybersecurity teams are facing a daunting challenge in the form of a “patch gap,” where attackers are increasingly exploiting vulnerabilities before patches are even available, leaving defenders scrambling to keep up. This issue is not just about patching faster or prioritizing high-severity vulnerabilities, but rather about fundamentally changing how we approach vulnerability management. The recent … Read more

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A Zero-Day SQL Injection Vulnerability in Metabase Cloud Threatens Widespread Consequences A critical vulnerability has been discovered in Metabase Cloud, a business analytics platform used by numerous organizations worldwide. The zero-day SQL injection flaw allows attackers to gain remote administrator access to affected instances, compromising sensitive data and potentially leading to further attacks on downstream … Read more

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains once limited to nation-states are spreading rapidly to organized cybercrime groups, posing a significant threat to global security. Two advanced iOS exploit chains, Coruna and DarkSword, have been making headlines in recent months due to their complex nature and widespread adoption. Initially used by nation-state actors and commercial surveillance vendors, these … Read more

The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists

The Patch Gap: Why Traditional Vulnerability Management Won’t Cut It in Today’s Threat Landscape Imagine being told that, on average, it takes just four hours for attackers to exploit a newly discovered vulnerability after it’s publicly disclosed. Sounds alarming? That’s exactly what’s happening right now. The rate at which vulnerabilities are being exploited has increased … Read more

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A critical zero-day vulnerability has been discovered in the Metabase Cloud business-analytics platform, allowing malicious attackers to gain remote administrator access and potentially compromise downstream organizations. The maximum-severity flaw, which has not yet been assigned a CVE identifier, affects versions 1.58 of the platform and above. According to an advisory posted on GitHub by Metabase, … Read more

Multistate Water System Attacks Widen, Iran Suspected

Cyberattacks on US Water Systems Continue to Spread, with Iran Suspected as Culprit A wave of cyberattacks targeting water and wastewater systems has been sweeping across the United States, leaving a trail of vulnerable industrial controllers in its wake. At least a dozen states have reported attacks, with the latest victims including Alabama and New … Read more