Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Fastjson, a popular Java library used for JSON parsing and serialization, has been hit with a critical Remote Code Execution (RCE) vulnerability that’s being actively exploited by attackers. The bug, which affects versions 1.x of Fastjson, allows hackers to inject malicious code on vulnerable systems, putting countless organizations at risk. Fastjson is widely used in … Read more

OpenAI confirms ChatGPT is down worldwide

A major outage has crippled access to ChatGPT worldwide, leaving users unable to load chats or send messages. The disruption, which began at around 5 AM ET, affected not only those in the US and Europe but also users across the globe. For nearly an hour, chat enthusiasts and developers were locked out of the … Read more

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

A Centralized Ransomware-as-a-Service (RaaS) Portal Puts Thousands at Risk of Devastating Cyberattacks A recent discovery has shed light on a sophisticated ransomware-as-a-service (RaaS) portal, codenamed “DevMan,” that’s been quietly wreaking havoc on unsuspecting victims. Dubbed the “Amazon of Ransomware” by cybersecurity experts, this centralized platform enables malicious actors to create, distribute, and manage their own … Read more

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p Gang’s Latest Tactic Exposes Companies Using PTC Windchill and FlexPLM Software A new wave of attacks has been spotted targeting organizations using software from PTC (Parametric Technology Corporation) – specifically, those running versions of PTC Windchill and FlexPLM that haven’t implemented the latest security patches. The Cl0p gang, a notorious group known for its … Read more

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

A New Wave of Account Hijacking Threats Loom Large, As Insurance Phishing Evolves into Real-Time Attacks Insurance phishing scams have been a persistent menace for individuals and businesses alike, preying on vulnerabilities in email security. However, researchers at CTM360 have uncovered a disturbing evolution in these tactics – from mere phishing attempts to real-time account … Read more

OpenAI confirms ChatGPT is down worldwide

ChatGPT Users Worldwide Hit by Widespread Outage as OpenAI Investigates Cause OpenAI’s popular chatbot, ChatGPT, has been taken offline for millions of users worldwide in a major outage that is causing widespread disruption. The outage, which started at around 5 AM ET on July 25th, is affecting users across the globe, including those in the … Read more

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

A new threat landscape has emerged with the launch of DevMan RaaS, a centralized portal that streamlines payload builds, victim management, and affiliate payouts for ransomware operators. This sophisticated platform is designed to simplify the process of launching and managing large-scale ransomware attacks, making it easier than ever for malicious actors to extort money from … Read more

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cybersecurity experts are warning of a new wave of attacks targeting companies that expose their Product Lifecycle Management (PLM) software to the internet. Cl0p, a notorious cybercrime group, has been exploiting unauthenticated Remote Code Execution (RCE) vulnerabilities in PTC Windchill and FlexPLM systems, granting attackers unfettered access to sensitive data and systems. The affected companies … Read more

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Cyberthieves have taken insurance phishing scams to a new level, leveraging sophisticated artificial intelligence (AI) models to hijack online accounts in real-time. According to a recent study by CTM360 Research, these attackers are using AI-powered tools to automate the process of infiltrating victims’ accounts, making it increasingly difficult for individuals and businesses to stay one … Read more

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A Critical GitLab Vulnerability Allows Authenticated Users to Run Commands with Elevated Privileges, Leaving Thousands of Developers Exposed GitLab, a popular web-based platform for software development collaboration, has been hit by a critical vulnerability that allows authenticated users to run commands as if they were administrators. Researchers have published a proof-of-concept (PoC) exploit, demonstrating the … Read more