E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

**Malicious FTP Banners Used as Hidden Command Channels for Malware** A new and insidious tactic has emerged in the world of cyber attacks, where hackers are exploiting a seemingly innocuous aspect of network infrastructure to secretly command malware. Cybersecurity researchers have discovered that malicious actors are hijacking File Transfer Protocol (FTP) banners – those brief … Read more

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

A significant escalation in the ongoing cat-and-mouse game between nation-state hackers and global cybersecurity authorities has unfolded with the United States imposing sanctions on a group of Iranian-linked hackers accused of breaching critical infrastructure targets worldwide. The move is seen as a major step up in efforts to disrupt state-sponsored cyberattacks, which have reached unprecedented … Read more

Hospital operator Nutex Health says data stolen in cyberattack

Nutex Health, a leading hospital operator with facilities across 12 states in the US, has revealed that it’s been hit by a cyberattack that resulted in sensitive data being stolen from its servers. The incident, which was disclosed in a filing with the Securities and Exchange Commission (SEC), is still under investigation, but initial findings … Read more

Massive DDoS attack disrupts Norway’s government digital services

Norway’s Government Digital Services Brought Down by Massive DDoS Attack A massive distributed denial-of-service (DDoS) attack has struck Norway’s shared government digital infrastructure, disrupting services used by the public sector. The attack started on Monday at 03:38 CEST and targeted the infrastructure supporting various government services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and … Read more

Frontier AI: Vulnerability Management’s Systemic Revolution

A groundbreaking vulnerability management system has been unveiled, one that promises to revolutionize the way organizations protect themselves from cyber threats. At its core is a novel approach to mapping out potential attack paths, leveraging AI-driven identity exposure analysis to pinpoint vulnerabilities and sever breach routes at strategic choke points. Frontier AI’s innovative system has … Read more

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Cybersecurity Researchers Expose Sophisticated FTP Banner Exploitation Technique A sophisticated threat actor has been using a novel technique to turn seemingly innocuous File Transfer Protocol (FTP) banners into covert channels for malware commands, exposing thousands of organizations worldwide to potential attacks. The revelation highlights the dangers of underestimating even the most mundane aspects of network … Read more

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

The US government has taken a significant step in combating state-sponsored cyber threats, imposing sanctions on Iranian-linked hackers believed to be behind several high-profile breaches targeting critical infrastructure. The move aims to disrupt and deter these actors from carrying out further attacks that could have devastating consequences for national security and the global economy. At … Read more

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Malware Spreads Through npm Packages, Targeting Cloudflare Users A disturbing trend has emerged in the world of cybersecurity, as hackers have exploited a vulnerability in the popular package manager npm to spread malware through 24 compromised packages. The malicious code uses a clever trick to impersonate Cloudflare’s CAPTCHA pages, potentially putting thousands of users at … Read more

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A massive wave of attacks, dubbed “Mirage2FA,” has struck over 4,500 companies in the US and EU, compromising sensitive login credentials and leaving a trail of exposed identities in its wake. The campaign’s operators have leveraged a clever manipulation of Microsoft 365 login flows to bypass multi-factor authentication (MFA) protections, allowing them to gain unauthorized … Read more

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Cybersecurity researchers have uncovered a critical flaw in the Marimo Notebook app that could allow attackers to execute malicious commands on users’ devices even when they are editing sensitive files. The vulnerability, which affects both Android and iOS versions of the app, highlights the importance of prioritizing security in popular productivity tools. The issue arises … Read more