Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A sophisticated hacking campaign is making headlines after hackers exploited a previously unknown vulnerability in Microsoft’s Entra Passkey enrollment process to gain unauthorized access to Microsoft 365 accounts. The attack, which has been linked to a nation-state actor, highlights the ongoing cat-and-mouse game between cyber attackers and defenders. The technique used by the hackers involves … Read more

Police suspects Dutch hackers were involved in Odido breach

A Dutch Telecom Firm’s Data Breach May Be Linked to Local Hackers In a significant development, the Dutch National Police has revealed “strong indications” that local hackers were involved in a major data breach at Odido, one of the country’s largest telecommunications providers. The company disclosed the attack on February 12, stating that the attackers … Read more

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

A Key Player Behind the Devastating Ryuk Ransomware Operation Pleads Guilty in the US, Faces Up to 15 Years in Prison Karen Serobovich Vardanyan, a 34-year-old Armenian man, has pleaded guilty to deploying the notorious Ryuk ransomware on multiple US companies’ systems between November 2019 and April 2020. This significant development marks a major breakthrough … Read more

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

A critical vulnerability discovery in U-Boot, a widely-used open-source firmware for embedded devices, has left many organizations scrambling to secure their systems. Six new flaws have been identified that could allow attackers to crash devices or run malicious code at boot time, potentially leading to devastating consequences. The vulnerabilities, discovered by researchers using AI-powered scanning … Read more

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

A Devastating GitHub Compromise Rocks the Cryptocurrency Ecosystem, Exposing Millions of Users to Wallet-Stealing Malware In a brazen and sophisticated attack, Injective Labs’ GitHub repository has been compromised, allowing malicious actors to push wallet-key-stealing npm packages to unsuspecting developers. The affected projects have already been downloaded thousands of times, putting millions of cryptocurrency users at … Read more

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Tells ShareFile Customers to Halt Storage Zone Controllers Over Critical Security Threat A critical security vulnerability has been discovered in Progress’s ShareFile, a cloud-based file-sharing service used by millions of users worldwide. In an urgent notice sent out yesterday, the company instructed its customers to immediately shut down their Storage Zone Controllers (SZCs) due … Read more

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

A massive study of free Android VPN apps has revealed shocking security lapses, compromising user data and exposing them to potential threats. Researchers analyzed 281 popular VPN applications available on Google Play Store, discovering that many of these apps are leaking sensitive information, storing unencrypted data, and engaging in tracking activities. The researchers found that … Read more

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched

A Sophisticated Cyber Attack Exploits Unpatchable Wallet Cards, Resetting User Passwords In a concerning incident that highlights the vulnerabilities of even the most secure systems, hackers have successfully exploited unpatchable wallet cards issued by Tangem, a Swiss-based company known for its high-security digital wallets. The attackers used a technique called a “laser attack” to reset … Read more

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

A newly discovered set of vulnerabilities in U-Boot, a popular open-source bootloader used in millions of devices worldwide, could allow attackers to crash or hijack devices during boot-up. The six flaws were uncovered by researchers using artificial intelligence (AI) models, highlighting the growing importance of AI-driven security testing. The affected devices include a wide range … Read more

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

A Malicious Operation Unfolds on GitHub: Wallet-Key-Stealing npm Packages Exposed Researchers have discovered a sophisticated operation on GitHub, where malicious actors exploited the platform’s weaknesses to push wallet-key-stealing packages to unsuspecting developers. The compromised accounts belong to Injective Labs, a blockchain development company, and the affected users are likely those who have installed the tainted … Read more