Ernst & Young discloses data breach after support system hack

Ernst & Young Reveals Data Breach After Support System Hack, Leaving Thousands of Clients Concerned Global auditing and professional services giant Ernst & Young (EY) has disclosed a data breach that occurred when an unauthorized third party accessed its support ticket system. The compromised platform allowed hackers to download multiple documents containing sensitive client information, … Read more

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

A sophisticated phishing campaign has been uncovered, leveraging fake coding tests and SVG flag images to deliver malicious malware linked to the notorious OtterCookie botnet. The attack’s novelty lies in its ability to evade detection by security software, making it a pressing concern for developers and organizations worldwide. The scheme targets individuals with programming skills, … Read more

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

A sophisticated cyber threat group, known as GoldenEyeDog Subgroup, has been linked to a major breach of DigiCert’s certificate authority infrastructure, resulting in the theft of code-signing certificates. This malicious activity has significant implications for software security and highlights the growing threat posed by advanced AI-powered attacks. The breach is believed to have occurred sometime … Read more

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A new botnet, dubbed NadMesh, has been identified hunting for exposed AI services that have been left unsecured on cloud platforms and Kubernetes clusters. This alarming trend highlights the growing threat of AI-powered attacks, which are increasingly being used by malicious actors to compromise sensitive systems. NadMesh is a sophisticated botnet that leverages machine learning … Read more

Windows Server 2022 reach end of mainstream support in 90 days

In just over three months, Microsoft will withdraw mainstream support for its popular server operating system, Windows Server 2022. This means that after October 13, 2026, no new features or security updates will be released for this version of the software, leaving systems vulnerable to emerging threats. The withdrawal of mainstream support is a natural … Read more

New Windows LegacyHive zero-day gives hackers admin privileges

A Critical Windows Vulnerability Exploited in the Wild: What You Need to Know In a worrying development, a security researcher has uncovered a previously unknown Windows vulnerability that allows attackers to gain admin privileges on up-to-date systems. The exploit, dubbed LegacyHive, takes advantage of a weakness in the Windows User Profile Service and can be … Read more

Inside the Search for “Clean” Residential Proxies for Carding

Criminal actors are refining their playbook to evade detection online, and at the heart of this strategy is a sophisticated approach to using residential proxies for carding. These individuals no longer view residential IPs as a simple anonymity tool, but rather as one component of a broader identity-simulation stack. They’re now combining these proxies with … Read more

Ernst & Young discloses data breach after support system hack

Ernst & Young, one of the world’s largest auditing and professional services providers, has disclosed a data breach that occurred when an unauthorized third-party accessed its support ticket system. The breach is significant not only because of Ernst & Young’s size and reach but also because it highlights the potential vulnerabilities in even the most … Read more

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

A new strain of malware, dubbed GoSerpent, has been discovered targeting Southeast Asian governments and diplomats for espionage purposes. This highly sophisticated threat leverages advanced tactics, techniques, and procedures (TTPs) to evade detection and compromise sensitive information. GoSerpent is a type of backdoor malware that allows attackers to remotely access and control infected systems. It’s … Read more