New phishing kits target Microsoft 365 accounts, evade MFA

Microsoft 365 Users at Risk as New Phishing Kits Emerge, Evading Multi-Factor Authentication Cybersecurity researchers have discovered two sophisticated phishing kits, Jalisco and OmegaLord, designed to target Microsoft 365 accounts and evade multi-factor authentication (MFA) protections. These tools demonstrate how threat actors are continually adapting their tactics to stay ahead of modern security defenses. Jalisco … Read more

US charges alleged operators of Russian bulletproof hosting service

US Charges Alleged Operators of Russian Bulletproof Hosting Service, Seeking $62M in Damages In a major crackdown on cybercrime infrastructure, US federal prosecutors have unsealed charges against three Russian nationals accused of providing “bulletproof hosting” (BPH) services to ransomware gangs that caused over $62 million in damages worldwide. The alleged operators of the BPH services, … Read more

Microsoft: Some Dell PCs shut down after recent Windows updates

Microsoft has temporarily blocked a recent batch of Windows 11 security updates on certain Dell PCs due to shutdowns and performance issues caused by an incompatibility between new Windows software and existing hardware drivers. The issue, which affects only some Dell devices after installing the KB5101650 update, is a stark reminder that even well-intentioned updates … Read more

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Cybersecurity firm SonicWall has issued a warning about two critical zero-day vulnerabilities affecting its SMA 1000 series of remote access appliances, potentially allowing attackers to gain unauthorized access and execute administrative commands on affected systems. The flaws, discovered by security researchers using artificial intelligence-powered tools, have sparked concerns among organizations that rely on the widely-used … Read more

Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits

Nigeria’s rapid digital transformation has led to a surge in cyberattacks, with the average organization facing 4,361 attempted attacks per week. Despite a 46% drop in reported fraud incidents over four years, losses from those incidents have increased as cybercriminals create more lucrative schemes. The country’s economic liberalization efforts, including allowing its currency to float … Read more

US sanctions VPN, malware providers for enabling ransomware attacks

The US Treasury Department’s Office of Foreign Assets Control (OFAC) has taken a significant step in combating ransomware attacks against American organizations, sanctioning two individuals and one entity that enabled such crimes. The move targets First VPN Service (1VPNS), a virtual private network provider with ties to ransomware groups, as well as its administrator, Dmytro … Read more

New phishing kits target Microsoft 365 accounts, evade MFA

Cyberattackers have unleashed two sophisticated phishing kits that target Microsoft 365 accounts, exploiting vulnerabilities in multi-factor authentication (MFA) to gain unauthorized access. The Jalisco and OmegaLord toolkits, analyzed by cybersecurity firm ReliaQuest, demonstrate the evolving tactics of threat actors as they adapt to modern security measures. Jalisco employs a device-code phishing method to trick victims … Read more

US charges alleged operators of Russian bulletproof hosting service

The US government has taken a significant step in its ongoing fight against cybercrime, charging three Russian nationals with operating a bulletproof hosting (BPH) service that provided infrastructure to ransomware gangs responsible for over $62 million in damages worldwide. The indictment unsealed on Tuesday targets Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin, who allegedly owned … Read more

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

A pair of zero-day vulnerabilities, discovered in SonicWall’s SMA 1000 series of secure remote access appliances, have been exploited in the wild, potentially allowing attackers to execute arbitrary system commands with admin privileges. The news has significant implications for organizations that rely on these devices for secure access to their networks. The two flaws, identified … Read more