US sanctions VPN, malware providers for enabling ransomware attacks

The US Treasury Department’s Office of Foreign Assets Control (OFAC) has taken a significant step in combating ransomware attacks against American organizations, sanctioning two individuals and one entity that enabled such crimes. The move targets First VPN Service (1VPNS), a virtual private network provider with ties to ransomware groups, as well as its administrator, Dmytro … Read more

New phishing kits target Microsoft 365 accounts, evade MFA

Cyberattackers have unleashed two sophisticated phishing kits that target Microsoft 365 accounts, exploiting vulnerabilities in multi-factor authentication (MFA) to gain unauthorized access. The Jalisco and OmegaLord toolkits, analyzed by cybersecurity firm ReliaQuest, demonstrate the evolving tactics of threat actors as they adapt to modern security measures. Jalisco employs a device-code phishing method to trick victims … Read more

US charges alleged operators of Russian bulletproof hosting service

The US government has taken a significant step in its ongoing fight against cybercrime, charging three Russian nationals with operating a bulletproof hosting (BPH) service that provided infrastructure to ransomware gangs responsible for over $62 million in damages worldwide. The indictment unsealed on Tuesday targets Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin, who allegedly owned … Read more

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

A pair of zero-day vulnerabilities, discovered in SonicWall’s SMA 1000 series of secure remote access appliances, have been exploited in the wild, potentially allowing attackers to execute arbitrary system commands with admin privileges. The news has significant implications for organizations that rely on these devices for secure access to their networks. The two flaws, identified … Read more

You Don’t Have to Run an Exploit to Know If You’re Vulnerable

Cybersecurity’s Great Unevenness: Why Patching Just Isn’t Enough Anymore Imagine having to deal with a never-ending flood of new vulnerabilities, each one potentially threatening your organization’s security. That’s the reality for cybersecurity teams today, thanks to the explosive growth in newly disclosed flaws and the lightning-fast pace at which attackers can turn them into working … Read more

LastPass, Bitwarden users targeted with fake security alerts

A sophisticated phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to trick them into divulging sensitive information. The attackers are using email notifications that appear to be from the password management services, but actually lead to malicious websites that prompt victims to download files or enter their credentials. LastPass has … Read more

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

A High-Severity Vulnerability Forces ShareFile to Shut Down Storage Zone Controllers, Urges Customers to Patch Immediately Progress Software has confirmed that a high-severity zero-day vulnerability is behind the sudden shutdown of ShareFile Storage Zone Controllers last week. The company acted out of caution after receiving information from a credible source about a potential threat and … Read more

Windows 11 KB5101650 & KB5099414 cumulative updates released

Windows 11 Receives Mandatory Security Updates, Alongside Long-Awaited Features and Fixes Microsoft has rolled out two critical cumulative updates for Windows 11, KB5101650 and KB5099414, which address a staggering 571 security vulnerabilities discovered over the past few months. These patches are mandatory, as they include the latest July Patch Tuesday fixes. If you’re running Windows … Read more

Microsoft Entra ID gets passkeys default authentication starting September

In a significant move to bolster account security and reduce reliance on vulnerable authentication methods, Microsoft has announced that passkeys will become the default authentication method for its Entra ID enterprise identity service starting September this year. This change is expected to impact millions of users worldwide who currently rely on phone-based SMS and voice … Read more