SAP warns of critical flaws in NetWeaver and Commerce Cloud

A trio of critical security vulnerabilities has been discovered in SAP’s NetWeaver and Commerce Cloud platforms, prompting the software giant to issue a warning to its customers. The flaws, which affect thousands of organizations worldwide, could allow attackers to gain unauthorized access to sensitive data, disrupt system availability, or even launch denial-of-service attacks. At stake … Read more

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A massive cyberattack, unfolding on July 13th, has left the open-source community reeling as it’s been revealed that over 148 npm packages have been compromised and repurposed as student proxies turned DDoS botnet. The malicious code, discovered in various package repositories, has successfully infiltrated thousands of user systems, putting a significant number of organizations at … Read more

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

The US government has taken a bold step in its ongoing battle against ransomware, imposing sanctions on a VPN service and a malware cryptor seller that allegedly provided support to malicious actors. The move marks a significant escalation in the fight against cybercrime, highlighting the need for organizations to prioritize cybersecurity measures. The sanctioned entities, … Read more

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

A shocking revelation has come to light about an AI-powered software development tool called Grok Build, which has been uploading entire Git repositories to its parent company’s storage server, xAI. This means that sensitive data and intellectual property (IP) stored in these repositories have been copied without users’ knowledge or consent. Grok Build is a … Read more

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

The Pentagon has suspended the second phase of its Cybersecurity Maturity Model Certification (CMMC) program, which was set to kick in next month. This move is a significant development in the ongoing effort to strengthen cybersecurity standards for companies working on government contracts. The CMMC program aims to verify that contractors handling sensitive information meet … Read more

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

A Major Salesforce Security Breach Exposed: Microsoft Uncovers Three Attack Paths Linked to ShinyHunters Activity Microsoft has released a security alert revealing that attackers have exploited three distinct paths into Salesforce’s systems, leading to potential unauthorized access and data breaches. The vulnerability stems from an AI-powered attack, demonstrating the growing threat of artificial intelligence in … Read more

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A massive malware campaign, disguised as innocuous npm packages, has infected thousands of computers worldwide, transforming them into unwitting participants in a powerful DDoS botnet. The attack, which has been linked to a sophisticated AI-powered discovery process, has left security experts scrambling to understand the scope and implications of this unprecedented threat. The compromised software, … Read more

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

The US government has taken an unprecedented step in its fight against ransomware, slapping sanctions on a VPN service and a malware cryptor seller for their alleged role in supporting cybercrime operations. The move marks a significant escalation in the battle against online extortion gangs, which have been wreaking havoc globally. At the center of … Read more

EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign

The European Union has taken a decisive step against Russian cyber espionage, imposing sanctions on nine individuals and four entities accused of participating in a yearslong campaign to undermine EU governments and critical infrastructure. The move targets those responsible for a sprawling online spying network that has been active since 2010, with attacks detected in … Read more