CISA looks to remedy ailments from big May credential leak

**CISA Takes Action After Major Credential Leak** The Cybersecurity and Infrastructure Security Agency (CISA) has taken significant steps to strengthen its defenses and improve incident response after a major credential leak in May. The agency’s sensitive materials were exposed when a contractor leaked privileged Amazon AWS GovCloud Keys on a public GitHub repository, prompting CISA … Read more

Armenian national pleads guilty to Ryuk ransomware attacks

A Notorious Ransomware Player Bites the Dust: Armenian National Pleads Guilty in Ryuk Attacks Karen Serobovich Vardanyan, a 34-year-old Armenian national, has pleaded guilty to participating in a series of high-profile ransomware attacks involving the notorious Ryuk malware. Between November 2019 and April 2020, Vardanyan and his co-conspirators deployed Ryuk against three US-based organizations, extorting … Read more

Australia warns of global campaign targeting vulnerable CMS platforms

A Global Campaign of Cyber Attacks Targeting Vulnerable CMS Platforms Has Been Unleashed, Warns Australia’s Cyber Security Centre Australian businesses are being warned about a massive global campaign targeting vulnerable content management systems (CMS) and plugins. The Australian Cyber Security Centre (ACSC) has issued an alert stating that many small to medium-sized enterprises in the … Read more

‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism

A New Attack Vector Emerges: ‘HalluSquatting’ Turns AI Hallucinations into Botnet Delivery Mechanism Researchers have uncovered a novel attack technique that exploits the tendency of artificial intelligence (AI) assistants to “hallucinate” or generate false information. Dubbed “HalluSquatting,” this method leverages the ability of AI tools to create fake resources and packages, allowing attackers to create … Read more

GigaWiper Combines Multiple Malware for System-Level Sabotage

A Sophisticated Threat Actor’s Tool of Choice: GigaWiper Microsoft has been tracking a highly destructive malware, dubbed GigaWiper, that has been wreaking havoc on Windows systems for over eight months. This sophisticated threat combines multiple malware families and boasts robust command-and-control (C&C) capabilities, making it a powerful tool in the hands of a skilled threat … Read more

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta Warns of Sophisticated Vishing Campaign Targeting Microsoft 365 Customers A highly targeted vishing campaign is underway, with hackers using social engineering tactics to trick Microsoft 365 users into divulging their login credentials. The attacks, which began in April, have been observed by Okta and are being tracked as O-UNC-066. The hacking group behind the … Read more

China, India-Linked Hackers Both Targeted Same Pakistani Police Force

Cyberspies from China and India Caught Snooping on Pakistani Police Networks In a shocking revelation, researchers at SentinelOne have uncovered a two-year-long cyberespionage campaign targeting Pakistani law enforcement networks, with both Chinese and Indian-linked hackers sneaking into the same police force’s systems. The Balochistan Police, which has been caught in the middle of the rivalries … Read more

‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets

**Malicious Image Exploit Leaks Secrets from AI-Coded Repositories** Researchers at the University of Missouri-Kansas City’s ASSET Research Group have unveiled a novel technique for stealing sensitive information from code repositories. Dubbed “Ghostcommit,” this exploit takes advantage of a review gap in popular coding agents to inject malicious instructions into images, which are then executed by … Read more

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

Okta Sounds Alarm on Sophisticated Vishing Attacks Targeting Microsoft 365 Users A wave of highly targeted and sophisticated vishing attacks is currently sweeping through various industries, with threat actors aiming to harvest sensitive information from unsuspecting Microsoft 365 users. The campaign, which kicked off in April, has been linked to a hacking group known as … Read more

China, India-Linked Hackers Both Targeted Same Pakistani Police Force

Pakistani Police Networks Breached by China and India-Linked Hackers A recent investigation has uncovered a sophisticated cyberespionage campaign that targeted the Balochistan Police force in Pakistan, with hackers linked to both China and India quietly breaching their networks over a period of two years. The attackers gained access to sensitive data, including biometric databases, criminal … Read more