Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

A newly discovered set of vulnerabilities in U-Boot, a popular open-source bootloader used in millions of devices worldwide, could allow attackers to crash or hijack devices during boot-up. The six flaws were uncovered by researchers using artificial intelligence (AI) models, highlighting the growing importance of AI-driven security testing. The affected devices include a wide range … Read more

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

A Malicious Operation Unfolds on GitHub: Wallet-Key-Stealing npm Packages Exposed Researchers have discovered a sophisticated operation on GitHub, where malicious actors exploited the platform’s weaknesses to push wallet-key-stealing packages to unsuspecting developers. The compromised accounts belong to Injective Labs, a blockchain development company, and the affected users are likely those who have installed the tainted … Read more

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress, the software giant behind the ShareFile file-sharing platform, is urging its customers to shut down Storage Zone Controllers (SZCs) due to a critical security threat. This move affects thousands of businesses worldwide, emphasizing the need for swift action to prevent potential data breaches and system compromises. ShareFile’s SZCs are essentially on-premises servers that act … Read more

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A notorious ransomware negotiator, who made headlines for facilitating lucrative attacks on behalf of the BlackCat gang, has been sentenced to 70 months in prison. The individual’s conviction serves as a stark reminder that the underworld of cybercrime is not just a distant threat, but a tangible reality with real-world consequences. The accused, a self-proclaimed … Read more

Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

A sophisticated cyberattack has left cryptocurrency enthusiasts reeling, with over $5 million drained from wallets due to an exploit of the “Ill Bloom” vulnerability. The attack targets users of several popular cryptocurrency exchanges and wallets, leaving a trail of financial losses in its wake. The Ill Bloom vulnerability is a type of software bug that … Read more

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

**RAT with gRPC Streaming Threatens Organizations Globally** A new Remote Access Trojan (RAT) called MODBEACON has been spotted in the wild, leveraging advanced technologies like gRPC streaming to evade detection and maintain encrypted command and control (C2) traffic. This sophisticated malware variant is a significant threat to organizations worldwide, putting sensitive data at risk of … Read more

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Researchers have uncovered a sophisticated attack chain that leverages three previously unknown vulnerabilities in WhatsApp, allowing hackers to remotely execute malicious code on targeted devices with complete control over the host system. Dubbed “OpenClaw,” this alarming discovery highlights the escalating threat landscape of AI-driven attacks. The OpenClaw exploit chain hinges on a combination of three … Read more

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A Massive Backdoor Campaign Exposed: Thousands of WordPress Sites Compromised Through WP-SHELLSTORM In a shocking revelation, an exposed hacker server has uncovered a massive backdoor campaign targeting thousands of WordPress sites worldwide. The malware, known as WP-SHELLSTORM, has been quietly infecting websites for months, leaving their owners vulnerable to cyber attacks and data breaches. WP-SHELLSTORM … Read more

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Cybersecurity experts at Lumen Technologies have made significant strides in rebuilding their exposure management systems, reducing the number of vulnerable assets from 17,000 to just over 1.1 million. This massive overhaul was necessitated by the increasing sophistication of AI-powered vulnerability discovery tools, which can identify vulnerabilities that human security teams may miss. To put this … Read more