Microsoft expects more Windows security updates from AI-discovered flaws

As AI-powers its vulnerability discovery capabilities, Microsoft is bracing users for an influx of Windows security updates. In a recent blog post, the tech giant revealed that advances in artificial intelligence have significantly accelerated the pace of vulnerability discovery, allowing engineers to identify more security issues before they can be exploited in zero-day attacks. This … Read more

New Helix vishing group emerges in SharePoint data theft attacks

A new and highly effective data-extortion group has emerged, targeting organizations through a combination of identity-focused tactics and social engineering. The group, known as Helix, has already been linked to several high-profile attacks against companies such as Medtronic, Nissan, and Kodak. Helix’s modus operandi involves initial contact with employees via voice phishing (vishing) calls, where … Read more

OpenMandriva Linux says contributor tried to sabotage the project

OpenMandriva Linux Project Bites Back After Attempted Sabotage A disturbing incident has unfolded within the OpenMandriva Linux community, with a contributor accused of attempting to sabotage the project. The alleged attempt involved deleting crucial repositories and pushing an empty package that could have caused harm to users’ systems. What’s more concerning is that this act … Read more

Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure

Iran’s cyber operations have long been a source of concern, with many assuming that only critical infrastructure is at risk. However, recent attacks demonstrate that this assumption is misguided. The groups behind these incidents, including Handala and Ababil of Minab, are not simply targeting high-profile targets; they are instead on the hunt for easily exploited … Read more

Injective SDK on npm infected with cryptocurrency wallet stealer

A malicious package on the Node Package Manager (npm) has compromised thousands of developer systems, targeting cryptocurrency wallets and stealing private keys and mnemonic seed phrases. The Injective Labs SDK project’s GitHub repository was hacked, allowing attackers to publish a malicious version of the @injectivelabs/sdk-ts npm package. This supply-chain attack highlights the importance of securing … Read more

OpenMandriva Linux says contributor tried to sabotage the project

OpenMandriva Linux Project Hit by Attempted Internal Sabotage A long-running dispute among contributors to the OpenMandriva Linux project has escalated into an attempted act of internal sabotage. The perpetrator, Davide Beatrici, a leading developer of the instant messaging app Mumble and a friend of the attacker, deliberately deleted crucial repositories and pushed an empty package … Read more

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

A devastating new backdoor has been discovered lurking in Windows systems, capable of unleashing a triple threat of malware on unsuspecting users. Dubbed GigaWiper, this cunning piece of code combines the destructive power of disk wiping, the deceitful tactics of fake ransomware, and the stealthy capabilities of spyware to wreak havoc on compromised machines. GigaWiper’s … Read more

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

As attackers continue to refine their tactics, a new trend is emerging that highlights the importance of cybersecurity vigilance. Dormant GitHub accounts are being exploited to blend in with legitimate users and gain insight into corporate organizational structures – all without raising suspicion. This stealthy approach has left many organizations scrambling to re-evaluate their security … Read more

Injective SDK on npm infected with cryptocurrency wallet stealer

A critical security vulnerability has been discovered in a popular Node Package Manager (npm) package, allowing hackers to steal cryptocurrency wallet private keys and mnemonic seed phrases. The Injective SDK project’s GitHub repository was compromised, leading to the publication of a malicious package on npm that has already been downloaded over 50,000 times. The affected … Read more

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

Cloud Bucket Hijacking, Windows LPE Chain, and Global Fraud Bust Exposed in Recent Threat Landscape Updates A series of alarming security threats has been exposed in recent days, with hackers targeting cloud storage buckets, exploiting a previously unknown vulnerability in Windows systems, and engaging in large-scale global fraud. In this article, we’ll take a closer … Read more