News
Suspected Chinese cybersnoop grounded in Italy after US tipoff
A man who US authorities allege is a member of Chinese state-sponsored cyberespionage outfit Silk Typhoon was arrested in Milan last week following a tipoff from the US embassy.…
Is your password ecosystem ready for the regulators?
Sponsored feature It's 2025, and credential theft is a thing of the past.…
Suspected Scattered Spider domains target everyone from manufacturers to Chipotle
While the aviation industry has borne the brunt of Scattered Spider's latest round of social engineering attacks, the criminals aim to catch manufacturing and medical tech companies — and even Chipotle Mexican Grill — in tjeor web, as evidenced by hundreds of domains that security researchers say look a lot like phishing websites used by the criminal crews.…
CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands
Multiple exploits are circulating for CVE-2025-5777, a critical bug in Citrix NetScaler ADC and NetScaler Gateway dubbed CitrixBleed 2, and security analysts are warning a "significant portion" of users still haven't patched.…
Phishing platforms, infostealers blamed as identity attacks soar
A rise in advanced phishing kits and info-stealing malware are to blame for a 156 percent jump in cyberattacks targeting user logins, say researchers.…
Stalkerware firm gets scooped by SQL-slinging security snoop
Infosec In Brief A security researcher looking at samples of stalkerware discovered an SQL vulnerability that allowed him to steal a database of 62,000 user accounts. …
Ingram Micro confirms ransomware behind multi-day outage
Ingram Micro, one of the world’s largest distributors, has confirmed it is trying to restore systems following a ransomware attack.…
Massive spike in use of .es domains for phishing abuse
Cybersecurity experts are reporting a 19x increase in malicious campaigns being launched from .es domains, making it the third most common, behind only .com and .ru.…
Microsoft Windows Firewall complains about Microsoft code
A mysterious piece of "under development" code is playing havoc with the Windows Firewall after the latest preview update for Windows 11 24H2.…
Young Consulting finds even more folks affected in breach mess – now over 1 million
Young Consulting's cybersecurity woes continue after the number of affected individuals from last year's suspected ransomware raid passed the 1 million mark.…
Meta calls €200M EU fine over pay-or-consent ad model 'unlawful'
Meta has come out swinging following the European Commission's decision that its pay-or-consent model falls foul of the Digital Markets Act (DMA).…
Ransomware crew Hunters International shuts down, hands out keys to victims
Ransomware gang Hunters International has shut up shop and offered decryption keys to all victims as a parting favor.…
Let's Encrypt rolls out free security certs for IP addresses
Let's Encrypt, a certificate authority (CA) known for its free TLS/SSL certificates, has begun issuing digital certificates for IP addresses.…
ChatGPT creates phisher’s paradise by recommending the wrong URLs for major companies
AI-powered chatbots often deliver incorrect information when asked to name the address for major companies’ websites, and threat intelligence business Netcraft thinks that creates an opportunity for criminals.…
Cisco scores a perfect 10 - sadly for a critical flaw in its comms platform
If you're running the Engineering-Special (ES) builds of Cisco Unified Communications Manager or its Session Management Edition, you need to apply Cisco's urgent patch after someone at Switchzilla made a big mistake.…
CISA warns the Signal clone used by natsec staffers is being attacked, so patch now
The US security watchdog CISA has warned that malicious actors are actively exploiting two flaws in the Signal clone TeleMessage TM SGNL, and has directed federal agencies to patch the flaws or discontinue use of the app by July 22.…
23andMe's new owner says your DNA is safe this time
The medical research nonprofit vying to buy 23andMe is informing existing customers that it plans to complete the deal on July 8.…
US drops sanctions on second Russian bulletproof hosting vehicle this year
The US Treasury has sanctioned Aeza Group, a Russian bulletproof hosting (BPH) provider, and four of its cronies for enabling ransomware and other cybercriminal activity.…
Cl0p cybercrime gang's data exfiltration tool found vulnerable to RCE attacks
Security experts have uncovered a hole in Cl0p's data exfiltration tool that could potentially leave the cybercrime group vulnerable to attack.…
UK eyes new laws as cable sabotage blurs line between war and peace
Cyberattacks and undersea cable sabotage are blurring the line between war and peace and exposing holes in UK law, a government minister has warned lawmakers.…
Pages
