loader image
SmartAttack Uses Smartwatches to Hack Air-Gapped PCs

A newly discovered cyberattack method, known as “SmartAttack,” leverages smartwatches to exfiltrate sensitive data from air-gapped systems, according to findings reported this week. The technique employs the built-in sensors of smartwatches to receive covert ultrasonic signals emitted by compromised devices within isolated environments. These air-gapped systems, typically disconnected from external networks for enhanced security, are […]

Russia Frees Convicted REvil Hackers After Time Served

A Russian court has released four convicted members of the notorious REvil ransomware group after ruling that their prison time already served satisfied their sentences. The decision came after the court found them guilty of computer-related crimes, concluding a rare prosecution of cybercriminals inside Russia. The case drew attention as Russia frees convicted REvil members […]

British Hacker ‘IntelBroker’ Charged in $25M Theft

A British citizen known online as IntelBroker has been charged by U.S. authorities for a series of cyberattacks that allegedly resulted in $25 million in damages. The individual reportedly stole and sold sensitive data from dozens of victims, targeting both private entities and public organizations. British hacker IntelBroker charged in connection with these breaches is […]

Dark Partners Gang Drives Global Crypto Thefts Spree

A cybercrime group known as “Dark Partner” is orchestrating widespread cryptocurrency thefts by leveraging a global network of fake software download sites, according to cybersecurity researchers. The fraud operation uses deceptive platforms that appear to offer artificial intelligence tools, virtual private networks (VPNs), and crypto-related applications to lure unsuspecting users. Once downloaded, the malicious software […]

Microsoft, CrowdStrike Unite to Standardize Hacker Names

Microsoft and CrowdStrike are spearheading a new initiative to standardize threat actor naming conventions across the cybersecurity industry. The joint project, which includes support from Google and Palo Alto Networks, seeks to map and align the disparate labels currently used by different organizations to identify the same cyber threat groups. The lack of standardized naming […]

40,000 Security Cameras Exposed, Spark Spy Fears

More than 40,000 internet-connected security cameras have been found exposed online, raising concerns over potential espionage, data breaches and privacy violations, according to a report from SC World. The vulnerable devices, lacking adequate protection, could allow unauthorized parties to monitor sensitive areas including data centers, corporate offices, retail locations and private homes. The exposure of […]

Fog Ransomware Wields Spyware, Pentesting Tools

Fog ransomware operators are deploying an unusual combination of spyware, pentesting tools, and legitimate software in their latest cyberattacks, raising concerns among security analysts. The attackers leverage open-source penetration testing utilities alongside Syteca, a legitimate employee monitoring software, to infiltrate and control targeted systems. This blend of authorized and unauthorized tools complicates detection efforts, allowing […]

Teens Recruited as Hitmen via Encrypted Messaging Apps

Criminal networks are exploiting encrypted messaging platforms to expand a disturbing underground industry known as violence-as-a-service. Authorities have reported that these groups use secure apps to recruit teenagers as hitmen, luring them with promises of quick money and anonymity. The trend has raised serious concerns among cybersecurity experts and law enforcement agencies across multiple countries. […]

Jira Tickets Used to Breach AI in Cato Networks Test

Security researchers at Cato Networks have demonstrated how Jira tickets used in internal workflows can become attack vectors through prompt injection exploits. The proof-of-concept attack, dubbed “living off AI,” reveals how external inputs can manipulate AI-driven systems that interface with enterprise applications. The attack leverages seemingly benign content embedded in Jira tickets, which AI tools […]

CISA Warns TP-Link Router Flaw Hit in Live Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has issued an alert about a security flaw affecting several outdated TP-Link router models. The vulnerability is currently being exploited in the wild, increasing the risk for organizations that still rely on the discontinued devices. CISA Warns TPLink Router users to take immediate action to protect their networks […]

China Hackers Spoof Certs to Deploy ShortLeash Malware

A cyber-espionage campaign with ties to China has deployed a new backdoor dubbed ShortLeash, using fraudulent digital certificates to evade detection. The campaign, identified as “LapDogs,” has targeted specific organizations by embedding the malware within seemingly legitimate software updates. Analysts say China hackers spoof certs to disguise malicious payloads and gain unauthorized access to systems. […]

Malware in AI Models on PyPI Hits Alibaba Users

Malicious actors have embedded malware within artificial intelligence models uploaded to the Python Package Index (PyPI), with a specific focus on compromising users affiliated with Alibaba’s AI Labs. The attack involves the distribution of seemingly legitimate AI models that, once downloaded, execute hidden malicious code on the target systems. The tactic exploits the growing reliance […]