loader image
SonicWall Warns NetExtender Tool Hijacked by Trojan

SonicWall warns NetExtender tool users to be on alert after discovering a tampered version of the application embedding data-theft capabilities. The company identified that attackers modified the legitimate NetExtender VPN client, inserting malicious code designed to capture user information. This development raises concerns for enterprises relying on the tool for secure remote access. According to […]

U.S. Seizes $7.7 Million, Nabs North Korea IT Agent

The U.S. Department of Justice on Monday announced the arrest of a key figure linked to North Korea’s illicit IT worker scheme. In a coordinated operation, authorities seized nearly $7.7 million tied to the network’s activities. The Justice Department also confiscated 29 financial accounts, dismantled 21 fraudulent websites, and took control of nearly 200 computers […]

Facebook Ad Scams Lure Victims With Fake Investors

Cybersecurity analysts have uncovered two sophisticated investment scam operations that leverage Facebook advertisements, deceptive domains, and IP-based filtering to target victims. Identified by DNS threat intelligence firm Infoblox as “Reckless Rabbit” and “Ruthless Rabbit,” the campaigns employ spoofed celebrity endorsements to lure users into fraudulent schemes. The scams are structured around traffic distribution systems (TDSes), […]

Malicious PyPI Code Hid RAT Targeting Discord Devs

A malicious Python package uploaded to the Python Package Index (PyPI) has been discovered delivering remote access trojan (RAT) malware, with its activity traced back to 2022. The package specifically targets developers involved with Discord, a popular communication platform used by both gamers and developers. Despite being available on PyPI for more than three years, […]

CISA Moves Security Alerts to Musk’s X, Email Updates

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has altered how it disseminates updates on security vulnerabilities, shifting its notifications to the social media platform X and email alerts. The move marks a significant change in the way the federal agency communicates with cybersecurity professionals and the public, as it steps away from more traditional […]

ASUS Fixes Flaws in DriverHub That Risked RCE

ASUSTeK Computer Inc. has issued patches addressing two security vulnerabilities in its DriverHub utility, according to a report from The Hacker News. The flaws, if left unremedied, could have enabled attackers to execute arbitrary code remotely on affected systems. The company released the updates to mitigate the risks associated with the bugs, which posed a […]

Proofpoint to Buy Hornetsecurity in $1 Billion Deal

Proofpoint has reached an agreement to acquire Germany-based Hornetsecurity Group in a deal valued at over $1 billion, the companies announced. The acquisition will expand Proofpoint’s capabilities in cloud-based email and collaboration security, particularly for Microsoft 365 environments. Hornetsecurity provides a suite of security tools tailored for Microsoft’s productivity platform, including email filtering, backup, and […]

SK Telecom Hack Exposes 26 Million Mobile IDs

SK Telecom, South Korea’s largest wireless carrier, has disclosed a major cybersecurity breach involving a stealthy malware attack that persisted undetected for two years. The breach resulted in the unauthorized leakage of approximately 26 million International Mobile Subscriber Identity (IMSI) records—unique identifiers tied to mobile users and critical for network authentication and tracking. The attack, […]

Hackers Target macOS With Fake Ledger Apps, Steal Crypto

Hackers are ramping up efforts to compromise macOS users by deploying malware through counterfeit versions of Ledger Live, the software used to manage Ledger hardware cryptocurrency wallets, according to research by Moonlock. Since August 2024, at least four distinct campaigns have been identified, with attackers refining tactics to bypass Apple’s security measures and steal users’ […]

EvilWorker Hijacks Browsers in Stealthier Phishing Blitz

A newly surfaced adversary-in-the-middle (AiTM) attack framework known as “EvilWorker” is gaining attention within the cybersecurity community for its innovative use of service workers to intercept and manipulate web traffic. Highlighted in a recent post on the r/netsec forum, EvilWorker is being compared to the widely known Evilginx2 tool, with users suggesting it may be […]

O2 Flaw Let Callers Track Users’ Locations Since 2017

A critical flaw in O2 UK’s Voice over LTE (VoLTE) service exposed the real-time location and device identifiers of its mobile customers during phone calls, according to a recent disclosure. The vulnerability, present since the service’s launch in March 2017, leaked sensitive data—including IMSI, IMEI, and precise cell tower information—via improperly configured SIP headers in […]

KrebsOnSecurity Hit by Record 6.3 Tbps DDoS Blast

Cybersecurity news site KrebsOnSecurity was targeted in a massive distributed denial-of-service (DDoS) attack that peaked at 6.3 terabits per second, according to HackRead. The attack was reportedly carried out by the Aisuru botnet, a network of compromised devices used to flood websites with traffic in an attempt to disrupt access. The scale of the incident […]