loader image
Google Calendar Abused to Hide Stealthy NPM Malware

A newly discovered malicious package in the NPM ecosystem is leveraging Google Calendar as a covert communication channel, allowing attackers to evade traditional detection mechanisms. The malware uses the calendar service as a “middleman” to receive commands and exfiltrate data, masking its activity behind legitimate infrastructure. In addition to this novel approach, the package employs […]

SAP Cyberattack Spreads, Echoes Typhoon APT Tactics

A wave of zero-day cyberattacks targeting SAP, Europe’s largest software maker, is expanding, with hundreds of victims identified globally. The scale and sophistication of the campaign have drawn comparisons to operations conducted by Salt Typhoon and Volt Typhoon—advanced threat groups linked to state-backed cyber activity. Although the full extent of the breach remains unclear, the […]

Zimbra Hack Hits 129,000 Servers; Sednit Suspected

A critical cross-site scripting (XSS) vulnerability tracked as CVE-2024-27443 has impacted more than 129,000 Zimbra Collaboration Suite servers worldwide, according to cybersecurity sources. The flaw has drawn scrutiny due to suspected exploitation by Sednit, a threat group believed to have ties with advanced persistent threat operations. The vulnerability allows attackers to inject malicious scripts into […]

Coinbase Fires Staff After Breach Hits 70,000 Users

Coinbase has confirmed that an internal breach compromised the personal data of approximately 70,000 users, following the discovery that support staff were bribed. The cryptocurrency exchange said the involved employees have been identified and terminated. The breach raises concerns about insider threats within digital asset platforms, particularly as Coinbase continues to expand its global operations. […]

Cybersecurity Pay 2025 Rises for Top Tech, Falls Elsewhere

Cybersecurity salaries are showing notable divergence heading into 2025, with specialized roles commanding higher pay while generalist and support positions see compensation stagnate, according to CyberSN’s 2025 Salary Data Report. The report highlights growing demand for advanced technical expertise and leadership capabilities, which are driving salary increases for professionals in those segments. In contrast, positions […]

O2 UK Fixes Flaw That Exposed Caller Location Data

O2 UK has addressed a security vulnerability in its implementation of Voice over LTE (VoLTE) and WiFi Calling technologies that exposed mobile users’ general location and unique identifiers. The flaw allowed anyone who placed a call to a target number to potentially extract sensitive metadata, including details that could reveal the recipient’s approximate whereabouts. The […]

UTC Joins ISASecure to Boost Utility Cyber Standards

The Utilities Technology Council (UTC) has joined ISASecure, a globally recognized cybersecurity certification program, in a move aimed at bolstering cybersecurity standards across utility infrastructure. The collaboration is expected to enhance the resilience of operational technology (OT) systems that underpin critical utility services. By aligning with ISASecure, UTC seeks to advance the development and implementation […]

Self-Spreading Malware Turns Docker into Dero Botnet

A newly discovered malware strain is targeting misconfigured Docker API endpoints, transforming exposed containers into nodes of a growing botnet used to mine Dero cryptocurrency. The campaign is distinguished by its self-propagating, worm-like behavior, allowing the malware to autonomously spread to other vulnerable Docker instances without requiring manual intervention. Security researchers at Kaspersky observed the […]

AVCheck Takedown Hits Cybercrime Malware Testing Network

Law enforcement agencies from the U.S., Europe, and other international partners have dismantled AVCheck, a cybercriminal platform used to test and encrypt malware to evade antivirus detection. Officials seized four domains and associated servers as part of Operation Endgame, a multinational crackdown on malware infrastructure. AVCheck offered counter-antivirus (CAV) services and crypting tools, enabling cybercriminals […]

SentinelOne Outage Blamed on Critical Software Bug

SentinelOne experienced hours-long network connectivity disruptions last Thursday due to a vulnerability in its infrastructure control systems, according to a report by Cybersecurity Dive. The issue resulted in the deletion of essential network routes and DNS resolver rules, impacting the company’s ability to maintain stable connections across its platform. The outage affected a broad range […]

DragonForce Ransomware Hits 120 Victims in One Year

DragonForce, a ransomware group that surfaced in late 2023, has claimed responsibility for over 120 cyberattacks globally, establishing itself as a major player in the cybercrime ecosystem. According to Bitdefender, the group has evolved beyond the traditional ransomware-as-a-service model into a cartel-like structure, offering affiliates up to 80% of ransom proceeds and centralized resources such […]

Lee Enterprises Hack Exposes 40,000 Social Security IDs

Lee Enterprises, one of the largest newspaper publishers in the U.S., disclosed that nearly 40,000 Social Security numbers were exposed during a ransomware attack that struck the company in February. The breach caused significant operational disruptions across its network of publications. In a regulatory filing submitted to authorities in Maine, the media company confirmed the […]