loader image
Google Uncovers Chrome Zero-Day Tied to Spyware

Google’s Threat Analysis Group has identified a zero-day vulnerability in the Chrome web browser that may have been exploited by commercial spyware vendors. The flaw, which was discovered recently, has raised concerns about the potential misuse of browser vulnerabilities by surveillance software developers. While technical details about the vulnerability have not been disclosed, the incident […]

Mirai Botnet Hijacks DVRs Using New CVE Exploit

A newly discovered variant of the Mirai botnet is exploiting a critical vulnerability, CVE-2024-3721, in TBK DVR-4104 and DVR-4216 digital video recorders, according to researchers from cybersecurity firm Kaspersky. The malware uses a direct infection method, bypassing architecture detection by deploying an ARM32 binary—tailored to the devices’ specifications—via a malicious POST request. Unlike earlier Mirai […]

Passion.io Leak Exposes Data of 3.6 Million Users

A misconfigured database has exposed the personal information of approximately 3.6 million creators using Passion.io, a platform that helps users build custom mobile apps. The unsecured database, left accessible without authentication, reportedly contained sensitive user data, including names, email addresses, and other identifiable information. The breach was discovered by security researchers who found that the […]

SmartAttack Uses Smartwatches to Hack Air-Gapped PCs

A newly discovered cyberattack method, known as “SmartAttack,” leverages smartwatches to exfiltrate sensitive data from air-gapped systems, according to findings reported this week. The technique employs the built-in sensors of smartwatches to receive covert ultrasonic signals emitted by compromised devices within isolated environments. These air-gapped systems, typically disconnected from external networks for enhanced security, are […]

Russia Frees Convicted REvil Hackers After Time Served

A Russian court has released four convicted members of the notorious REvil ransomware group after ruling that their prison time already served satisfied their sentences. The decision came after the court found them guilty of computer-related crimes, concluding a rare prosecution of cybercriminals inside Russia. The case drew attention as Russia frees convicted REvil members […]

British Hacker ‘IntelBroker’ Charged in $25M Theft

A British citizen known online as IntelBroker has been charged by U.S. authorities for a series of cyberattacks that allegedly resulted in $25 million in damages. The individual reportedly stole and sold sensitive data from dozens of victims, targeting both private entities and public organizations. British hacker IntelBroker charged in connection with these breaches is […]

Société Générale Intern Aided SIM Swap Scam, 50 Hit

French authorities have arrested a business student interning at Société Générale for allegedly assisting cybercriminals in a SIM-swapping scheme that targeted 50 bank clients. The Société Générale intern aided scammers by providing confidential customer data, enabling the attackers to hijack victims’ mobile phone numbers and gain unauthorized access to their bank accounts. The scam involved […]

Dark Partners Gang Drives Global Crypto Thefts Spree

A cybercrime group known as “Dark Partner” is orchestrating widespread cryptocurrency thefts by leveraging a global network of fake software download sites, according to cybersecurity researchers. The fraud operation uses deceptive platforms that appear to offer artificial intelligence tools, virtual private networks (VPNs), and crypto-related applications to lure unsuspecting users. Once downloaded, the malicious software […]

Microsoft, CrowdStrike Unite to Standardize Hacker Names

Microsoft and CrowdStrike are spearheading a new initiative to standardize threat actor naming conventions across the cybersecurity industry. The joint project, which includes support from Google and Palo Alto Networks, seeks to map and align the disparate labels currently used by different organizations to identify the same cyber threat groups. The lack of standardized naming […]

40,000 Security Cameras Exposed, Spark Spy Fears

More than 40,000 internet-connected security cameras have been found exposed online, raising concerns over potential espionage, data breaches and privacy violations, according to a report from SC World. The vulnerable devices, lacking adequate protection, could allow unauthorized parties to monitor sensitive areas including data centers, corporate offices, retail locations and private homes. The exposure of […]

Fog Ransomware Wields Spyware, Pentesting Tools

Fog ransomware operators are deploying an unusual combination of spyware, pentesting tools, and legitimate software in their latest cyberattacks, raising concerns among security analysts. The attackers leverage open-source penetration testing utilities alongside Syteca, a legitimate employee monitoring software, to infiltrate and control targeted systems. This blend of authorized and unauthorized tools complicates detection efforts, allowing […]

Teens Recruited as Hitmen via Encrypted Messaging Apps

Criminal networks are exploiting encrypted messaging platforms to expand a disturbing underground industry known as violence-as-a-service. Authorities have reported that these groups use secure apps to recruit teenagers as hitmen, luring them with promises of quick money and anonymity. The trend has raised serious concerns among cybersecurity experts and law enforcement agencies across multiple countries. […]