Category: Uncategorized
-

DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM [email protected] (The Hacker News)
The U.S. Department of Justice (DoJ) on Tuesday resentenced the former administrator of BreachForums to three years in prison in connection with his role in running the cybercrime forum and possessing child sexual abuse material (CSAM). Conor Brian Fitzpatrick (aka Pompompurin), 22, of Peekskill, New York, pleaded guilty to one count of access device conspiracy,…
-
APT 41 – Indictments of Nation State Actors Involved in a Global Hacking Campaign
This week, the United States Department of Justice (USDOJ) indicted five Chinese nationals for hacking into the networks of over 100 companies in a global cyber crime campaign. According to the press release, the industries attacked included software development companies, computer hardware manufacturers, telecommunications providers, social media companies, video game companies, non-profit organizations, universities, think…
-
SigRed: CVE-2020-1350 Windows DNS Server Remote Code Execution Vulnerability
The Microsoft Patch Tuesday release for July 14, 2020 contains (123) reported disclosures. This month’s release has one critical vulnerability in Microsoft Windows Server (CVE-2020-1350) that allows for remote code execution by an unauthenticated attacker. It also has been confirmed by Microsoft to be wormable; devoid of user interaction. What are the specifics of the…
-

RaccoonO365 Phishing Network Shut Down After Microsoft and Cloudflare Disrupt 338 Domains [email protected] (The Hacker News)
Microsoft’s Digital Crimes Unit said it teamed up with Cloudflare to coordinate the seizure of 338 domains used by RaccoonO365, a financially motivated threat group that was behind a phishing-as-a-service (Phaas) toolkit used to steal more than 5,000 Microsoft 365 credentials from 94 countries since July 2024. “Using a court order granted by the Southern…
-
Citrix NetScaler ADC and NetScaler RCE
What is the Vulnerability? FortiGuard Labs has observed active network telemetry relating to CVE-2025-7775, a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that enables remote code execution (RCE) and denial of service (DoS) under certain pre-conditions. Exploitation on unpatched appliances has been confirmed, and CISA has added the vulnerability to its Known Exploited…
-

Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover [email protected] (The Hacker News)
Cybersecurity researchers have disclosed multiple critical security vulnerabilities in Chaos Mesh that, if successfully exploited, could lead to cluster takeover in Kubernetes environments. “Attackers need only minimal in-cluster network access to exploit these vulnerabilities, execute the platform’s fault injections (such as shutting down pods or disrupting network communications), and performRead More
-

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids [email protected] (The Hacker News)
A massive ad fraud and click fraud operation dubbed SlopAds ran a cluster of 224 apps, collectively attracting 38 million downloads across 228 countries and territories. “These apps deliver their fraud payload using steganography and create hidden WebViews to navigate to threat actor-owned cashout sites, generating fraudulent ad impressions and clicks,” HUMAN’s Satori Threat Intelligence…
-

New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site [email protected] (The Hacker News)
Cybersecurity researchers have warned of a new campaign that’s leveraging a variant of the FileFix social engineering tactic to deliver the StealC information stealer malware. “The observed campaign uses a highly convincing, multilingual phishing site (e.g., fake Facebook Security page), with anti-analysis techniques and advanced obfuscation to evade detection,” Acronis security researcher EliadRead More
-

Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack [email protected] (The Hacker News)
Apple on Monday backported fixes for a recently patched security flaw that has been actively exploited in the wild. The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds write issue in the ImageIO component that could result in memory corruption when processing a malicious image file. “Apple is aware of a report that…
-

Securing the Agentic Era: Introducing Astrix’s AI Agent Control Plane [email protected] (The Hacker News)
AI agents are rapidly becoming a core part of the enterprise, being embedded across enterprise workflows, operating with autonomy, and making decisions about which systems to access and how to use them. But as agents grow in power and autonomy, so do the risks and threats. Recent studies show 80% of companies have already experienced…
