Category: Uncategorized
-
New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide [email protected] (The Hacker News)
Cybersecurity researchers have uncovered a never-before-seen botnet comprising an army of small office/home office (SOHO) and IoT devices that are likely operated by a Chinese nation-state threat actor called Flax Typhoon (aka Ethereal Panda or RedJuliett). The sophisticated botnet, dubbed Raptor Train by Lumen’s Black Lotus Labs, is believed to have been operational since at…
-
Chinese Spies Built Massive Botnet of IoT Devices to Target US, Taiwan Military Ryan Naraine
Black Lotus Labs estimates that more than 200,000 routers, network-attached storage servers, and IP cameras have been ensnared in the botnet. The post Chinese Spies Built Massive Botnet of IoT Devices to Target US, Taiwan Military appeared first on SecurityWeek. Read More
-
Chinese Engineer Charged in U.S. for Years-Long Cyber Espionage Targeting NASA and Military [email protected] (The Hacker News)
A Chinese national has been indicted in the U.S. on charges of conducting a “multi-year” spear-phishing campaign to obtain unauthorized access to computer software and source code created by the National Aeronautics and Space Administration (NASA), research universities, and private companies. Song Wu, 39, has been charged with 14 counts of wire fraud and 14…
-
Threat Actors Target Accounting Software Used by Construction Contractors Ionut Arghire
Malicious hackers are caught brute-forcing Foundation Accounting Software at scale, compromising organizations in the construction industry. The post Threat Actors Target Accounting Software Used by Construction Contractors appeared first on SecurityWeek. Read More
-
North Korean Hackers Lure Critical Infrastructure Employees With Fake Jobs Eduard Kovacs
A North Korean group tracked as UNC2970 has been spotted trying to deliver new malware to people in the aerospace and energy industries. The post North Korean Hackers Lure Critical Infrastructure Employees With Fake Jobs appeared first on SecurityWeek. Read More
-
Australian Police Infiltrate Encrypted Messaging App Ghost and Arrest Dozens Associated Press
Australian police have infiltrated encrypted messaging app Ghost, which has been used for illegal activities, and arrested dozens of people. The post Australian Police Infiltrate Encrypted Messaging App Ghost and Arrest Dozens appeared first on SecurityWeek. Read More
-
CISA, FBI Urge Organizations to Eliminate XSS Vulnerabilities Ionut Arghire
CISA and the FBI have released an alert on XSS vulnerabilities, urging organizations to adopt a secure by design approach and eliminate them. The post CISA, FBI Urge Organizations to Eliminate XSS Vulnerabilities appeared first on SecurityWeek. Read More
-
Chrome 129 Patches High-Severity Vulnerability in V8 Engine Ionut Arghire
Google has released Chrome 129 with patches for nine vulnerabilities, including a high-severity bug in the V8 engine. The post Chrome 129 Patches High-Severity Vulnerability in V8 Engine appeared first on SecurityWeek. Read More
-
Why Pay A Pentester? [email protected] (The Hacker News)
The evolution of software always catches us by surprise. I remember betting against the IBM computer Deep Blue during its chess match against the grandmaster Garry Kasparov in 1997, only to be stunned when the machine claimed victory. Fast forward to today, would we have imagined just three years ago that a chatbot could write…
-
AT&T to Pay $13 Million in Settlement Over 2023 Data Breach Ionut Arghire
AT&T has agreed to pay $13 million in a settlement with the FCC over a 2023 data breach at a third-party vendor’s cloud environment. The post AT&T to Pay $13 Million in Settlement Over 2023 Data Breach appeared first on SecurityWeek. Read More