UK cybersecurity agency details China-linked Pygmy Goat backdoor discovered on Sophos XG firewalls
The report follows a series of Sophos reports detailing five years of encounters with Chinese threat actors increasingly targeting networking devices globally.
November 4, 2024
Hackers abuse Microsoft SharePoint bug to breach corporate networks
The attackers exploited CVE-2024-38094 to gain unauthorized access to a vulnerable SharePoint server.
November 4, 2024
Cyber Security Week in Review: November 1, 2024
In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
November 1, 2024
North Korean hackers caught collaborating with Play ransomware
The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
October 31, 2024
Large-scale phishing campaign targeting Ukraine's taxpayers
The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
October 30, 2024
Ongoing malvertising campaign hijacks Facebook accounts to distribute SYS01Stealer malware
Threat actors use Meta’s platform to promote fake advertisements for popular software tools.
October 30, 2024
Akira and Fog ransomware exploit SonicWall VPN bug to breach corporate networks
In many cases, the interval between initial access and data encryption was about ten hours on average.
October 30, 2024
Russian APT29 targets over 100 critical sector orgs via RDP
The threat actor targeted more than 100 organizations via phishing emails designed to trick users into opening an RDP configuration file.
October 30, 2024
Major French ISP Free confirms data breach after dark web leak
The breach exposed the personal data of some of Free’s 22.9 million customers.
October 29, 2024
UK sanctions Russians behind Doppelgänger disinformation op
The sanctioned entities include the Social Design Agency (SDA) and its partner company Structura.
October 29, 2024