Dashlane confirms limited vault access following brute-force attack
An unknown threat actor attempted to bypass two-factor authentication and add new devices to existing user accounts.
An unknown threat actor attempted to bypass two-factor authentication and add new devices to existing user accounts.
The campaign begins with weaponized xHTML files that deliver a malicious RAR archive exploiting a WinRAR vulnerability (CVE-2025-8088).
The attack is designed to steal developer credentials and CI/CD secrets during package installation.
The campaign mainly targets organizations in government, research, education, technology, and financial services.
The Marimo flaw was exploited for the initial compromise and AWS credential theft.
The botnet relied on more than 200 servers hosted in the Netherlands.
The campaign, active since at least August 2025, has targeted military, government, civilian, and business sectors.
The attacks used forged authentication override cookies to impersonate local administrator accounts.
In brief: KnowledgeDeliver zero-day exploited to deploy the Bluebeam malware, a FortiClient EMS flaw abused in EKZ Infostealer attacks, and more.
The threat actors appear to have abused trusted management channels to execute malicious PowerShell commands across connected systems.
Showing elements 181 - 190