-
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying on a conventional server or domain. The design shi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal information of 13,689 customers. Importantly, Trezor’s internal systems, hardware wallets, pri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Beacon CRM has confirmed that a threat actor likely downloaded a complete copy of its customer database after gaining access to its Amazon Web Services (AWS) environment using a compromised AWS access key. In an incident update published on August 12, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download pages. This malware combines various malicious features, including password theft, browser data collect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfuscated malware payloads in documents that victim implants retrieve and execute. The technique all…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has released security updates that address six vulnerabilities in Exchange Server. These vulnerabilities include flaws that could allow remote code execution (RCE), privilege escalation, denial-of-service (DoS), spoofing, and bypass of securi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dell has disclosed a significant security vulnerability in its Virtual Storage Integrator (VSI) for VMware vSphere Client. This vulnerability could allow unauthenticated remote attackers to execute arbitrary operating system commands with root privileg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Trump administration has issued a presidential memorandum that establishes a federal program allowing vetted U.S. private-sector companies to conduct government-directed cyber surveillance and cyber operations against foreign cyber-enabled transnat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The LiteLLM supply-chain compromise has shifted from a short-lived malicious package incident into a sprawling enterprise exposure event. Analysis of an alleged 153GB attacker archive has linked 118,829 CI runner dumps to 2,488 corporate domains, expos…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft Windows vulnerability to its Known Exploited Vulnerabilities catalog, warning that the flaw is actively being exploited in real-world attacks. The vulnerabi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


