Co-creator of Empire Market dark web marketplace given 40-year sentence
FBI disrupts Chinese hacking tools used to breach critical infrastructure
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country.
International coalition seizes tools used by cyber firm behind Flax Typhoon
International coalition seizes tools used by cyber firm behind Flax Typhoon
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
CastleStealer: An Emerging Infostealer Growing More Sophisticated
Explore Flashpoint's analysis of CastleStealer, an emerging infostealer with evolving browser data theft, encryption bypass, and remote command capabilities.
Making sure the checks get printed
Pierre's debut newsletter explores the messy, real-world side of risk management and how to keep vital systems running when a perfect patch isn't an option.
DOJ charges ransomware recovery CEO for secretly paying hackers
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.
Customer Advocacy: come costruire relazioni di fiducia durature
La customer advocacy guida la crescita B2B nella sicurezza informatica. Strategie di fiducia e gestione delle relazioni con i clienti.
Phishing, la nuova trappola dei falsi servizi AI: il login diventa un attacco interattivo
Il phishing usa falsi servizi AI e login contraffatti per rubare credenziali e codici MFA. Come funziona la trappola del pulsante Connect
ASOS: Hackers tricked way into employee account before sending rogue push notification
Crypto thief who splurged on gold grills sentenced in London
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
OAuth grants pile up faster than you can review them. Here's how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard
Hackers target two South Korean megachurches, potentially exposing congregant data
Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021.
The phone was compromised before the user turned it on: the rise of Midnight Mimosa
Bitdefender has identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms.
Thousands of cheap Android phones shipped with ad-fraud malware
Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
Major Yandex data center in Russia hit by Ukrainian drone strike
Microsoft Teams to get support for third-party deepfake detection tools
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings.
ASOS links data breach to social engineering attack, credential theft
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data.
Anthropic cambia le regole dell’AI per la cyber: più capacità ai difensori verificati
Anthropic unifica Glasswing e Cyber Verification Program: tre livelli di accesso ai modelli AI per la cyber. Le implicazioni per SOC e imprese
Owner of Empire cybercrime market gets 40 years in prison
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020.
Rogue AI Agents
Live dashboard of incidents where AI agents went rogue: an interactive timeline plus charts by AI company, agent, technique and initial access.
VPN a 2,99€ al mese con lo sconto del 70%: l’analisi dell’offerta e quanto costa davvero il rinnovo
Sconti sulla VPN di Proton: come ottenere il piano di 2 anni a soli 2,99 al mese, ecco l'analisi di tutti i costi che dobbiamo conoscere.
Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis.