Latest news

Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting
Malware

Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting

3 May 2025 securebulletin.com

A coordinated malware operation targeting npm employs cross-ecosystem typosquatting to mimic popular libraries from Python, Java, C++, and .NET ecosystems....
Dismantling “764”: inside the takedown of a sophisticated child exploitation network
Cybercrime

Dismantling “764”: inside the takedown of a sophisticated child exploitation network

1 May 2025 securebulletin.com

In a significant development for cybersecurity and child protection efforts, law enforcement agencies have successfully apprehended two key figures allegedly...
Hijacking Trust: how Gmail and Google APIs are being weaponized for stealthy C2 channels
Spyware

Hijacking Trust: how Gmail and Google APIs are being weaponized for stealthy C2 channels

1 May 2025 securebulletin.com

In the ever-evolving landscape of cybersecurity, attackers are increasingly exploiting trusted services to establish covert command-and-control (C2) channels. By leveraging...
Kintetsu World Express ransomware attack: technical overview and response
Ransomware

Kintetsu World Express ransomware attack: technical overview and response

30 April 2025 securebulletin.com

Kintetsu World Express (KWE), a major Japanese global logistics provider, has confirmed a significant ransomware attack that began impacting its...
JFL Hospital targeted in ransomware attack amid wave of cyber incidents in US Virgin Islands
Ransomware

JFL Hospital targeted in ransomware attack amid wave of cyber incidents in US Virgin Islands

29 April 2025 securebulletin.com

Governor Juan F. Luis Hospital & Medical Center (JFL) in the US Virgin Islands has become the latest government entity...
SuperCard X: exposing a MaaS for NFC Relay fraud operation
Malware

SuperCard X: exposing a MaaS for NFC Relay fraud operation

20 April 2025 securebulletin.com

The Cleafy Threat Intelligence team has uncovered SuperCard X, a sophisticated Android malware campaign leveraging NFC-relay attacks to authorize fraudulent...
MITRE Signals Critical Risk to CVE Program as Federal Funding Expires
Vulnerability

MITRE Signals Critical Risk to CVE Program as Federal Funding Expires

15 April 2025 securebulletin.com

The cybersecurity world faces a significant challenge as the Common Vulnerabilities and Exposures (CVE) program, a cornerstone of global vulnerability...
Malicious NPM packages targeting PayPal users: a recap analysis
Malware

Malicious NPM packages targeting PayPal users: a recap analysis

12 April 2025 securebulletin.com

FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages,...
Malicious VSCode extensions: a growing threat to developers
Malware

Malicious VSCode extensions: a growing threat to developers

7 April 2025 securebulletin.com

The Visual Studio Code (VSCode) Marketplace has recently become a target for sophisticated cyberattacks, with malicious extensions infiltrating development environments...
Everest ransomware gang faces unprecedented blow: leak site hacked and defaced
Ransomware

Everest ransomware gang faces unprecedented blow: leak site hacked and defaced

7 April 2025 securebulletin.com

In a surprising turn of events, the Everest ransomware gang—a notorious Russia-linked cybercriminal organization—has suffered a significant setback. Over the...
Surge in Palo Alto Networks scanner activity
Vulnerability

Surge in Palo Alto Networks scanner activity

1 April 2025 securebulletin.com

GreyNoise has detected a significant surge in login scanning activity aimed at Palo Alto Networks PAN-OS GlobalProtect portals. In the...
Crocodilus: a sophisticated new Android banking trojan emerges
Spyware

Crocodilus: a sophisticated new Android banking trojan emerges

30 March 2025 securebulletin.com

A new Android banking trojan, dubbed Crocodilus, has been discovered targeting users primarily in Spain and Turkey. This malware isn’t...