JFL Hospital targeted in ransomware attack amid wave of cyber incidents in US Virgin Islands
Governor Juan F. Luis Hospital & Medical Center (JFL) in the US Virgin Islands has become the latest government entity to suffer a cybersecurity breach, confirming a ransomware...
SuperCard X: exposing a MaaS for NFC Relay fraud operation
The Cleafy Threat Intelligence team has uncovered SuperCard X, a sophisticated Android malware campaign leveraging NFC-relay attacks to authorize fraudulent POS and ATM transactions. This Malware-as-a-Service (MaaS) operation1...
MITRE Signals Critical Risk to CVE Program as Federal Funding Expires
The cybersecurity world faces a significant challenge as the Common Vulnerabilities and Exposures (CVE) program, a cornerstone of global vulnerability management, risks disruption due to expiring federal funding....
Malicious NPM packages targeting PayPal users: a recap analysis
FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages, created between March 5 and March 14, were...
Malicious VSCode extensions: a growing threat to developers
The Visual Studio Code (VSCode) Marketplace has recently become a target for sophisticated cyberattacks, with malicious extensions infiltrating development environments to deploy cryptominers. These attacks highlight vulnerabilities in...
Everest ransomware gang faces unprecedented blow: leak site hacked and defaced
In a surprising turn of events, the Everest ransomware gang—a notorious Russia-linked cybercriminal organization—has suffered a significant setback. Over the weekend, their dark web leak site was hacked...
Surge in Palo Alto Networks scanner activity
GreyNoise has detected a significant surge in login scanning activity aimed at Palo Alto Networks PAN-OS GlobalProtect portals. In the last month, nearly 24,000 unique IP addresses have...
Crocodilus: a sophisticated new Android banking trojan emerges
A new Android banking trojan, dubbed Crocodilus, has been discovered targeting users primarily in Spain and Turkey. This malware isn’t just another clone; it’s a fully-fledged threat employing...