FBI and Allied Governments Warn Companies Are Unknowingly Hiring North Korean Operatives
A joint advisory from the U.S. State Department, FBI, and partner nations including Japan, the UK, Germany, Canada, and South Korea warns that North Korean IT workers are...
The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking
A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver...
SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login
SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform...
SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware
Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the...
North Korean Hackers Hide Malware Instructions Inside Ethereum Smart Contracts to Drain Crypto Wallets
A North Korean-linked campaign is using fake macOS update screens to trick victims into pasting a malicious command into Terminal, kicking off an infection chain that hunts for...
Dark Web Persona ‘ModernStealer’ Ties Together Alleged Military and Nuclear Regulator Data Leaks
Threat intelligence firm StealthMole has traced a web of dark forum and Telegram listings advertising alleged military, nuclear, and aerospace data back to a recurring set of contact...
Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw
A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...
New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys
Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or...