- Conduent confirms cybersecurity incident behind recent outageby Sergiu Gatlan (BleepingComputer) on January 22, 2025 at 4:56 pm
American business services giant and government contractor Conduent confirmed today that a recent outage resulted from what it described as a "cyber security incident." [...]
- Trump Terminates DHS Advisory Committee Memberships, Disrupting Cybersecurity Reviewby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 4:17 pm
The new Trump administration has terminated all memberships of advisory committees that report to the Department of Homeland Security (DHS). "In alignment with the Department of Homeland Security's (DHS) commitment to eliminating the misuse of resources and ensuring that DHS activities prioritize our national security, I am directing the termination of all current memberships on advisory
- MasterCard DNS Error Went Unnoticed for Yearsby BrianKrebs (Krebs on Security) on January 22, 2025 at 3:24 pm
The payment card giant MasterCard just fixed a glaring error in its domain name server settings that could have allowed anyone to intercept or divert Internet traffic for the company by registering an unused domain name. The misconfiguration persisted for nearly five years until a security researcher spent $300 to register the domain and prevent it from being grabbed by cybercriminals.
- Windows 11 24H2 now also offered to all eligible Windows 10 PCsby Sergiu Gatlan (BleepingComputer) on January 22, 2025 at 3:19 pm
Microsoft says Windows 11 24H2 has entered the broad deployment phase and is now available to all seekers via Windows Update. [...]
- IPany VPN breached in supply-chain attack to push custom malwareby Bill Toulas (BleepingComputer) on January 22, 2025 at 3:11 pm
South Korean VPN provider IPany was breached in a supply chain attack by the "PlushDaemon" China-aligned hacking group, who compromised the company's VPN installer to deploy the custom 'SlowStepper' malware. [...]
- Use this AI chatbot prompt to create a password-exclusion listby Sponsored by Specops (BleepingComputer) on January 22, 2025 at 3:00 pm
Creating a custom password-exclusion list can help prevent employees from using passwords that are likely to be guessed. Learn from Specops Software on using AI to generate password dictionary for securing your organization's credentials. [...]
- Will 2025 See a Rise of NHI Attacks?by Itzik Alvas (darkreading) on January 22, 2025 at 3:00 pm
The flurry of non-human identity attacks at the end of 2024 demonstrates extremely strong momentum heading into the new year. That does not bode well.
- Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025by Sergiu Gatlan (BleepingComputer) on January 22, 2025 at 2:38 pm
On the first day of Pwn2Own Automotive 2025, security researchers exploited 16 unique zero-days and collected $382,750 in cash awards. [...]
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnetby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 1:53 pm
Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed denial-of-service (DDoS) attacks. According to QiAnXin XLab, the attacks have leveraged the security flaw since June 2024. Additional details about the shortcomings have been withheld to prevent further abuse. Some
- Discover Hidden Browsing Threats: Free Risk Assessment for GenAI, Identity, Web, and SaaS Risksby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 10:31 am
As GenAI tools and SaaS platforms become a staple component in the employee toolkit, the risks associated with data exposure, identity vulnerabilities, and unmonitored browsing behavior have skyrocketed. Forward-thinking security teams are looking for security controls and strategies to address these risks, but they do not always know which risks to prioritize. In some cases, they might have
- President Trump Pardons Silk Road Creator Ross Ulbricht After 11 Years in Prisonby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 10:30 am
U.S. President Donald Trump on Tuesday granted a "full and unconditional pardon" to Ross Ulbricht, the creator of the infamous Silk Road drug marketplace, after spending 11 years behind bars. "I just called the mother of Ross William Ulbricht to let her know that in honor of her and the Libertarian Movement, which supported me so strongly, it was my pleasure to have just signed a full and
- PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attackby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 8:49 am
A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN) provider in 2023, according to new findings from ESET. "The attackers replaced the legitimate installer with one that also deployed the group's signature implant that we have named SlowStepper – a
- Oracle Releases January 2025 Patch to Address 318 Flaws Across Major Productsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 7:25 am
Oracle is urging customers to apply its January 2025 Critical Patch Update (CPU) to address 318 new security vulnerabilities spanning its products and services. The most severe of the flaws is a bug in the Oracle Agile Product Lifecycle Management (PLM) Framework (CVE-2025-21556, CVSS score: 9.9) that could allow an attacker to seize control of susceptible instances. "Easily exploitable
- Mandatory MFA, Biometrics Make Headway in Middle East, Africaby Robert Lemos, Contributing Writer (darkreading) on January 22, 2025 at 7:00 am
Despite lagging in technology adoption, African and Middle Eastern organizations are catching up, driven by smartphone acceptance and national identity systems.
- Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13,000+ IoT Devicesby info@thehackernews.com (The Hacker News) (The Hacker News) on January 22, 2025 at 6:19 am
Web infrastructure and security company Cloudflare on Tuesday said it detected and blocked a 5.6 Terabit per second (Tbps) distributed denial-of-service (DDoS) attack, the largest ever attack to be reported to date. The UDP protocol-based attack took place on October 29, 2024, targeting one of its customers, an unnamed internet service provider (ISP) from Eastern Asia. The activity originated
- [Virtual Event]: Cybersecurity's Most Promising New and Emerging Technologiesby (darkreading) on January 21, 2025 at 11:02 pm
- Trump Fires Cyber Safety Board Investigating Salt Typhoon Hackersby Becky Bracken, Senior Editor, Dark Reading (darkreading) on January 21, 2025 at 10:21 pm
In a letter sent today, the acting DHS secretary terminated membership to all advisory boards, including the Cyber Safety Review Board (CSRB) tasked with investigating state-sponsored cyber threats against the US.
- Email Bombing, 'Vishing' Tactics Abound in Microsoft 365 Attacksby Kristina Beek, Associate Editor, Dark Reading (darkreading) on January 21, 2025 at 9:50 pm
Sophos noted more than 15 attacks have been reported during the past three months.
- DONOT Group Deploys Malicious Android Apps in Indiaby Jai Vijayan, Contributing Writer (darkreading) on January 21, 2025 at 9:15 pm
The advanced persistent threat (APT) group is likely India-based and targeting individuals with connections to the country's intelligence community.
- Cloudflare mitigated a record-breaking 5.6 Tbps DDoS attackby Bill Toulas (BleepingComputer) on January 21, 2025 at 9:04 pm
The largest distributed denial-of-service (DDoS) attack to date peaked at 5.6 terabits per second and came from a Mirai-based botnet with 13,000 compromised devices. [...]
- HPE Investigates After Alleged Data Breachby Kristina Beek, Associate Editor, Dark Reading (darkreading) on January 21, 2025 at 8:30 pm
The company reports that it is not experiencing any operational issues within its business, so far.
- Fake Homebrew Google ads target Mac users with malwareby Bill Toulas (BleepingComputer) on January 21, 2025 at 7:58 pm
Hackers are once again abusing Google ads to spread malware, using a fake Homebrew website to infect Macs and Linux devices with an infostealer that steals credentials, browser data, and cryptocurrency wallets. [...]
- Microsoft previews Game Assist in-game browser in Edge Stableby Sergiu Gatlan (BleepingComputer) on January 21, 2025 at 6:25 pm
Microsoft has announced that Game Assist, its recently unveiled in-game browser, is now also available in preview for Microsoft Edge Stable users. [...]
- Mirai Botnet Spinoffs Unleash Global Wave of DDoS Attacksby Elizabeth Montalbano, Contributing Writer (darkreading) on January 21, 2025 at 6:09 pm
Two separate campaigns are targeting flaws in various IoT devices globally, with the goal of compromising them and propagating malware worldwide.
- Bitbucket services “hard down” due to major worldwide outageby Sergiu Gatlan (BleepingComputer) on January 21, 2025 at 5:23 pm
Bitbucket is investigating a massive outage affecting Atlassian Bitbucket Cloud customers worldwide, with the company saying its cloud services are "hard down." [...]
- 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch nowby Sergiu Gatlan (BleepingComputer) on January 21, 2025 at 4:05 pm
A high-severity vulnerability in the 7-Zip file archiver allows attackers to bypass the Mark of the Web (MotW) Windows security feature and execute code on users' computers when extracting malicious files from nested archives. [...]
- Ransomware gangs pose as IT support in Microsoft Teams phishing attacksby Bill Toulas (BleepingComputer) on January 21, 2025 at 3:59 pm
Ransomware gangs are increasingly adopting email bombing followed by posing as tech support in Microsoft Teams calls to trick employees into allowing remote control and install malware that provides access to the company network. [...]
- Cisco Previews AI Defenses to Cloud Security Platformby Jeffrey Schwartz (darkreading) on January 21, 2025 at 3:07 pm
Set for release in March, Cisco AI Defense will provide algorithmic red teaming of large language models with technology that came over as part of the Robust Intelligence acquisition last year.
- Criminal IP Teams Up with OnTheHub for Digital Education Cybersecurityby Sponsored by Criminal IP (BleepingComputer) on January 21, 2025 at 3:02 pm
AI SPERA announced today that it has partnered with education platform OnTheHub to provide its integrated cybersecurity solution, Criminal IP, to students and educational institutions. [...]
- Why CISOs Must Think Clearly Amid Regulatory Chaosby Marene Allison (darkreading) on January 21, 2025 at 3:00 pm
Even as the rule book changes, the profession of the CISO remains unchanged: protecting the organization in a world of constant, continually evolving threats.
- Mirai Variant Murdoc Botnet Exploits AVTECH IP Cameras and Huawei Routersby info@thehackernews.com (The Hacker News) (The Hacker News) on January 21, 2025 at 2:00 pm
Cybersecurity researchers have warned of a new large-scale campaign that exploits security flaws in AVTECH IP cameras and Huawei HG532 routers to rope the devices into a Mirai botnet variant dubbed Murdoc Botnet. The ongoing activity "demonstrates enhanced capabilities, exploiting vulnerabilities to compromise devices and establish expansive botnet networks," Qualys security researcher Shilpesh
- 13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacksby info@thehackernews.com (The Hacker News) (The Hacker News) on January 21, 2025 at 12:46 pm
A global network of about 13,000 hijacked Mikrotik routers has been employed as a botnet to propagate malware via spam campaigns, the latest addition to a list of botnets powered by MikroTik devices. The activity "take[s] advantage of misconfigured DNS records to pass email protection techniques," Infoblox security researcher David Brunsdon said in a technical report published last week. "This
- Ex-CIA Analyst Pleads Guilty to Sharing Top-Secret Data with Unauthorized Partiesby info@thehackernews.com (The Hacker News) (The Hacker News) on January 21, 2025 at 10:52 am
A former analyst working for the U.S. Central Intelligence Agency (CIA) pleaded guilty to transmitting top secret National Defense Information (NDI) to individuals who did not have the necessary authorization to receive it and attempted to cover up the activity. Asif William Rahman, 34, of Vienna, was an employee of the CIA since 2016 and had a Top Secret security clearance with access to
- HackGATE: Setting New Standards for Visibility and Control in Penetration Testing Projectsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 21, 2025 at 10:30 am
Imagine receiving a penetration test report that leaves you with more questions than answers. Questions like, "Were all functionalities of the web app tested?" or " Were there any security issues that could have been identified during testing?" often go unresolved, raising concerns about the thoroughness of the security testing. This frustration is common among many security teams. Pentest
- PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installersby info@thehackernews.com (The Hacker News) (The Hacker News) on January 21, 2025 at 5:45 am
Cybersecurity researchers are calling attention to a series of cyber attacks that have targeted Chinese-speaking regions like Hong Kong, Taiwan, and Mainland China with a known malware called ValleyRAT. The attacks leverage a multi-stage loader dubbed PNGPlug to deliver the ValleyRAT payload, Intezer said in a technical report published last week. The infection chain commences with a phishing
- CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Auditsby info@thehackernews.com (The Hacker News) (The Hacker News) on January 21, 2025 at 5:27 am
The Computer Emergency Response Team of Ukraine (CERT-UA) is warning of ongoing attempts by unknown threat actors to impersonate the cybersecurity agency by sending AnyDesk connection requests. The AnyDesk requests claim to be for conducting an audit to assess the "level of security," CERT-UA added, cautioning organizations to be on the lookout for such social engineering attempts that seek to
- Weekly Update 435by Troy Hunt (Troy Hunt) on January 21, 2025 at 2:14 am
If I'm honest, I was in two minds about adding additional stealer logs to HIBP. Even with the new feature to include the domains an email address appears against in the logs, my concern was that I'd get a barrage of "that's useless
- Name That Toon: Incentivesby John Klossner (darkreading) on January 20, 2025 at 5:04 pm
Feeling creative? Have something to say about cybersecurity? Submit your caption and our panel of experts will reward the winner with a $25 gift card.
- Unsecured Tunneling Protocols Expose 4.2 Million Hosts, Including VPNs and Routersby info@thehackernews.com (The Hacker News) (The Hacker News) on January 20, 2025 at 3:08 pm
New research has uncovered security vulnerabilities in multiple tunneling protocols that could allow attackers to perform a wide range of attacks. "Internet hosts that accept tunneling packets without verifying the sender's identity can be hijacked to perform anonymous attacks and provide access to their networks," Top10VPN said in a study, as part of a collaboration with KU Leuven professor
- DoNot Team Linked to New Tanzeem Android Malware Targeting Intelligence Collectionby info@thehackernews.com (The Hacker News) (The Hacker News) on January 20, 2025 at 2:53 pm
The Threat actor known as DoNot Team has been linked to a new Android malware as part of highly targeted cyber attacks. The artifacts in question, named Tanzeem (meaning "organization" in Urdu) and Tanzeem Update, were spotted in October and December 2024 by cybersecurity company Cyfirma. The apps in question have been found to incorporate identical functions, barring minor modifications to the
Hate Watch
Events, Research, Work
Think Tanks
National Security and Intel Think Tanks and Government Research
Listed:
Investigative Project Profiles