A Group of Young Cybercriminals Poses the ‘Most Imminent Threat’ of Cyberattacks Right Now post, juli 2, 2025juli 4, 2025 The Scattered Spider hacking group has caused chaos among retailers, insurers, and airlines in recent months. Researchers warn that its flexible structure poses challenges for defense. Empty grocery store shelves and grounded planes tend to signal a crisis, whether it’s an extreme weather event, public health crisis, or geopolitical emergency. But these scenes of… Continue Reading
GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool post, juni 28, 2025juni 30, 2025 The threat actor behind the GIFTEDCROOK malware has made significant updates to turn the malicious program from a basic browser data stealer to a potent intelligence-gathering tool. “Recent campaigns in June 2025 demonstrate GIFTEDCROOK’s enhanced ability to exfiltrate a broad range of sensitive documents from the devices of targeted individuals,… Continue Reading
APT-C-36 Hackers Attacking Government Institutions, Financial Organizations, and Critical Infrastructure post, juni 27, 2025juli 3, 2025 Since 2018, the advanced persistent threat group APT-C-36, commonly known as Blind Eagle, has emerged as a formidable cyber adversary targeting critical sectors across Latin America. This sophisticated threat actor has demonstrated persistent focus on Colombian organizations, launching coordinated attacks against government institutions, financial organizations, and critical infrastructure through carefully orchestrated phishing… Continue Reading
‘Cyber Fattah’ Hacktivist Group Leaks Saudi Games Data post, juni 27, 2025 As tensions in the Middle East rise, hacktivist groups are coming out of the woodwork with their own agendas, leading to notable shifts in the hacktivist threat landscape. A pro-Iranian hacktivist group known as Cyber Fattah leaked thousands of records containing information about visitors and athletes from past Saudi Games events. Saudi… Continue Reading
Whole Foods supplier UNFI restores core systems after cyberattack post, juni 27, 2025 American grocery wholesale giant United Natural Foods (UNFI) reports that it has restored its core systems and brought online the electronic ordering and invoicing systems affected by a cyberattack. UNFI, which is also a primary distributor for Amazon’s Whole Foods, said in a Thursday update that the incident has been contained and… Continue Reading
Hackers Make Hay? Smart Tractors Vulnerable to Full Takeover post, juni 27, 2025juni 30, 2025 Hackers can spy on tens of thousands of connected tractors in the latest IoT threat, and brick them too, thanks to poor security in an aftermarket steering system. Researchers have figured out how to simultaneously spy on tens of thousands of smart tractors around the world, and even take full… Continue Reading
Meldingen van misbruik van kwetsbaarheid in Citrix NetScaler ADC en NetScaler Gateway post, juni 26, 2025juni 27, 2025 Softwarebedrijf Citrix heeft een kwetsbaarheid verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid wordt aangeduid met het kenmerk CVE-2025-6543. Er zijn al meldingen van misbruik op systemen die niet zijn bijgewerkt. Het is daarom belangrijk om deze kwetsbaarheid serieus te nemen. Ook het Nationaal Cyber Security Centrum (NCSC) schaalt… Continue Reading
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access post, juni 26, 2025juni 27, 2025 Cisco has released updates to address two maximum-severity security flaws in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could permit an unauthenticated attacker to execute arbitrary commands as the root user. The vulnerabilities, assigned the CVE identifiers CVE-2025-20281 and CVE-2025-20282, carry a CVSS score of 10.0 each. Continue Reading
Beware the Hidden Risk in Your Entra Environment post, juni 25, 2025juni 27, 2025 A gap in access control in Microsoft Entra’s subscription handling is allowing guest users to create and transfer subscriptions into the tenant they are invited into, while maintaining full ownership of them. All the guest user needs are the permissions to create subscriptions in their home tenant, and an invitation… Continue Reading
China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom post, juni 24, 2025 The Canadian Centre for Cyber Security and the U.S. Federal Bureau of Investigation (FBI) have issued an advisory warning of cyber attacks mounted by the China-linked Salt Typhoon actors to breach major global telecommunications providers as part of a cyber espionage campaign. The attackers exploited a critical Cisco IOS XE software (CVE-2023-20198, CVSS score:… Continue Reading