Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations post, mei 21, 2025mei 22, 2025 The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to disseminate known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with threat actors deploying the LummaC2 information stealer (infostealer) malware. LummaC2 malware is able to infiltrate victim… Continue Reading
Online orders paused and missing items – what we know about the M&S cyber chaos post, mei 1, 2025mei 2, 2025 The country may be enjoying the sunny weather, but the storm clouds that have been gathering over Marks & Spencer currently show no sign of abating. We are now well into the second week of a cyber attack that has hit one of the UK’s oldest and biggest retailers, causing… Continue Reading
Brits warenhuis Harrods getroffen door cyberaanval, derde bedrijf in week tijd post, mei 1, 2025mei 2, 2025 Het Britse warenhuis Harrods zegt dat hackers hebben geprobeerd om in te breken in de systemen. Het bedrijf heeft uit voorzorg het internetverkeer in zijn winkels vertraagd. Het is het derde bedrijf in twee weken tijd dat te maken heeft met een cyberaanval in het Verenigd Koninkrijk. Ondanks de aanval zijn… Continue Reading
Together through the storm: How our university withstood the cyberattack post, april 30, 2025mei 2, 2025 The cyberattack that struck our university on January 11, 2025, was repelled through quick and vigilant action. The decision to disconnect all internal and external network connections that night significantly impacted our entire community. While our university has returned to normal operations over the past few months, the aftermath resonates… Continue Reading
Exposed Automated Tank Gauge Systems (DIVD-2025-00005) post, april 29, 2025mei 19, 2025 Automated Tank Gauge (ATG) systems are widely used in gas stations and other critical facilities to monitor fuel levels, detect leaks, and manage inventory. These industrial control systems have been found exposed directly to the internet without proper authentication mechanisms, creating significant security and potential safety risks. The vulnerability affects… Continue Reading
Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices post, april 23, 2025april 24, 2025 Cybersecurity researchers have revealed that Russian military personnel are the target of a new malicious campaign that distributes Android spyware under the guise of the Alpine Quest mapping software. “The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it in various ways, including through one of… Continue Reading
Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp post, april 23, 2025april 24, 2025 Multiple suspected Russia-linked threat actors are “aggressively” targeting individuals and organizations with ties to Ukraine and human rights with an aim to gain unauthorized access to Microsoft 365 accounts since early March 2025. The highly targeted social engineering operations, per Volexity, are a shift from previously documented attacks that leveraged… Continue Reading
Voor het eerst Russische sabotage-aanval in Nederland: ‘Rusland wordt brutaler’ post, april 22, 2025april 24, 2025 Nederland wordt steeds vaker geconfronteerd met hybride aanvallen van Rusland, waarmee ze onze samenleving willen ontwrichten. Zo hebben Russische hackers afgelopen jaar voor het eerst geprobeerd een sabotage-actie uit te voeren op de computers van een openbare Nederlandse instelling. De sabotage richtte geen schade aan. Continue Reading
Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks post, april 17, 2025april 24, 2025 Apple on Wednesday released security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to address two security flaws that it said have come under active exploitation in the wild. The vulnerabilities in question are listed below – Continue Reading
U.S. Govt. Funding for MITRE’s CVE Ends April 16, Cybersecurity Community on Alert post, april 16, 2025 The U.S. government funding for non-profit research giant MITRE to operate and maintain its Common Vulnerabilities and Exposures (CVE) program will expire Wednesday, an unprecedented development that could shake up one of the foundational pillars of the global cybersecurity ecosystem. The 25-year-old CVE program is a valuable tool for vulnerability… Continue Reading