CISA Rescues MITRE’s Critical Common Vulnerabilities & Exposures (CVE) Program With Extended Funding post, april 16, 2025april 17, 2025 The United States Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that the U.S. government has extended funding for the Common Vulnerabilities and Exposures (CVE) program, ensuring uninterrupted operations. On April 15, 2025, it was reported that the U.S. government would not renew MITRE’s contract, ending on April 16. Without… Continue Reading
EC issues burner phones for visits to US post, april 15, 2025april 16, 2025 The European Commission is giving staffers visiting the US on official business burner laptops and phones to avoid espionage attempts, according to the Financial Times. The use of clean and locked-down hardware is common practice for anyone visiting China, Russia, and other states where aggressive electronic surveillance is expected. Apparently… Continue Reading
HelloKitty Ransomware Resurafced Targeting Windows, Linux, & ESXi Environments post, april 13, 2025april 14, 2025 Cybersecurity experts have detected a concerning revival of the HelloKitty ransomware, with new variants actively targeting Windows, Linux, and ESXi environments simultaneously. First observed in October 2020, HelloKitty has evolved from its origins as a DeathRansom ransomware fork, expanding its targeting capabilities and refining its attack techniques. Continue Reading
Extremely Critical Vulnerability In FortiSwitch GUI Allows Attacker To Modify Admin Passwords post, april 9, 2025 Fortinet has issued urgent security updates to address a critical vulnerability in FortiSwitch that could allow attackers to change passwords without authorization. The flaw, identified as CVE-2024-48887, has been assigned a CVSS score of 9.8 out of 10. According to Fortinet’s advisory, the vulnerability lies in the FortiSwitch GUI and… Continue Reading
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages post, april 5, 2025april 7, 2025 The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. “These latest samples employ hexadecimal string encoding to evade automated detection systems and… Continue Reading
Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE Malware post, april 4, 2025april 7, 2025 Ivanti has disclosed details of a now-patched critical security vulnerability impacting its Connect Secure product that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2025-22457 (CVSS score: 9.0), concerns a case of a stack-based buffer overflow that could be exploited to execute arbitrary code on affected systems. Continue Reading
Six Governments Likely Use Israeli Paragon Spyware to Hack IM Apps and Harvest Data post, maart 20, 2025augustus 21, 2025 The governments of Australia, Canada, Cyprus, Denmark, Israel, and Singapore are likely customers of spyware developed by Israeli company Paragon Solutions, according to a new report from The Citizen Lab. Paragon, founded in 2019 by Ehud Barak and Ehud Schneorson, is the maker of a surveillance tool called Graphite that’s capable of… Continue Reading
Threat Actor Impersonates Booking.com in Phishing Scheme post, maart 14, 2025maart 17, 2025 Microsoft detailed a sophisticated campaign that relies on a social engineering technique, “ClickFix,” in which a phisher uses security verification like captcha to give the target a false sense of safety. That’s according to Microsoft, which published threat intelligence on March 13 regarding a threat actor tracked as Storm-1865. The actor was… Continue Reading
Threat Actor Tied to LockBit Ransomware Targets Fortinet Users post, maart 14, 2025maart 17, 2025 Since January, threat actors have been exploiting two Fortinet vulnerabilities tracked as CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware. It’s believed that the threat actor, dubbed “Mora_001” by researchers at Forescout Research–Vedere Labs, is responsible for the attacks that use Russian-language artifacts and other characteristics. Mora_001 is exploiting the two… Continue Reading
Undocumented commands found in Bluetooth chip used by a billion devices post, maart 8, 2025maart 10, 2025 The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains undocumented commands that could be leveraged for attacks. The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence. Continue Reading