A Tumultuous Week for Federal Cybersecurity Efforts post, januari 27, 2025januari 30, 2025 President Trump last week issued a flurry of executive orders that upended a number of government initiatives focused on improving the nation’s cybersecurity posture. The president fired all advisors from the Department of Homeland Security’s Cyber Safety Review Board, called for the creation of a strategic cryptocurrency reserve, and voided a… Continue Reading
Phemex – Rekt post, januari 24, 2025februari 24, 2025 When your hot wallets become dozens of points of failure, $73.54 million makes for an expensive lesson in access control. Phemex exchange just learned this lesson the hard way, watching helplessly as an attacker drained their hot wallets across almost 30 different chains in a masterclass of multi-chain mayhem. Continue Reading
Waarom worden onderwijsinstellingen plots tegelijkertijd getroffen door cyberaanvallen? post, januari 17, 2025januari 30, 2025 Donderdag werden opnieuw onderwijsinstellingen getroffen door een grootschalige cyberaanval, waaronder de Universiteit van Maastricht. Woensdag viel het netwerk van de Fontys Hogeschool in Tilburg al uit, en de systemen van de TU Eindhoven staan sinds zondag op zwart. Wat is hier aan de hand? Continue Reading
SURF en onderwijsinstellingen opnieuw getroffen door ddos-aanval post, januari 16, 2025januari 30, 2025 SURF heeft opnieuw te maken met een ddos-aanval. Daardoor hebben onderwijsinstellingen in heel Nederland last van trage of geen internetverbindingen. Gisteren vond ook een ddos-aanval plaats. SURF merkt sinds vanmorgen 8.30 uur soortgelijke activiteiten op het netwerk als gisteren, meldt de organisatie op zijn website. Net als bij de vorige aanval gaat er… Continue Reading
U.S. Treasury Breached By People’s Republic of China (PRC) In ‘Major Incident’ post, december 31, 2024januari 9, 2025 U.S. officials have disclosed a state-sponsored Chinese hacker infiltrated the U.S. Treasury Department’s systems, gaining access to employee workstations and some unclassified documents. The breach, which occurred in early December, was revealed in a letter the Treasury Department sent to lawmakers notifying them of the incident. Continue Reading
North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin post, december 24, 2024februari 24, 2025 Japanese and U.S. authorities have formerly attributed the theft of cryptocurrency worth $308 million from cryptocurrency company DMM Bitcoin in May 2024 to North Korean cyber actors. “The theft is affiliated with TraderTraitor threat activity, which is also tracked as Jade Sleet, UNC4899, and Slow Pisces,” the agencies said. “TraderTraitor activity… Continue Reading
Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS post, december 12, 2024december 13, 2024 Details have emerged about a now-patched security vulnerability in Apple’s iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and result in unauthorized access to sensitive information. The flaw, tracked as CVE-2024-44131 (CVSS score: 5.3), resides in the FileProvider component, per Apple, and has been… Continue Reading
Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States post, december 12, 2024december 13, 2024 The Russia-linked state-sponsored threat actor tracked as Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking the first time the adversary has been discovered using mobile-only malware families in its attack campaigns. “BoneSpy and PlainGnome target former Soviet states and focus on Russian-speaking victims,” Lookout said in an analysis…. Continue Reading
ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms post, december 11, 2024februari 24, 2025 Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago. “Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and… Continue Reading
Ransomware attack hits leading heart surgery device maker post, december 9, 2024december 11, 2024 Artivion, a leading manufacturer of heart surgery medical devices, has disclosed a November 21 ransomware attack that disrupted its operations and forced it to take some systems offline. The Atlanta-based company employs over 1,250 people worldwide and has sales representatives in more than 100 countries. It also operates manufacturing facilities… Continue Reading