U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign post, oktober 18, 2024 Cybersecurity and intelligence agencies from Australia, Canada, and the U.S. have warned about a year-long campaign undertaken by Iranian cyber actors to infiltrate critical infrastructure organizations via brute-force attacks. “Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations… Continue Reading
North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data post, oktober 18, 2024 North Korean information technology (IT) workers who obtain employment under false identities in Western companies are not only stealing intellectual property, but are also stepping up by demanding ransoms in order to not leak it, marking a new twist to their financially motivated attacks. “In some instances, fraudulent workers demanded… Continue Reading
Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts post, oktober 17, 2024juli 3, 2025 A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm)… Continue Reading
U.S. Charges Two Sudanese Brothers for Record 35,000 DDoS Attacks post, oktober 17, 2024 Federal prosecutors in the U.S. have charged two Sudanese brothers with running a distributed denial-of-service (DDoS) botnet for hire that conducted a record 35,000 DDoS attacks in a single year, including those that targeted Microsoft’s services in June 2023. The attacks, which were facilitated by Anonymous Sudan’s “powerful DDoS tool,” singled out… Continue Reading
Google: 70% of exploited flaws disclosed in 2023 were zero-days post, oktober 16, 2024oktober 17, 2024 Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software. Specifically, of the 138 vulnerabilities disclosed as actively exploited in 2023, Mandiant says 97 (70.3%) were leveraged as zero-days. This means that threat actors exploited… Continue Reading
China Possibly Hacking US “Lawful Access” Backdoor post, oktober 8, 2024februari 24, 2025 The Wall Street Journal is reporting that Chinese hackers (Salt Typhoon) penetrated the networks of US broadband providers, and might have accessed the backdoors that the federal government uses to execute court-authorized wiretap requests. Those backdoors have been mandated by law—CALEA—since 1994. It’s a weird story. The first line of the article is: “A… Continue Reading
American Water Works IT Systems Hit by Cyber Attack post, oktober 8, 2024oktober 9, 2024 American Water Works Company, Inc., the largest regulated water and wastewater utility in the United States, reported a cybersecurity incident on October 3, 2024, affecting its computer networks and systems. The company, which provides services to over 14 million people across 14 states and 18 military installations, immediately activated its incident… Continue Reading
Chinese Government Hackers Infiltrate U.S Telecommunications Companies post, oktober 6, 2024oktober 7, 2024 A group of hackers linked to the Chinese government has infiltrated multiple US telecommunications companies in recent months, likely in an effort to access sensitive national security information. The hacking activity was first reported by The Wall Street Journal (WSJ). US investigators suspect that the hackers may have gained access… Continue Reading
Apple Releases Critical iOS and iPadOS Updates to Fix VoiceOver Password Vulnerability post, oktober 5, 2024oktober 7, 2024 Apple has released iOS and iPadOS updates to address two security issues, one of which could have allowed a user’s passwords to be read out aloud by its VoiceOver assistive technology. The vulnerability, tracked as CVE-2024-44204, has been described as a logic problem in the new Passwords app impacting a slew of… Continue Reading
North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks post, oktober 3, 2024juli 3, 2025 Threat actors with ties to North Korea have been observed delivering a previously undocumented backdoor and remote access trojan (RAT) called VeilShell as part of a campaign targeting Cambodia and likely other Southeast Asian countries. The activity, dubbed SHROUDED#SLEEP by Securonix, is believed to be the handiwork of APT37, which is also known… Continue Reading