WantToCry Ransomware Exploits SMB Vulnerabilities to Remotely Encrypts NAS Drives post, februari 1, 2025februari 24, 2025 The notorious WantToCry ransomware group leverages misconfigured Server Message Block (SMB) services to infiltrate networks and launch widespread attacks. The weaknesses in SMBs, such as weak credentials, outdated software, and poor security configurations, are providing attackers with an easy entry point through which attackers exploit publicly exposed network drives and… Continue Reading
New Jailbreak Techniques Expose DeepSeek LLM Vulnerabilities, Enabling Malicious Exploits post, januari 31, 2025 Recent revelations have exposed critical vulnerabilities in DeepSeek’s large language models (LLMs), particularly DeepSeek-R1, through advanced jailbreaking techniques. These exploits, including “Bad Likert Judge,” “Crescendo,” and “Deceptive Delight,” have demonstrated the ease with which malicious actors can bypass safety measures to extract harmful outputs or generate malicious code. Continue Reading
Indian tech giant Tata Technologies hit by ransomware attack post, januari 31, 2025februari 3, 2025 Tata Technologies Ltd. had to suspend some of its IT services following a ransomware attack that impacted the company network. A subsidiary of Tata Motors, Tata Technologies is an Indian public multinational tech firm that focuses on automotive design, aerospace engineering, and R&D engineering in general. Continue Reading
Politie haalt webwinkel voor cybercriminelen offline post, januari 30, 2025 De Nederlandse politie heeft een van belangrijkste webwinkels voor cybercriminelen offline gehaald. De winkel bood kant-en-klare software om online fraude te plegen en verkocht lijsten met inloggegevens van slachtoffers. Het gaat om de site HeartSender en een groot aantal onderliggende domeinen. De politie spreekt van “criminele webshops”, waar reclame voor wordt… Continue Reading
Threat Actors Exploit Government Website Vulnerabilities For Phishing Attacks post, januari 30, 2025februari 24, 2025 A recent report by Cofense Intelligence shows that how attackers are weaponizing .gov top-level domains (TLDs) across multiple countries for malicious purposes, including credential phishing, malware delivery, and command-and-control (C2) operations. Continue Reading
Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek post, januari 30, 2025januari 30, 2025 China-based AI biz DeepSeek may have developed competitive, cost-efficient generative models, but its cybersecurity chops are another story. Wiz, a New York-based infosec house, says that shortly after the DeepSeek R1 model gained widespread attention, it began investigating the machine-learning outfit’s security posture. What Wiz found is that DeepSeek – which not… Continue Reading
PrintNightmare Aftermath: Windows Print Spooler is Better. What’s Next? post, januari 29, 2025januari 30, 2025 While Microsoft has boosted the security of Windows Print Spooler in the three years since the disclosure of the PrintNightmare vulnerability, the service remains a spooky threat that organizations cannot afford to ignore. The 2021 PrintNightmare vulnerability exposed multiple deep-rooted security flaws in Microsoft’s Print Spooler service, a core Windows… Continue Reading
Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More post, januari 28, 2025januari 30, 2025 Apple has released software updates to address several security flaws across its portfolio, including a zero-day vulnerability that it said has been exploited in the wild. The vulnerability, tracked as CVE-2025-24085, has been described as a use-after-free bug in the Core Media component that could permit a malicious application already installed on a device… Continue Reading
A Tumultuous Week for Federal Cybersecurity Efforts post, januari 27, 2025januari 30, 2025 President Trump last week issued a flurry of executive orders that upended a number of government initiatives focused on improving the nation’s cybersecurity posture. The president fired all advisors from the Department of Homeland Security’s Cyber Safety Review Board, called for the creation of a strategic cryptocurrency reserve, and voided a… Continue Reading
Phemex – Rekt post, januari 24, 2025februari 24, 2025 When your hot wallets become dozens of points of failure, $73.54 million makes for an expensive lesson in access control. Phemex exchange just learned this lesson the hard way, watching helplessly as an attacker drained their hot wallets across almost 30 different chains in a masterclass of multi-chain mayhem. Continue Reading