HelloKitty Ransomware Resurafced Targeting Windows, Linux, & ESXi Environments post, april 13, 2025april 14, 2025 Cybersecurity experts have detected a concerning revival of the HelloKitty ransomware, with new variants actively targeting Windows, Linux, and ESXi environments simultaneously. First observed in October 2020, HelloKitty has evolved from its origins as a DeathRansom ransomware fork, expanding its targeting capabilities and refining its attack techniques. Continue Reading
Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE Malware post, april 4, 2025april 7, 2025 Ivanti has disclosed details of a now-patched critical security vulnerability impacting its Connect Secure product that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2025-22457 (CVSS score: 9.0), concerns a case of a stack-based buffer overflow that could be exploited to execute arbitrary code on affected systems. Continue Reading
Undocumented commands found in Bluetooth chip used by a billion devices post, maart 8, 2025maart 10, 2025 The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains undocumented commands that could be leveraged for attacks. The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence. Continue Reading
Belgium probes if Chinese hackers breached its intelligence service post, februari 27, 2025februari 28, 2025 The Belgian federal prosecutor’s office is investigating whether Chinese hackers were behind a breach of the country’s State Security Service (VSSE). Chinese state-backed attackers reportedly gained access to VSSE’s external email server between 2021 and May 2023, siphoning around 10% of all emails sent and received by the agency’s staff. Continue Reading
China’s Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers post, februari 13, 2025februari 20, 2025 When the Chinese hacker group known as Salt Typhoon was revealed last fall to have deeply penetrated major US telecommunications companies—ultimately breaching no fewer than nine of the phone carriers and accessing Americans’ texts and calls in real time—that hacking campaign was treated as a four-alarm fire by the US government. Yet… Continue Reading
Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek post, januari 30, 2025januari 30, 2025 China-based AI biz DeepSeek may have developed competitive, cost-efficient generative models, but its cybersecurity chops are another story. Wiz, a New York-based infosec house, says that shortly after the DeepSeek R1 model gained widespread attention, it began investigating the machine-learning outfit’s security posture. What Wiz found is that DeepSeek – which not… Continue Reading
U.S. Treasury Breached By People’s Republic of China (PRC) In ‘Major Incident’ post, december 31, 2024januari 9, 2025 U.S. officials have disclosed a state-sponsored Chinese hacker infiltrated the U.S. Treasury Department’s systems, gaining access to employee workstations and some unclassified documents. The breach, which occurred in early December, was revealed in a letter the Treasury Department sent to lawmakers notifying them of the incident. Continue Reading
People’s Republic of China Undertaking Major Cyberespionage Targeting U.S. Telecom Networks post, november 15, 2024november 18, 2024 US authorities have revealed a “broad and significant” cyberespionage campaign conducted by China-linked hackers aimed at stealing information from Americans involved in government and politics. In a joint statement on Wednesday, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) reported that hackers connected to Beijing had “compromised networks… Continue Reading
Reminder: China-backed crews compromised ‘multiple’ US telcos in ‘significant cyber espionage campaign’ post, november 14, 2024 The US government has confirmed there was “a broad and significant cyber espionage campaign” conducted by China-linked snoops against “multiple” American telecommunications providers’ networks. In a joint statement issued on Wednesday by the FBI and US Cybersecurity and Infrastructure Security Agency (CISA), the two government bodies said the previously-reported digital assaults resulted… Continue Reading
China Possibly Hacking US “Lawful Access” Backdoor post, oktober 8, 2024februari 24, 2025 The Wall Street Journal is reporting that Chinese hackers (Salt Typhoon) penetrated the networks of US broadband providers, and might have accessed the backdoors that the federal government uses to execute court-authorized wiretap requests. Those backdoors have been mandated by law—CALEA—since 1994. It’s a weird story. The first line of the article is: “A… Continue Reading