All Articles (2438)

Sort by

12701959081?profile=RESIZE_400xAI is fueling a lot of wild ideas for our tech-driven future.  If everything pans out, we will not have to write our own essays, take our notes, or drive our cars.   But with AI’s rapid growth, it is hard not to give at least some of those lofty visions credence, even the most sci-fi ones, even Star Wars-level humanoid robots.  There are a lot of humanoid bots now and a lot more seemingly on the way, Figure’s AI robot, Unitree’s speed demon, Agility’s workhorse, but arguably most important of al

12684845272?profile=RESIZE_400xAfter confirming a production-halting cyberattack last month, forklift manufacturer Crown Equipment said on 1 July that operations have resumed.  Crown said work was proceeding at all 24 of its manufacturing plants.  The company’s manufacturing operations had been suspended since 10 June due to the attack on its business systems.

A company spokesman has declined to comment on the attack and said no further information would be available.  The company has declined to answer questions about how ma

12701432895?profile=RESIZE_400xThe United Nations' telecommunication agency condemned Russian interference in the satellite systems of several European countries.  Earlier this month, the UN’s International Telecommunication Union (ITU) received a series of complaints from Ukraine, France, Sweden, the Netherlands and Luxembourg about the Kremlin’s alleged satellite interference that has affected GPS signals and television channels.  The ITU reviewed these complaints and published a document Monday calling the practice “extrem

12676049296?profile=RESIZE_400xMore than 1,000 planned operations and over 3,000 outpatient appointments have been postponed amid ongoing disruption caused by a cyber-attack that impacted London hospitals.  Synnovis, an agency which manages labs for NHS trusts and GPs in south-east London, was the victim of a data hack on 3 June.[1]

New figures from NHS England show that since then, 3,396 appointments and 1,255 elective procedures have been postponed.  In a statement, the chief executives of two affected trusts said they were

12676026299?profile=RESIZE_400xJuly 4th marks the anniversary of when Congress, comprised of delegates from the United States' original 13 colonies, signed the Declaration of Independence on 4 July 1776. The document declared the nation's independence from Great Britain.

Some research indicates that the original signers didn't even write their names on the official document until 2 August 1776.  In fact, it would take six months to acquire all 56 signatures.  Thomas McKean, a delegate from Delaware, was reportedly the last pe

12686776086?profile=RESIZE_400xP2Pinfect is a rust-based malware analyzed extensively by Cado Security in the past.  It is a reasonably sophisticated malware sample that uses a peer-to-peer (P2P) botnet for its command and control mechanism.  Upon initial discovery, the malware mainly appeared dormant.  It would spread primarily via Redis and a limited SSH spreader, but ultimately, it did not seem to have an objective other than to spread.  Recently, we observed a new update to P2Pinfect that introduced ransomware and crypto

12684850059?profile=RESIZE_400xAfter spending five years in detention in London's high-security H M Prison Belmarsh, a Category A men’s prison in Thamesmead, WikiLeaks founder Julian Assange has made a plea deal with the US Government. He will plead guilty to one charge of espionage and return home to Australia after years of fighting extradition from Britain. US authorities have agreed to drop their demand for Assange to be extradited from Britain after reaching a plea deal with the WikiLeaks founder.

In return for pleading

12676007501?profile=RESIZE_400xThe US military recently launched a groundbreaking initiative to strengthen ties with the commercial space industry.  The aim is to integrate commercial equipment into military space operations, including satellites and other hardware. This would enhance cybersecurity for military satellites.  As space becomes more important to the world’s critical infrastructure, the risk increases that hostile nation states will deploy cyber-attacks on important satellites and other space infrastructure.  Targ

12685916258?profile=RESIZE_400xThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding an ongoing phone-based impersonation fraud campaign where scammers are masquerading as CISA staff. In a brief notification, the agency stated it is "aware of recent impersonation scammers claiming to represent the agency."

The CISA warning  https://www.cisa.gov/news-events/alerts/2024/06/12/phone-scammers-impersonating-cisa-employees  explicitly states that its employees "will never contact you with a

12057871866?profile=RESIZE_400x

Red Sky Alliance monthly queries our backend databases, identifying all new data containing Motor Vessel (MV) and Motor Tanker (MT) in the subject line of malicious emails.  Malicious actors use emails with Motor Vessel (MV) or Motor Tanker (MT) in the subject line as a lure to entice users in the maritime industry to open emails containing malicious attachments.  Red Sky Alliance is providing this list of Motor Vessels in which we directly observed the vessel being impersonated, with associate

12673816255?profile=RESIZE_400xSpyware is malicious software engineered to covertly monitor and gather information from a user’s computer without their awareness or consent.  It can record activities like keystrokes, browsing behavior, and personal information, often transmitting this data to a third party for espionage or theft.

Researchers at FortiGuard Labs recently detected an attack exploiting the CVE-2021-40444 vulnerability in Microsoft Office.  This flaw allows attackers to execute malicious code via specially crafted

12684847278?profile=RESIZE_400xThreat actors have exploited hacked high-ranking legitimate websites to enable BadSpace malware backdoor distribution on Windows machines.  The threat actor employs a multi-stage attack chain involving an infected website, a command-and-control (C2) server, in some cases, a fake browser update, and a JScript downloader to deploy a backdoor into the victim's system.  BadSpace is a backdoor Trojan that secretly installs itself on a computer, giving cybercriminals remote access and control. It can

12681499859?profile=RESIZE_400xResearchers at Graz University of Technology could spy on users’ online activities simply by monitoring fluctuations in the speed of their internet connection.  This vulnerability, known as SnailLoad, does not require malicious code to exploit, and the data traffic does not need to be intercepted.  All types of end devices and internet connections are affected.[1]

SnailLoad attack setup:

  • The victim communicates with a server.
  • The server has a fast Internet connection, and the victim’s last-mile

12672491899?profile=RESIZE_400xA hack into software maker CDK Global has disrupted operations at auto dealerships across the US, the latest in a series of hacks where ransom-demanding cybercriminals target big companies by breaching behind-the-scenes software suppliers.  CDK makes software that is commonly used by car dealerships to process sales and other transactions.  Considering the hack, many dealers have started processing transactions manually, according to local press reports.[1]

Here is more about BlackSuit, the hack

12673831262?profile=RESIZE_400xA major cyber-attack occurred just before the Fourth of July holiday in 2021, affecting at least 200 US companies.  The attack was a ransomware attack that occurred first at Kaseya, a Florida-based IT company, and then spread through the corporate networks that use its software.  The attack affected multiple managed service providers and their customers.  The REvil ransomware gang was behind the attack.  Please stay vigilant during all holiday times.

At least 200 US companies were hit by a major

12672484674?profile=RESIZE_400xOn 26 June, Evolve Bank and Trust, a financial institution that’s popular with fintech startups, announced that it had been victim of a cyberattack and data breach that could have affected its partner companies as well.  The incident, according to the company’s statement, involved “the data and personal information of some Evolve retail bank customers and financial technology partners’ customers.”

Evolve’s communications chief Thomas Holmes said that the incident involves “a known cybercriminal

12671954060?profile=RESIZE_400xOn 8 March 2024, KrebsOnSecurity published a deep dive on the consumer data broker Radaris, showing how the original owners are two men in Massachusetts who operated multiple Russian language dating services and affiliate programs, in addition to a dizzying array of people-search websites.  The subjects of that piece are threatening to sue KrebsOnSecurity for defamation unless the story is retracted. Meanwhile, their attorney has admitted that the person Radaris named as the CEO from its incepti

12672524291?profile=RESIZE_180x180Our friends at FortiGuard Labs recently captured a new phishing campaign that demonstrates the spread of a new Agent Tesla variant, specifically targeting Spanish-speaking people.  Agent Tesla is a well-known. Net-based Remote Access Trojan (RAT) is designed to stealthily infiltrate victim’s computers and steal their sensitive information, such as their computer’s hardware information, login user information, keystrokes, email contacts, web browser cookies files, system clipboard data, screensho

12670030671?profile=RESIZE_400xA controversial proposal put forth by the European Union (EU) to scan users' private messages for detection of child sexual abuse material (CSAM) poses severe risks to end-to-end encryption (E2EE), warned Meredith Whittaker, president of the Signal Foundation, which maintains the privacy-focused messaging service of the same name. "Mandating mass scanning of private communications fundamentally undermines encryption.  Full Stop," Whittaker said in a statement on 17 June 2024.  "Whether this happ

12671248683?profile=RESIZE_400xThe notorious Russia-based ransomware gang Lockbit 3.0 has claimed responsibility for a cyber-attack on the US Federal Reserve.  The attack, which was announced on 23 June via a post on a site associated with the ransomware gang, allegedly saw the gang infiltrate the systems of the US Federal Reserve and exfiltrate 33 TB of sensitive banking information.

In the post, which was entitled 'federalreserve.gov', the gang explained how the Federal Reserve is structured, and its role in distributing mo