Category: EN

Four-Faith Industrial Routers Targeted in Botnet Hijacking Campaign

Four-Faith industrial cellular routers are being actively targeted in a growing botnet campaign exploiting a critical authentication bypass flaw tracked as CVE-2024-9643. Security researchers warn that attackers are rapidly weaponizing the vulnerability to hijack exposed devices and repurpose them as…

CISA Admin Exposes AWS GovCloud Credentials on Public GitHub Repository

A major security lapse has exposed highly sensitive U.S. government cloud credentials after a contractor working with the Cybersecurity and Infrastructure Security Agency (CISA) accidentally published them in a public GitHub repository. The repository, named “Private-CISA,” remained publicly accessible until…

Waymo Cars Flood Quiet Atlanta Cul-De-Sac

Dozens of automated Waymo cars filmed driving in and out of Atlanta dead-end street, as company blames ‘fleet positioning’ This article has been indexed from Silicon UK Read the original article: Waymo Cars Flood Quiet Atlanta Cul-De-Sac

Shai-Hulud worm copycats emerge after source code leak

Shai-Hulud worm copycats are already attacking NPM developers after its source code leaked, enabling fast supply chain exploitation. The first copycats of the Shai-Hulud worm have already started showing up online, only a few days after the malware’s source code…

JLR Profit Drops 99 Percent After Cyber-Attack

Profit at largest UK carmaker plunges after hack disrupts production for weeks, as it seeks to get delayed EV plans back on track This article has been indexed from Silicon UK Read the original article: JLR Profit Drops 99 Percent…

Jurors Dismiss Musk’s OpenAI Lawsuit

California jury finds entrepreneur Elon Musk waited too long to file lawsuit accusing Sam Altman, Greg Brockman, OpenAI of misdeeds This article has been indexed from Silicon UK Read the original article: Jurors Dismiss Musk’s OpenAI Lawsuit

JavaScript Malware Campaign Drops Crypto Clipper via PowerShell

A large-scale CountLoader campaign that uses layered obfuscation, multi-stage payload delivery, and covert command-and-control (C2) communication to deploy cryptocurrency clipper malware. The campaign stands out for its complex infection chain, combining JavaScript, PowerShell, and in-memory shellcode execution to evade detection…

Compromised GitHub Action Steals Workflow Credentials

A widely used GitHub Action, actions-cool/issues-helper, has been compromised in a supply chain attack that exposes sensitive CI/CD secrets to an attacker-controlled domain. The attack hinges on a subtle but powerful manipulation of Git tags. Instead of altering the visible commit…