Security researchers have identified six vulnerabilities in the widely deployed U-Boot bootloader that could allow attackers to execute malicious code during the earliest stages of a device’s startup process. If successfully exploited, the flaws could enable firmware-level attacks capable…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
U.S. Security Expert Sentenced for Aiding BlackCat Ransomware Gang
A cybersecurity professional has become the third U.S. security expert sentenced to prison for aiding a ransomware gang, marking a significant escalation in insider threat cases involving incident response firms. Angelo Martino, a 41-year-old from Florida, pleaded guilty to…
Injective Labs GitHub Compromise Distributes Malicious npm Package Targeting Crypto Wallet Keys
Cybersecurity researchers have detected a software supply chain attack in which threat actors compromised the Injective Labs SDK GitHub repository and utilized it to distribute a backdoored version of the npm package containing cryptocurrency wallet credentials stealing capabilities. Researchers…
Hackers Target Industries in Japan, Attacks Share One Pattern
Four big Japan cyberattacks point to a common trend: threat actors are getting access via third-party infrastructure and subsidiaries, not from corporate headquarters. While the attacks impacted companies from varying industries such as telecommunications, manufacturing, insurance, and brewing, the breaches…
Injective SDK Supply Chain Attack Exposed Developers to Cryptocurrency Wallet Theft
InjectiveLabs/SDK-TS, a widely used package, was briefly published on Node Package Manager (npm) as a malicious version after attackers gained access to a legitimate contributor’s GitHub account, exposing developers to the theft of cryptocurrency wallet credentials. Several security researchers…
Why Apple, Meta and Snap Want You to Stop Looking at Your Phone
The technology industry’s next computing platform may not fit in your hand. Instead, it could rest on your ears, sit on your face or hang around your neck. Apple is reportedly exploring AirPods equipped with cameras that would give…
OpenMandriva Accuses Former Contributor of Project Sabotage
OpenMandriva Linux is facing a serious internal security dispute after it said a former contributor abused administrative access to damage the project’s infrastructure. The alleged actions included deleting GitHub repositories and publishing an empty package that could have broken…
QIZ Security Raises $17 Million to Expand Cryptographic Security and Post-Quantum Readiness Platform
Israeli cybersecurity startup QIZ Security has raised $17 million in seed funding to fuel the development of its cryptographic security management solution and post-quantum cryptographic (PQC) readiness platform. The Israeli cybersecurity company has seen rising demand for its service,…
AI Agents Built to Detect Malware Can Be Manipulated Into Running It
AI agents capable of identifying malicious software can be manipulated by the AI Now Institute to execute it, according to new research. The proof-of-concept attack, known as “Friendly Fire,” demonstrates that autonomous AI coding agents, such as Claude Code…
GhostApproval Symlink Codes Could Run Malicious Codes in AI Coding Agents
Cyber security experts at Wiz discovered that a bug in six famous AI coding assistants allows a booby-trapped code project to silently take over a developer’s system. The assistant can ask access to edit one innocent-looking file, but the write…
Mount Royal University says hackers stole and deleted files following June cyberattack
Mount Royal University (MRU) has confirmed that threat actors stole data and deleted files after breaching the university’s network in a cyberattack that continues to affect recovery efforts weeks after the incident. In an update published on its website, the…
Fake Paysafe and Skrill SDKs on npm and PyPI Steal Developer Credentials
A coordinated supply-chain attack has compromised developers by distributing 17 malicious packages on npm and PyPI that impersonate legitimate SDKs for Paysafe, Skrill, and Neteller payment services. These packages were designed to silently exfiltrate sensitive credentials, including API keys,…
AI Agent Executes End-to-End Ransomware Attack Without Human Intervention, Researchers Say
Cybersecurity researchers have uncovered what they believe is the first ransomware attack conducted by an autonomous artificial intelligence agent which they named JADEPUFFER. It is notable because the AI performed all stages of the attack, from targeting and compromising…
Rogue Agent Bug Could Have Let Attackers Hack AI Conversations
A critical vulnerability in Google’s Dialogflow could have let a hacker exploit other Code-Block-enabled agents via one Code Block-power agent, in one Google Cloud project. After this, the attacker could read chats, steal user data, and command bots to send…
Accenture Confirms Cyber Breach as Hacker Lists Alleged Company Data
Accenture, a global IT services firm, has confirmed experiencing a cybersecurity breach as a threat actor claimed to have stolen company data and was offering it for sale on a cybercrime forum. The breach claim was made in relation…
Romania’s Hospital Cyberattack Highlights Growing Ransomware Threats to Healthcare Systems
A large-scale ransomware attack that took place in the healthcare system of Romania in February 2024 makes for textbook material on how to respond to such incidents, as well as the challenges they present. The ransomware attack scenario started…
ED Charge Sheet Maps Sriki’s Darknet Crypto Laundering Network
The Enforcement Directorate (ED) has filed a sprawling 3,500-page prosecution complaint before a special PMLA court in Bengaluru, laying out what it calls a “sophisticated network” blending high-level hacking, darknet operations, cyber extortion and multi-crore cryptocurrency laundering. The charge…
Business Threat Management: Moving from Isolated to Unified Approach
Shifting away from isolated, technical data, to a continuous risk lifecycle can assist organizations in balancing security controls with actual business impact. A CVSS score of 9.5 may not be significant to a CFO, but when it demonstrates a flaw…
Phishing Campaign Targets Marketing Professionals Using Fake Job Interviews from Top Global Brands
A sophisticated phishing campaign is targeting marketing professionals by posing as recruiters from more than 30 globally recognized brands, including Adobe, Netflix, Coca-Cola, OpenAI, Adidas, and Marriott. The attackers aim to steal Google account credentials by luring victims into…
BeyondTrust Patches Four Vulnerabilities in Remote Support and PRA
BeyondTrust has released security updates to remediate four vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, including two Critical authentication bypass flaws that could allow attackers to gain unauthorized access to vulnerable appliances under specific…