security Spotted in intrusions targeting insurance, education, IT, and professional services sectors A new self-destructing backdoor called Mistic used in intrusions since April appears to be linked to a criminal gang that compromises corporate networks and then sells that access to ransomware groups, according to security researchers. This backdoor, also tracked as MLTBackdoor, was first documented...Read More
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. The operation was carried out by the Polish Cybercrime Bureau (CBZC) with support from the FBI and Homeland Security Investigations (HSI) in the United States. According to investigators, the suspects...Read More
Prediction market giant Polymarket confirmed that hackers stole funds from an unspecified number of users after a third-party breach. In an X post on Thursday, Polymarket said that a compromise at a third-party vendor allowed hackers to inject malicious code into its website “for some users.” The company said it has “contained” the incident and...Read More
RICHMOND, Va. — A unique summer program in Richmond is helping visually impaired students discover what is possible in the world of technology. Twenty-one students from across Virginia are participating in the 10th annual Department for the Blind and Vision Impaired’s Cyber Space Program. Students are building websites from scratch, learning cybersecurity fundamentals, and exploring...Read More
A recent presentation from Kaspersky APAC, Ransomware groups negotiation tactics: what you need to know, explained for webinar participants how the ransomware ecosystem looks and operates today, the tactics being used and the negotiation steps which seem to be common from one attack to the next. That said, the Asia-Pacific regional division of the global...Read More
International law enforcement agencies, working alongside Microsoft and leading cybersecurity firms, have dealt another significant blow to the global cybercrime ecosystem after dismantling the infrastructure supporting the StealC infostealer and Amadey malware operations. The coordinated action marks the latest phase of Operation Endgame, one of the largest international campaigns ever launched against the digital infrastructure...Read More
The National Association of Insurance Commissioners (NAIC) now says the data taken earlier this month from its information technology systems has been published online by the hackers responsible. In a short note on it’s website, NAIC said it is “actively working with an external cybersecurity partner to compare the scope and type of data the...Read More
LEXINGTON, Ky. (WKYT) – About 40 middle school students are participating in the KC-7 Cybersecurity Summer Camp at The Hill this week, investigating realistic cyber incidents and analyzing digital evidence to identify potential threats. The STEM camp is designed for underserved and at-risk youth populations in Title One schools. It introduces students to one of...Read More
Per Bleeping Computer, a new malicious Microsoft Edge extension named “Edgecution” has been identified by Zscaler, capable of escaping browser sandboxes and deploying a Python-based backdoor, facilitating ransomware attacks.The Edgecution malware exploits the Chrome Native Messaging protocol to enable communication between browser extensions and native desktop applications. Attackers impersonate IT support on Microsoft Teams, directing...Read More
Cyber-Crime Former employee accuses company of prioritizing pending IPO over client security Security firm Huntress allegedly has a turncoat insider leaking info to a ransomware operation, according to an ex-employee who took his grievances to social media after claiming the security shop tried to “silence” him with legal threats. And it all started with a...Read More