Sourcewww.cyber.gc.ca
Curated
Daily curated cyber threat intelligence for security professionals.
Sourcewww.cyber.gc.ca
Curated
Published
Massive 1.17TB Data Leak Exposes Billions of IoT Grow Light Records A massive data leak exposed 2.7 billion records from Mars Hydro, a Chinese IoT grow light company, including Wi-Fi passwords, IP addresses, and device IDs. The unprotected database, discovered by cybersecurity researcher Jeremiah Fowler, contained sensitive information and was secured within hours of notification. This incident highlights the urgent need for improved data protection measures in IoT devices and apps.
Sourcemedium.com
Curated
A reflected XSS vulnerability was discovered in the main site search, bypassing a WAF and HTML sanitizer using two reflections of the input. The exploit involves injecting an
Sourcewww.darkreading.com
Curated
Japan has passed the Active Cyber Defense Bill, granting the government new powers to combat cyberattacks. The legislation, a response to mounting cyber threats and criticism of Japan’s cybersecurity preparedness, enables proactive measures like shutting down enemy servers and hiring “cyber harm prevention officers.” While controversial, the bill reflects Japan’s shift towards a more proactive cybersecurity stance.
Published
Ransomware Groups Made Less Money in 2024 www.darkreading.com/cybersecu…
The total volume of ransom payments decreased year-over-year by approximately 35%, due to law enforcement activities and more victims refusing to pay, according to blockchain analytics company Chainalysis.
In 2024, ransomware attackers collected approximately $813.55 million in payments, a significant drop from the $1.25 billion collected in 2023 and $1.07 billion collected in 2021, Chainalysis said in its 2025 Crypto Crime Report.
Improved cyber hygiene and overall resiliency is helping organizations make the decision to not pay, according to Christian Geyer, founder and CEO of Actfore. Better incident response capabilities, digital forensics, and data mining services are helping victims identify the breached data faster.
“Organizations have increasingly implemented comprehensive data backup solutions, so the business can rapidly recover their systems through a wipe and restore process,” Geyer said.
Published
Russian military hackers deploy malicious Windows activators in Ukraine www.bleepingcomputer.com/news/secu…
The Sandworm Russian military cyber-espionage group is targeting Windows users in Ukraine with trojanized Microsoft Key Management Service (KMS) activators and fake Windows updates.
These attacks likely started in late 2023 and have now been linked by EclecticIQ threat analysts with Sandworm hackers based on overlapping infrastructure, consistent Tactics, Techniques and Procedures (TTPs), and frequently used ProtonMail accounts to register domains used in the attacks.
The attackers also used a BACKORDER loader to deploy DarkCrystal RAT (DcRAT) malware (used in previous Sandworm attacks) and debug symbols referencing a Russian-language build environment, further reinforcing the researchers' confidence that Russian military hackers were involved.
Published
Russian bulletproof hosting service Zservers sanctioned by US for LockBit coordination therecord.media/zservers-…
A Russian service used to facilitate ransomware attacks by LockBit hackers has been sanctioned by U.S. authorities.
The company, Zservers, offers bulletproof hosting — which allows cybercriminals to avoid law enforcement while renting IP addresses, servers and domains used for disseminating malware, forming botnet armies and carrying out other tasks related to fraud and cyberattacks.
On Tuesday, the U.S. Treasury Department partnered with officials in Australia and the U.K. in sanctioning Zservers as well as Russian nationals Alexander Igorevich Mishin and Aleksandr Sergeyevich Bolshakov, who served as administrators at the company.
According to the U.S., LockBit affiliates frequently leased IP addresses from Zservers. The company is based in Barnaul, Russia, and advertises its services on cybercriminal forums. Blockchain analysis company Elliptic said it confirmed the link between the cybercrime gang and Zservers.
Published
Over 12,000 KerioControl firewalls exposed to exploited RCE flaw www.scworld.com/brief/tho…
Over twelve thousand GFI KerioControl firewall instances are exposed to a critical remote code execution vulnerability tracked as CVE-2024-52875.
KerioControl is a network security suite that small and medium-sized businesses use for VPNs, bandwidth management, reporting and monitoring, traffic filtering, AV protection, and intrusion prevention.
The flaw in question was discovered in mid-December by security researcher Egidio Romano (EgiX), who demonstrated the potential for dangerous 1-click RCE attacks.
GFI Software released a security update for the problem with version 9.4.5 Patch 1 on December 19, 2024, yet three weeks later, according to Censys, over 23,800 instances remained vulnerable.
Despite the warning about active exploitation, threat monitoring service The Shadowserver Foundation now reports seeing 12,229 KerioControl firewalls exposed to attacks leveraging CVE-2024-52875.
“NOTE: the Reflected XSS vector might be abused to perform 1-click Remote Code Execution (RCE) attacks.”
If you haven’t applied the security update yet, it is strongly advised that you install KerioControl version 9.4.5 Patch 2, released on January 31, 2025, which contains additional security enhancements.
Published
Microsoft’s February Patch a Lighter Lift Than January’s www.darkreading.com/applicati…
Microsoft’s February security update contains substantially fewer vulnerabilities for admins to address compared to a month ago, but there’s still plenty in it that requires immediate attention.
Topping the list are two zero-day vulnerabilities that attackers are actively exploiting in the wild, two more that are publicly known but not exploited yet, a patch for a zero-day that Microsoft disclosed in December 2024, and an assortment of other common vulnerabilities and exposures (CVEs) with potentially severe consequences for affected organizations.
Published
SonicWall firewall exploit lets hackers hijack VPN sessions, patch now www.bleepingcomputer.com/news/secu…
Security researchers at Bishop Fox have published complete exploitation details for the CVE-2024-53704 vulnerability that allows bypassing the authentication mechanism in certain versions of the SonicOS SSLVPN application.
The vendor warned about the high exploitation possibility of the flaw in a bulletin on January 7, urging administrators to upgrade their SonicOS firewalls' firmware to address the problem.
The flaw allows a remote attacker to hijack active SSL VPN sessions without authentication, granting them unauthorized access to the victim’s network.
On January 22 Bishop Fox researchers announced that they had developed an exploit for CVE-2024-53704 after a “significant reverse-engineering effort,” confirming SonicWall’s fears about the exploitation potential of the vulnerability.
After allowing some time for system administrators to apply the available patches, Bishop Fox released the full exploitation details on Monday.
Fixes were made available in SonicOS 8.0.0-8037 and later, 7.0.1-5165 and higher, 7.1.3-7015 and higher, and 6.5.5.1-6n and higher. For model-specific information, check out SonicWall’s bulletin here.
Sourcehackread.com
Curated
Cisco denies recent data breach claims by the Kraken ransomware group, stating the leaked credentials are from a resolved 2022 incident. The company asserts the exposed information, including usernames, domains, and hashed passwords, poses no risk to customers. While the incident highlights the prevalence of credential-based cyberattacks, Cisco maintains the breach was contained and resolved.
Sourcewww.cyber.gc.ca
Curated
Sourcewww.cyber.gc.ca
Curated
Sourcewww.cyber.gc.ca
Curated
Sourcewww.cyber.gc.ca
Curated
Sourcewww.cyber.gc.ca
Curated
Sourcewww.shelltrail.com
Curated
A vulnerability in Sitevision CMS allows remote attackers to access private keys used for signing SAML Authn requests. The issue arises from a low-complexity, auto-generated password protecting the Java keystore containing these keys, which can be cracked offline. While the impact is difficult to assess, it highlights the importance of strong password complexity and proper configuration for sensitive data protection.
Sourcesecurityaffairs.com
Curated
OpenSSL patched a high-severity vulnerability, CVE-2024-12797, that allowed man-in-the-middle attacks on TLS connections using raw public keys. The vulnerability, discovered by Apple, impacted OpenSSL 3.2, 3.3, and 3.4 and was fixed in versions 3.2.4, 3.3.2, and 3.4.1. This vulnerability highlights the importance of secure communication protocols and regular software updates.
Sourcewww.cyber.gc.ca
Curated
Sourcehackread.com
Curated
A hacker claims to have breached OmniGPT, an AI-powered chatbot and productivity platform, exposing over 30,000 user emails, phone numbers, and 34 million lines of chat messages. The leaked data includes sensitive information like API keys, credentials, and file links, potentially leading to identity theft, phishing, and financial fraud. OmniGPT has yet to issue an official response to the alleged breach.
Sourcecyberscoop.com
Curated
Microsoft released a security update addressing 63 vulnerabilities, including two zero-day flaws. One zero-day allows attackers to delete targeted files on a system, while the other enables privilege escalation and system compromise. Nine vulnerabilities are rated as “more likely” to be exploited, including remote-code execution flaws in Microsoft SharePoint Server and Windows Telephony Service.
Sourcesecurityaffairs.com
Curated
Threat actors are exploiting a new zero-day vulnerability in FortiOS and FortiProxy to hijack Fortinet firewalls. The vulnerability, CVE-2025-24472, allows remote attackers to gain super-admin privileges by making maliciously crafted CSF proxy requests. Arctic Wolf researchers observed a campaign involving unauthorized logins, account creation, and configuration changes on Fortinet FortiGate firewalls, likely exploiting this zero-day flaw.
Published
Malware from fake recruiters www.gdatasoftware.com/blog/2025…
Fake recruiters are currently on the hunt for CVs – and also your data. Reports have emerged about malware being put into work assignments that supposedly test a candidate’s technical skills.
Recruiters are in a constant struggle to find matches for their job openings. Be it via classic job ads online, or via DM on platforms like LinkedIn.
We have recently discovered a report by several users on Reddit who says that they have been contacted by a recruiter and given a task to create a work sample. This practice is not uncommon, though it has been claimed in the past that some companies use this tactic to take advantage of applicants and get production work done for free. But on the whole, companies want to see that you are capable of doing what your resume says. This case, however, was interesting. From the fact that you are reading this post on the blog of a company that fights malware, you can probably guess where this is going. But let’s not get ahead of ourselves.
Published
Sky ECC encrypted service distributors arrested in Spain, Netherlands www.bleepingcomputer.com/news/lega…
Four distributors of the encrypted communications service Sky ECC, used extensively by criminals, were arrested in Spain and the Netherlands.
According to an announcement by the Spanish police, the two suspects arrested in the country were the leading global distributors of the service, generating over €13.5 million ($14M) in profits.
In March 2021, Europol announced that it had cracked Sky ECC’s encryption, allowing investigators to monitor the communications of 70,000 users, revealing extensive criminal activity.
Today, the police in Spain announced the apprehension of two leading sellers of the Sky ECC service and the confiscation of money and key items.
The search and arrest operation took place in late January 2025 in Jávea (Alicante) and Ibiza.
The police in the Netherlands reported on January 31, 2025, that they arrested two men in Amsterdam and Arnhem. The two were high-ranking sellers of the service, reportedly having direct contact with the platform’s CEO for years.
Published
4 Arrested as Police Dismantle 8Base Ransomware, Seize Dark Web Sites hackread.com/police-di…
International law enforcement agencies have seized the dark web infrastructure of the notorious 8Base ransomware group and arrested four suspected members, including two men and two women.
The operation, led by the Bavarian State Criminal Police Office and the Office of the Public Prosecutor General in Bamberg, targeted the group’s TOR-based leak site used to publish stolen data and pressure victims into paying ransoms.
According to a Thai media report, the arrests, carried out in Phuket, Thailand, targeted individuals believed to be part of the Phobos ransomware gang, the malware family linked to 8Base’s operations. The suspects are accused of carrying cyberattacks against over 1,000 victims worldwide, marking a big win in the ongoing fight against ransomware.