FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Attacks

FortiBleed, the large-scale campaign targeting Fortinet FortiGate firewalls and VPN gateways, has now been linked to the ransomware groups INC and Lynx, making the threat even more serious. Security researchers found evidence that the stolen credentials are not only being collected but are also being used in real ransomware operations. This marks one of the … Continued

Fake GitHub PoC Repositories Spread ChocoPoC RAT to Target Vulnerability Researchers

Cybersecurity researchers have uncovered a new malware campaign that specifically targets vulnerability researchers and penetration testers. The malware, named ChocoPoC, is being spread through fake proof-of-concept (PoC) exploit repositories hosted on GitHub. These repositories appear to contain working exploits for newly disclosed security vulnerabilities, making them look trustworthy to professionals who regularly test the latest … Continued

Anthropic’s AI Finds Hidden Software Bugs as IBM Invests $5 Billion to Speed Up Cybersecurity Fixes

Anthropic has introduced a powerful AI system that is changing the way software security works. The company says its new AI can identify critical software vulnerabilities much faster than traditional testing methods. Instead of releasing the model publicly, Anthropic is working with leading technology companies and government partners to responsibly fix the flaws before they … Continued

ToddyCat’s Umbrij Malware Hijacks Gmail Accounts Using Google OAuth

Cybersecurity researchers have uncovered a new malware tool called Umbrij, which is being used by the advanced persistent threat (APT) group ToddyCat to gain unauthorized access to corporate Gmail accounts. Instead of stealing usernames and passwords, the malware abuses Google’s OAuth authorization process to obtain access tokens, allowing attackers to read emails through the Google … Continued

ConsentFix Attack Hijacks Microsoft 365 Accounts in Just 3 Seconds

Cybercriminals are now using a new phishing method called ConsentFix, which builds on the well-known ClickFix technique to take over Microsoft 365 accounts within seconds. Instead of breaking into systems through software flaws, attackers trick users into completing what looks like a normal verification step. Everything appears legitimate, making the attack much harder to recognize. … Continued

Over 900 Oracle E-Business Systems Exposed as Hackers Launch Active Cyber Attacks

More than 900 internet-facing Oracle E-Business Suite (EBS) systems have been identified as being exposed while cybercriminals actively target a newly discovered security flaw. Security researchers say attackers have already started exploiting the vulnerability against vulnerable servers. The issue affects Oracle Payments, an important part of Oracle E-Business Suite used by many organizations worldwide. The … Continued

Amazon Fined $2.25 Million for Failing to Help Identity Theft Victims

Amazon has agreed to pay a $2.25 million civil penalty after U.S. regulators found that the company failed to properly assist victims of identity theft. The action was announced by the U.S. Federal Trade Commission (FTC), which said Amazon did not provide important transaction records that victims needed to investigate fraudulent activity. These records are … Continued

Phantom Squatting: Hackers Turn AI-Hallucinated Domains Into Phishing and Malware Traps

Cybersecurity researchers have uncovered a new attack technique called Phantom Squatting, where cybercriminals take advantage of web addresses that artificial intelligence (AI) models mistakenly generate. Instead of relying on fake domains that closely resemble real ones, attackers register domains that never actually existed but are repeatedly suggested by AI systems. Researchers say this creates a … Continued

81 Million Azure Login Attempts: Password Spray Attack Compromises Microsoft Accounts

Cybersecurity researchers have uncovered a massive password spray campaign targeting Microsoft’s Azure Command-Line Interface (Azure CLI). According to Huntress, the attackers carried out more than 81 million login attempts between June 12 and June 26. The campaign successfully compromised at least 78 Microsoft user accounts across 64 different organizations. Researchers believe the attack is still … Continued

Newsletter line