Cyber Security

Cyber Security
Cyber Security

RMM Tools Essential for IT Operations but Increasingly Weaponized by Attackers

rmm-tools-essential-for-it-operations-but-increasingly-weaponized-by-attackers

Remote Monitoring and Management (RMM) tools are the backbone of modern IT operations. Security professionals rely on them daily to patch systems, troubleshoot issues, and manage entire networks from anywhere. These tools deliver speed, control, and convenience — qualities every IT team values. But the same features that make them indispensable have made them a […]

FBI Investigates Hack on its Wiretap and Critical Surveillance Systems

fbi-investigates-hack-on-its-wiretap-and-critical-surveillance-systems

FBI Investigates Hack The Federal Bureau of Investigation has confirmed a cybersecurity incident targeting a sensitive internal network used to manage wiretapping operations and foreign intelligence surveillance warrants, raising serious concerns among national security officials about the potential exposure of classified law enforcement data. “The FBI identified and addressed suspicious activities on FBI networks, and […]

China-Nexus Hackers Attacking Telecommunication Providers With New Malware

china-nexus-hackers-attacking-telecommunication-providers-with-new-malware

A China-linked advanced persistent threat actor has been actively targeting telecommunications providers across South America since 2024, deploying three new malware implants to gain deep access into critical network infrastructure. The group, tracked as UAT-9244, operates against both Windows and Linux-based endpoints, as well as network edge devices — the embedded hardware that telecom providers […]

Threat Actors Using Fake Claude Code Download to Deploy Infostealer

threat-actors-using-fake-claude-code-download-to-deploy-infostealer

Cybercriminals have found a new way to target developers and IT professionals by setting up fake download pages that impersonate Claude Code, a legitimate AI coding assistant. These deceptive pages trick users into downloading what appears to be an official installation package, but instead silently deploy an infostealer malware onto the victim’s system. The use […]

Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access

cisco-catalyst-sd-wan-vulnerabilities-allow-attackers-to-gain-root-access

Cisco Catalyst SD-WAN Vulnerabilities An urgent security advisory from Cisco warns that multiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow attackers to bypass authentication, gain root access, and overwrite critical files. Two of these vulnerabilities are already being exploited in the wild by hackers, making immediate remediation critical.​ The advisory details five vulnerabilities, led […]

Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners

tycoon-2fa-phishing-kit-disrupted-by-microsoft,-europol-and-partners

Microsoft, Europol, and partners have dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform, seizing 330 domains used for credential theft and MFA bypass. This coordinated action disrupts a service active since 2023 that powered tens of millions of phishing emails monthly. Tycoon 2FA enabled cybercriminals to bypass multifactor authentication (MFA) via adversary-in-the-middle (AiTM) techniques, capturing credentials, […]

Operation Leak Dismantles LeakBase Cybercriminal Forum User Data, IP Logs Secured by Authorities

operation-leak-dismantles-leakbase-cybercriminal-forum-user-data,-ip-logs-secured-by-authorities

The FBI, in coordination with multiple international law enforcement agencies, has officially seized LeakBase, a prominent cybercriminal forum notorious for hosting and trading stolen databases, under a coordinated global operation dubbed “Operation Leak.” Both primary domains, leakbase[.]ws and leakbase[.]la, now redirect visitors to an FBI seizure banner, with name servers switched to ns1.fbi.seized.gov and ns2.fbi.seized.gov. The takedown was […]

CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks

cisa-warns-of-vmware-aria-operations-vulnerability-exploited-in-attacks

VMware Aria Operations Vulnerability A critical vulnerability affecting VMware Aria Operations has been added to the Known Exploited Vulnerabilities (KEV) catalog. Broadcom recently issued a security advisory detailing a flaw that allows unauthenticated attackers to execute arbitrary commands. Organizations are urged to implement mitigations or discontinue use of the product if a fix is not […]