Cisco zero-day under ongoing attack by persistent threat group

The threat group behind the attacks is also linked to a series of recently disclosed vulnerabilities in the vendor’s firewalls and SD-WAN systems.

The post Cisco zero-day under ongoing attack by persistent threat group appeared first on CyberScoop.

Continue reading Cisco zero-day under ongoing attack by persistent threat group

Major tech manufacturer Foxconn confirms cyberattack hit North American factories

The ransomware group Nitrogen claimed responsibility for the attack and said it stole 8 terabytes of data spanning more than 11 million files belonging to the company’s top customers.

The post Major tech manufacturer Foxconn confirms cyberattack hit North American factories appeared first on CyberScoop.

Continue reading Major tech manufacturer Foxconn confirms cyberattack hit North American factories

Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical

The high volume of vulnerabilities reflects a growing trend researchers have been anticipating as artificial intelligence models are deployed to find previously uncovered defects in code.

The post Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical appeared first on CyberScoop.

Continue reading Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical

Pressure mounts on Canvas as data leak extortion deadline looms

Attackers affiliated with The Com are threatening to leak data from more than 8,800 school systems if Instructure doesn’t pay a ransom.

The post Pressure mounts on Canvas as data leak extortion deadline looms appeared first on CyberScoop.

Continue reading Pressure mounts on Canvas as data leak extortion deadline looms

Google spotted an AI-developed zero-day before attackers could use it

Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain.

The post Google spotted an AI-developed zero-day before attackers could use it appeared first on CyberScoop.

Continue reading Google spotted an AI-developed zero-day before attackers could use it

Ivanti customers confront yet another actively exploited zero-day

Attackers are hitting a frequent target in the network edge space, intruding victim networks through a defect in a widely used mobile endpoint security product.

The post Ivanti customers confront yet another actively exploited zero-day appeared first on CyberScoop.

Continue reading Ivanti customers confront yet another actively exploited zero-day

A critical Palo Alto PAN-OS zero-day is being exploited in the wild

The vendor hasn’t released a patch for the vulnerability or described the scope and objective of confirmed attacks.

The post A critical Palo Alto PAN-OS zero-day is being exploited in the wild appeared first on CyberScoop.

Continue reading A critical Palo Alto PAN-OS zero-day is being exploited in the wild

Latvian national sentenced for ransomware attacks run by former Conti leaders

Deniss Zolotarjovs was mostly tasked with putting pressure on the Russia-based crew’s victims, in one case leaking hundreds of children’s health records.

The post Latvian national sentenced for ransomware attacks run by former Conti leaders appeared first on CyberScoop.

Continue reading Latvian national sentenced for ransomware attacks run by former Conti leaders

‘Copy Fail’ is a real Linux security crisis wrapped in AI slop

The actively exploited defect could affect every mainstream Linux distribution built since 2017, but some researchers found Theori’s AI-generated disclosure unhelpful and lacking.

The post ‘Copy Fail’ is a real Linux security crisis wrapped in AI slop appeared first on CyberScoop.

Continue reading ‘Copy Fail’ is a real Linux security crisis wrapped in AI slop

Former incident responders sentenced to 4 years in prison for committing ransomware attacks

Ryan Goldberg and Kevin Martin attacked five companies in 2023 and extorted nearly $1.3 million from one of their victims.

The post Former incident responders sentenced to 4 years in prison for committing ransomware attacks appeared first on CyberScoop.

Continue reading Former incident responders sentenced to 4 years in prison for committing ransomware attacks