Attackers bypass patch in deprecated Windows Server update tool

Microsoft addressed the critical vulnerability earlier this month, but had to issue an emergency update to resolve issues it previously missed.

The post Attackers bypass patch in deprecated Windows Server update tool appeared first on CyberScoop.

Continue reading Attackers bypass patch in deprecated Windows Server update tool

North Korea’s Lazarus group attacked three companies involved in drone development

The attacks, which involved fake job offers as a social engineering lure, were likely aimed at stealing proprietary information about drone manufacturing, ESET said in a report.

The post North Korea’s Lazarus group attacked three companies involved in drone development appeared first on CyberScoop.

Continue reading North Korea’s Lazarus group attacked three companies involved in drone development

Researchers track surge in high-level Smishing Triad activity

The China-linked operation has grown from a phishing kit marketplace into an active and growing community supporting a decentralized large-scale phishing ecosystem.

The post Researchers track surge in high-level Smishing Triad activity appeared first on CyberScoop.

Continue reading Researchers track surge in high-level Smishing Triad activity

Researchers uncover remote code execution flaw in abandoned Rust code library

The high-severity defect affects a widely used — but largely hidden — archive tool that spans many forks.

The post Researchers uncover remote code execution flaw in abandoned Rust code library appeared first on CyberScoop.

Continue reading Researchers uncover remote code execution flaw in abandoned Rust code library

China’s spy agency accuses NSA of yearslong attack on the country’s timekeeping service

The NSA did not confirm nor deny the allegations made by China’s Ministry of State Security. China said the origins of the attack date back to March 2022.

The post China’s spy agency accuses NSA of yearslong attack on the country’s timekeeping service appeared first on CyberScoop.

Continue reading China’s spy agency accuses NSA of yearslong attack on the country’s timekeeping service

Europol dismantles cybercrime network linked to $5.8M in financial losses

Authorities arrested seven people allegedly involved in the operation and seized 1,200 SIM boxes containing 40,000 active SIM cards.

The post Europol dismantles cybercrime network linked to $5.8M in financial losses appeared first on CyberScoop.

Continue reading Europol dismantles cybercrime network linked to $5.8M in financial losses

North Korean operatives spotted using evasive techniques to steal data and cryptocurrency

Research from Cisco Talos and Google Threat Intelligence Group underscores the extent to which North Korea-aligned attackers attempt to avoid detection.

The post North Korean operatives spotted using evasive techniques to steal data and cryptocurrency appeared first on CyberScoop.

Continue reading North Korean operatives spotted using evasive techniques to steal data and cryptocurrency

PowerSchool hacker sentenced to 4 years in prison

Matthew Lane pleaded guilty to crimes stemming from attacks on PowerSchool and a U.S. telecom company earlier this year. His sentence is half the amount prosecutors sought in the cause.

The post PowerSchool hacker sentenced to 4 years in prison appeared first on CyberScoop.

Continue reading PowerSchool hacker sentenced to 4 years in prison

CISA warns of imminent risk posed by thousands of F5 products in federal agencies

Cyber authorities issued their second emergency directive in three weeks. This one requires agencies to mitigate or disconnect potentially compromised F5 devices and services.

The post CISA warns of imminent risk posed by thousands of F5 products in federal agencies appeared first on CyberScoop.

Continue reading CISA warns of imminent risk posed by thousands of F5 products in federal agencies

Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero-days

The tech giant addressed a record-high number of defects for the year in its latest update.

The post Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero-days appeared first on CyberScoop.

Continue reading Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero-days