CISA alerts federal agencies of widespread attacks using Cisco zero-days

Cisco said it was investigating state-sponsored espionage attacks in May. CISA did not explain why it waited four months to issue an emergency directive.

The post CISA alerts federal agencies of widespread attacks using Cisco zero-days appeared first on CyberScoop.

Continue reading CISA alerts federal agencies of widespread attacks using Cisco zero-days

Teen arrested in UK was a core figure in Scattered Spider’s operations

Researchers said Thalha Jubair was a principal operator, leading or directing many attacks attributed to the hacker subset of The Com since 2022.

The post Teen arrested in UK was a core figure in Scattered Spider’s operations appeared first on CyberScoop.

Continue reading Teen arrested in UK was a core figure in Scattered Spider’s operations

Las Vegas police arrest minor accused of high-profile 2023 casino attacks

Officials accused the teenage boy of working with Scattered Spider, which attacked MGM Resorts and Caesars Entertainment in 2023.

The post Las Vegas police arrest minor accused of high-profile 2023 casino attacks appeared first on CyberScoop.

Continue reading Las Vegas police arrest minor accused of high-profile 2023 casino attacks

Researchers raise alarm over maximum-severity defect in GoAnywhere file-transfer service

The vendor didn’t provide evidence of active exploitation, yet experts said it’s only a matter of time before that changes.

The post Researchers raise alarm over maximum-severity defect in GoAnywhere file-transfer service appeared first on CyberScoop.

Continue reading Researchers raise alarm over maximum-severity defect in GoAnywhere file-transfer service

UK arrests two teens accused of heavy involvement in yearslong Scattered Spider attack spree

One suspect faces separate charges in the United States linking him to at least 120 cyberattacks.

The post UK arrests two teens accused of heavy involvement in yearslong Scattered Spider attack spree appeared first on CyberScoop.

Continue reading UK arrests two teens accused of heavy involvement in yearslong Scattered Spider attack spree

Attack on SonicWall’s cloud portal exposes customers’ firewall configurations

The company confirmed to CyberScoop that an unidentified cybercriminal accessed SonicWall’s customer portal through a series of brute-force attacks.

The post Attack on SonicWall’s cloud portal exposes customers’ firewall configurations appeared first on CyberScoop.

Continue reading Attack on SonicWall’s cloud portal exposes customers’ firewall configurations

Microsoft seizes hundreds of phishing sites tied to massive credential theft operation

The company acted on a court order and collaborated with Cloudflare to seize RaccoonO365’s infrastructure, which was used to steal credentials from organizations in 94 countries.

The post Microsoft seizes hundreds of phishing sites tied to massive credential theft operation appeared first on CyberScoop.

Continue reading Microsoft seizes hundreds of phishing sites tied to massive credential theft operation

Apple addresses dozens of vulnerabilities in latest software for iPhones, iPads and Macs

The tech giant doesn’t provide details about the severity of vulnerabilities it discloses, but none of the new defects are under active attack.

The post Apple addresses dozens of vulnerabilities in latest software for iPhones, iPads and Macs appeared first on CyberScoop.

Continue reading Apple addresses dozens of vulnerabilities in latest software for iPhones, iPads and Macs

SonicWall firewalls targeted by fresh Akira ransomware surge

A recent wave of attacks targeting SonicWall customers has researchers and authorities on alert. Many victim organizations had misconfigurations in their systems.

The post SonicWall firewalls targeted by fresh Akira ransomware surge appeared first on CyberScoop.

Continue reading SonicWall firewalls targeted by fresh Akira ransomware surge

The npm incident frightened everyone, but ended up being nothing to fret about

Disaster was averted after widely used open-source packages were compromised via social engineering.

The post The npm incident frightened everyone, but ended up being nothing to fret about appeared first on CyberScoop.

Continue reading The npm incident frightened everyone, but ended up being nothing to fret about