Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

Cameron Wagenius faces a maximum of 27 years in prison. A researcher that helped with the investigation called this ‘one of the most significant wins in the fight against cybercrime.’

The post Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others appeared first on CyberScoop.

Continue reading Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

AsyncRAT seeds family of more than 30 remote access trojans

ESET researchers observed tens of thousands of machines infected with AsyncRAT and its variants over the past year. The open-source malware is a popular tool among cybercriminals.

The post AsyncRAT seeds family of more than 30 remote access trojans appeared first on CyberScoop.

Continue reading AsyncRAT seeds family of more than 30 remote access trojans

CitrixBleed 2 beckons sweeping alarm as exploits spread across the globe

The number of Citrix customers impacted by CVE-2025-5777 remains unknown, but researchers have already observed more than 11.5 million attack attempts, targeting thousands of sites.

The post CitrixBleed 2 beckons sweeping alarm as exploits spread across the globe appeared first on CyberScoop.

Continue reading CitrixBleed 2 beckons sweeping alarm as exploits spread across the globe

Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited

Researchers are especially concerned about a high-severity defect in SQL Server and a critical vulnerability in SPNEGO, a foundational protocol.

The post Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited

Oligo Security strives to fill application-layer gaps in MITRE ATT&CK framework

Application Attack Matrix is a community effort designed to help defenders and organizations better understand and define how attackers use and exploit weaknesses in applications.

The post Oligo Security strives to fill application-layer gaps in MITRE ATT&CK framework appeared first on CyberScoop.

Continue reading Oligo Security strives to fill application-layer gaps in MITRE ATT&CK framework

Scattered Spider weaves web of social-engineered destruction

The cybercrime ring has infiltrated more than 100 businesses since 2022, including more than a dozen since it regrouped earlier this year.

The post Scattered Spider weaves web of social-engineered destruction appeared first on CyberScoop.

Continue reading Scattered Spider weaves web of social-engineered destruction

China-linked attacker hit France’s critical infrastructure via trio of Ivanti zero-days last year

French authorities said government agencies and businesses spanning telecom, media, finance and transportation were impacted by the widely exploited Ivanti vulnerabilities.

The post China-linked attacker hit France’s critical infrastructure via trio of Ivanti zero-days last year appeared first on CyberScoop.

Continue reading China-linked attacker hit France’s critical infrastructure via trio of Ivanti zero-days last year

US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations

Russia-based Aeza Group allegedly provided infrastructure to BianLian ransomware and the Meduza, RedLine and Lumma infostealer operators.

The post US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations appeared first on CyberScoop.

Continue reading US sanctions bulletproof hosting provider for supporting ransomware, infostealer operations

Notorious cybercriminal ‘IntelBroker’ arrested in France, awaits extradition to US

Kai West, a 25-year-old British national, is accused of stealing data from more than 40 organizations during a two-year spree.

The post Notorious cybercriminal ‘IntelBroker’ arrested in France, awaits extradition to US appeared first on CyberScoop.

Continue reading Notorious cybercriminal ‘IntelBroker’ arrested in France, awaits extradition to US

Citrix users hit by actively exploited zero-day vulnerability

The vendor disclosed the critical zero-day in NetScaler ADC and NetScaler Gateway nine days after it warned of a pair of defects in the same products.

The post Citrix users hit by actively exploited zero-day vulnerability appeared first on CyberScoop.

Continue reading Citrix users hit by actively exploited zero-day vulnerability