Attack on SonicWall’s cloud portal exposes customers’ firewall configurations

The company confirmed to CyberScoop that an unidentified cybercriminal accessed SonicWall’s customer portal through a series of brute-force attacks.

The post Attack on SonicWall’s cloud portal exposes customers’ firewall configurations appeared first on CyberScoop.

Continue reading Attack on SonicWall’s cloud portal exposes customers’ firewall configurations

Microsoft seizes hundreds of phishing sites tied to massive credential theft operation

The company acted on a court order and collaborated with Cloudflare to seize RaccoonO365’s infrastructure, which was used to steal credentials from organizations in 94 countries.

The post Microsoft seizes hundreds of phishing sites tied to massive credential theft operation appeared first on CyberScoop.

Continue reading Microsoft seizes hundreds of phishing sites tied to massive credential theft operation

Apple addresses dozens of vulnerabilities in latest software for iPhones, iPads and Macs

The tech giant doesn’t provide details about the severity of vulnerabilities it discloses, but none of the new defects are under active attack.

The post Apple addresses dozens of vulnerabilities in latest software for iPhones, iPads and Macs appeared first on CyberScoop.

Continue reading Apple addresses dozens of vulnerabilities in latest software for iPhones, iPads and Macs

SonicWall firewalls targeted by fresh Akira ransomware surge

A recent wave of attacks targeting SonicWall customers has researchers and authorities on alert. Many victim organizations had misconfigurations in their systems.

The post SonicWall firewalls targeted by fresh Akira ransomware surge appeared first on CyberScoop.

Continue reading SonicWall firewalls targeted by fresh Akira ransomware surge

The npm incident frightened everyone, but ended up being nothing to fret about

Disaster was averted after widely used open-source packages were compromised via social engineering.

The post The npm incident frightened everyone, but ended up being nothing to fret about appeared first on CyberScoop.

Continue reading The npm incident frightened everyone, but ended up being nothing to fret about

Microsoft Patch Tuesday addresses 81 vulnerabilities, none actively exploited

The company is ahead of pace, disclosing about 100 more vulnerabilities at this point in the year than it did in 2024, according to a researcher.

The post Microsoft Patch Tuesday addresses 81 vulnerabilities, none actively exploited appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday addresses 81 vulnerabilities, none actively exploited

Treasury Department targets Southeast Asia scam hubs with sanctions

Cybercrime hubs in Southeast Asia scammed Americans out of at least $10 billion last year, a 66% increase from 2023, officials said.

The post Treasury Department targets Southeast Asia scam hubs with sanctions appeared first on CyberScoop.

Continue reading Treasury Department targets Southeast Asia scam hubs with sanctions

Salesloft Drift security incident started with undetected GitHub access

The company said a threat actor accessed and snooped around its account for months, then stole OAuth tokens for Drift integrations from its cloud environment.

The post Salesloft Drift security incident started with undetected GitHub access appeared first on CyberScoop.

Continue reading Salesloft Drift security incident started with undetected GitHub access

Sitecore zero-day vulnerability springs up from exposed machine key

The actively exploited defect, triggered by an attacker’s use of a publicly available sample machine key, underscores the vendor and customers’ poor configuration practices.

The post Sitecore zero-day vulnerability springs up from exposed machine key appeared first on CyberScoop.

Continue reading Sitecore zero-day vulnerability springs up from exposed machine key

Streameast, world’s largest pirated live sports network, shut down by Egyptian authorities

An antipiracy coalition of entertainment companies applauded the takedown. The network’s two operators were arrested at their residences in Egypt.

The post Streameast, world’s largest pirated live sports network, shut down by Egyptian authorities appeared first on CyberScoop.

Continue reading Streameast, world’s largest pirated live sports network, shut down by Egyptian authorities