Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups

Linen Typhoon, Violet Typhoon and Storm-2603 are behind the initial attack spree that erupted over the weekend. Other threat groups are now following suit.

The post Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups appeared first on CyberScoop.

Continue reading Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups

Mass attack spree hits Microsoft SharePoint zero-day defect

Attackers have already used the exploit dubbed “ToolShell” to intrude hundreds of organizations globally, including private companies and government agencies.

The post Mass attack spree hits Microsoft SharePoint zero-day defect appeared first on CyberScoop.

Continue reading Mass attack spree hits Microsoft SharePoint zero-day defect

United Natural Foods loses up to $400M in sales after cyberattack

The food distributor and wholesaler completely shut down its systems upon discovering the attack last month, yet core systems were restored and normal operating capacity returned within three weeks.

The post United Natural Foods loses up to $400M in sales after cyberattack appeared first on CyberScoop.

Continue reading United Natural Foods loses up to $400M in sales after cyberattack

Ryuk ransomware operator extradited to US, faces five years in federal prison

Karen Vardanyan and his co-conspirators allegedly deployed ransomware on hundreds of machines in 2019 and 2020, extorting more than $15 million from victims at the time.

The post Ryuk ransomware operator extradited to US, faces five years in federal prison appeared first on CyberScoop.

Continue reading Ryuk ransomware operator extradited to US, faces five years in federal prison

SonicWall customers hit by fresh, ongoing attacks targeting fully patched SMA 100 devices

Google Threat Intelligence Group said a financially motivated threat group is abusing the outdated remote access VPN devices, underscoring a continued pattern of threats confronting SonicWall customers.

The post SonicWall customers hit by fresh, ongoing attacks targeting fully patched SMA 100 devices appeared first on CyberScoop.

Continue reading SonicWall customers hit by fresh, ongoing attacks targeting fully patched SMA 100 devices

Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

Cameron Wagenius faces a maximum of 27 years in prison. A researcher that helped with the investigation called this ‘one of the most significant wins in the fight against cybercrime.’

The post Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others appeared first on CyberScoop.

Continue reading Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

AsyncRAT seeds family of more than 30 remote access trojans

ESET researchers observed tens of thousands of machines infected with AsyncRAT and its variants over the past year. The open-source malware is a popular tool among cybercriminals.

The post AsyncRAT seeds family of more than 30 remote access trojans appeared first on CyberScoop.

Continue reading AsyncRAT seeds family of more than 30 remote access trojans

CitrixBleed 2 beckons sweeping alarm as exploits spread across the globe

The number of Citrix customers impacted by CVE-2025-5777 remains unknown, but researchers have already observed more than 11.5 million attack attempts, targeting thousands of sites.

The post CitrixBleed 2 beckons sweeping alarm as exploits spread across the globe appeared first on CyberScoop.

Continue reading CitrixBleed 2 beckons sweeping alarm as exploits spread across the globe

Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited

Researchers are especially concerned about a high-severity defect in SQL Server and a critical vulnerability in SPNEGO, a foundational protocol.

The post Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited

Oligo Security strives to fill application-layer gaps in MITRE ATT&CK framework

Application Attack Matrix is a community effort designed to help defenders and organizations better understand and define how attackers use and exploit weaknesses in applications.

The post Oligo Security strives to fill application-layer gaps in MITRE ATT&CK framework appeared first on CyberScoop.

Continue reading Oligo Security strives to fill application-layer gaps in MITRE ATT&CK framework