Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers

Attackers have exploited the critical defect to reconfigure firewall settings, create unauthorized accounts with privileged access to multiple versions of the vendor’s security products.

The post Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers appeared first on CyberScoop.

Continue reading Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers

Cybercriminals and nation-state groups are exploiting a six-month old WinRAR defect

Nation-state groups are consistently exploiting the defect to target victims in military, government and technology for espionage.

The post Cybercriminals and nation-state groups are exploiting a six-month old WinRAR defect appeared first on CyberScoop.

Continue reading Cybercriminals and nation-state groups are exploiting a six-month old WinRAR defect

A new wave of ‘vishing’ attacks is breaking into SSO accounts in real time

Cybercrime groups, including one that identifies as ShinyHunters, are targeting single sign-on services to gain access to victim networks and steal data.

The post A new wave of ‘vishing’ attacks is breaking into SSO accounts in real time appeared first on CyberScoop.

Continue reading A new wave of ‘vishing’ attacks is breaking into SSO accounts in real time

Leader of ransomware crew pleads guilty to four-year crime spree

Ianis Antropenko, a Russian national living in California, admitted to committing ransomware attacks against at least 50 victims. He faces up to 25 years in jail.

The post Leader of ransomware crew pleads guilty to four-year crime spree appeared first on CyberScoop.

Continue reading Leader of ransomware crew pleads guilty to four-year crime spree

Black Basta’s alleged ringleader identified as authorities raid homes of other members

Oleg Evgenievich Nefedov, a 35-year-old Russian national, is accused of forming and running the ransomware outfit since 2022. He’s now on Europol and Interpol’s most-wanted lists.

The post Black Basta’s alleged ringleader identified as authorities raid homes of other members appeared first on CyberScoop.

Continue reading Black Basta’s alleged ringleader identified as authorities raid homes of other members

The thin line between saving a company and funding a crime

Ransomware negotiators dish on being in a ‘moral gray zone,’ unrestricted by accountability or industrywide rules of engagement.

The post The thin line between saving a company and funding a crime appeared first on CyberScoop.

Continue reading The thin line between saving a company and funding a crime

Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks

Authorities linked the 40-year-old to multiple crimes by tracing the email address he used for a cybercrime forum to the same account he used to apply for a U.S. visa in 2016.

The post Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks appeared first on CyberScoop.

Continue reading Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks

Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers

The botnet took an unusual path by abusing residential proxy networks, allowing it to control an untapped collection of unofficial Android TV devices.

The post Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers appeared first on CyberScoop.

Continue reading Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers

Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day

Researchers said the information disclosure zero-day exposes sensitive information that attackers can use to undermine defenses and make other exploits more reliable.

The post Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day