Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four cities

The criminal organization specialized in business email compromise scams and generated billions of dollars in criminal proceeds annually from many small-scale operations, officials said.

The post Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four cities appeared first on CyberScoop.

Continue reading Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four cities

Inside Vercel’s sleep-deprived race to contain React2Shell

Talha Tariq quickly found his company at the center of a fast-moving, high-stakes mitigation effort. The result: a bounty program, a cat-and-mouse patch fight, and a debate about open-source security coordination.

The post Inside Vercel’s sleep-deprived race to contain React2Shell appeared first on CyberScoop.

Continue reading Inside Vercel’s sleep-deprived race to contain React2Shell

Researchers rush to warn defenders of max-severity defect in n8n

Roughly 100,000 servers running the automated workflow platform for AI and other enterprise tools are potentially exposed to exploitation.

The post Researchers rush to warn defenders of max-severity defect in n8n appeared first on CyberScoop.

Continue reading Researchers rush to warn defenders of max-severity defect in n8n

MongoBleed defect swirls, stamping out hope of year-end respite

The high-severity vulnerability is under active exploitation and affects many versions of MongoDB, a nearly ubiquitous open-source database.

The post MongoBleed defect swirls, stamping out hope of year-end respite appeared first on CyberScoop.

Continue reading MongoBleed defect swirls, stamping out hope of year-end respite

Leader of 764 offshoot pleads guilty, faces up to 60 years in jail

Alexis Chavez admitted to coercing multiple victims during a yearslong crime spree, landing law enforcement another win against the violent extremist collective he joined as a minor in 2022.

The post Leader of 764 offshoot pleads guilty, faces up to 60 years in jail appeared first on CyberScoop.

Continue reading Leader of 764 offshoot pleads guilty, faces up to 60 years in jail

Ukrainian national pleads guilty to Nefilim ransomware attacks

The 35-year-old faces up to 10 years in jail and authorities announced an $11 million reward for information on his alleged co-conspirator who remains at large.

The post Ukrainian national pleads guilty to Nefilim ransomware attacks appeared first on CyberScoop.

Continue reading Ukrainian national pleads guilty to Nefilim ransomware attacks

Former incident responders plead guilty to ransomware attack spree

Ryan Goldberg and Kevin Martin were working at cybersecurity companies when they switched sides and hit five companies with ransomware attacks in 2023.

The post Former incident responders plead guilty to ransomware attack spree appeared first on CyberScoop.

Continue reading Former incident responders plead guilty to ransomware attack spree

Cisco customers hit by fresh wave of zero-day attacks from China-linked APT

Cisco has yet to release a patch for the actively exploited vulnerability, and attacks have been underway since at least late November.

The post Cisco customers hit by fresh wave of zero-day attacks from China-linked APT appeared first on CyberScoop.

Continue reading Cisco customers hit by fresh wave of zero-day attacks from China-linked APT

React2Shell fallout spreads to sensitive targets as public exploits hit all-time high

Attacker interest in the vulnerability is magnified by an unparalleled number of publicly available exploits, earning the defect the highest verified public exploit count of any CVE ever.

The post React2Shell fallout spreads to sensitive targets as public exploits hit all-time high appeared first on CyberScoop.

Continue reading React2Shell fallout spreads to sensitive targets as public exploits hit all-time high

Amazon warns that Russia’s Sandworm has shifted its tactics

Researchers said attackers linked to Russia’s military intelligence agency have moved from vulnerability exploits to focus on poorly configured network edge devices to keep its access to target networks.

The post Amazon warns that Russia’s Sandworm has shifted its tactics appeared first on CyberScoop.

Continue reading Amazon warns that Russia’s Sandworm has shifted its tactics