153GB of stolen credentials surface after LiteLLM supply chain attack

A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the ar… Continue reading 153GB of stolen credentials surface after LiteLLM supply chain attack

Signal’s new security feature checks if your encrypted chats were tampered with

Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an addi… Continue reading Signal’s new security feature checks if your encrypted chats were tampered with

Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-runn… Continue reading Lazarus hackers pair fake job offers with Windows zero-day exploit

Split-second deepfake glitch blows digital certificate fraudster’s cover

Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man … Continue reading Split-second deepfake glitch blows digital certificate fraudster’s cover

Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found. Researchers di… Continue reading Ready-made $500 kit puts a crypto scam within anyone’s reach

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execut… Continue reading Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Ransomware gangs don’t need control system access to disrupt industrial production

Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware… Continue reading Ransomware gangs don’t need control system access to disrupt industrial production

Previously unseen entry vector used to breach Polish energy plant

The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a D… Continue reading Previously unseen entry vector used to breach Polish energy plant

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data brea… Continue reading Cyberattack on Steam hardware shipper leaks names, addresses, and order data