On Friday, the U.S. Department of the Treasury announced sanctions against Integrity Technology Group, a Beijing-based cybersecurity firm accused of aiding a state-sponsored hacking collective known as Flax Typhoon.
The hackers allegedly leveraged Integrity Tech’s services and infrastructure to compromise...
Federal authorities have unsealed an indictment against a U.S. Army soldier, accusing him of selling and attempting to sell stolen confidential phone records.
Cameron John Wagenius, a 20-year-old soldier stationed at Fort Cavazos in Killeen, Texas, was arrested on December...
Security researchers have uncovered a novel attack targeting macOS systems running on Apple Silicon processors. Dubbed "SysBumps," this attack exploits speculative execution vulnerabilities in system calls to bypass kernel isolation and break Kernel Address Space Layout Randomization (KASLR), a...
German authorities have charged three Russian-German nationals with espionage and sabotage activities aimed at undermining Germany's military support for Ukraine.
The Federal Prosecutor's Office filed charges against Dieter S., Alexander J., and Alex D. on December 9, 2024, before the...
Researchers have demonstrated a method to bypass Windows 11's BitLocker encryption, enabling the extraction of Full Volume Encryption Keys (FVEKs) from memory.
This vulnerability underscores the risks associated with physical access attacks and highlights potential weaknesses in memory protection mechanisms.
The...
A sophisticated hacker group dubbed "EC2 Grouper" has been exploiting AWS tools and compromised credentials to launch attacks on cloud environments.
This prolific threat actor has been observed in dozens of customer environments over the past couple of years,...
A critical security vulnerability in Angular Expressions, a standalone module for the Angular.JS web framework, has been discovered, potentially allowing attackers to execute arbitrary code and gain full system access.
The vulnerability, identified as CVE-2024-54152, affects versions prior to 1.4.3...
Researchers unveiled a proof-of-concept (PoC) exploit for a critical vulnerability in Windows Lightweight Directory Access Protocol (LDAP), tracked as CVE-2024-49112.
The flaw, disclosed by Microsoft on December 10, 2024, during its Patch Tuesday update, carries a CVSS severity score of...
A massive phishing campaign has compromised at least 35 Google Chrome extensions, collectively used by approximately 2.6 million users, injecting malicious code to steal sensitive information from unsuspecting victims.
Early indicators suggest that the hackers employed deceptive emails, posing as...
Thomas Cook (India) Ltd, a leading travel services provider, has fallen victim to a cyber attack targeting its IT infrastructure, the company announced on Tuesday.
The breach has led to significant disruptions in its operations, prompting the company to take...