Latest Briefings
US Sanctions VPN Provider First VPN for Enabling Ransomware Attacks
Treasury sanctioned First VPN Service and its Ukrainian administrator for supplying anonymizing infrastructure to ransomware gangs, alongside a Belarusian seller of malware-cloaking…
CrashStealer Malware Impersonates Apple Crash Reporter to Raid macOS Keychains and Crypto Wallets
A notarized, Apple-signed installer slips past Gatekeeper to drop CrashStealer, a new macOS infostealer that fakes a password prompt to unlock the…
Critical Joomla Extension Flaws Under Active Exploitation, CISA Adds to KEV
Unauthenticated file upload vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions, both scoring a maximum CVSS of 10, are being exploited…
US and Allies Warn Russian FSB Hackers Are Hunting Weak Router Configs
A joint advisory from CISA, the NSA, FBI, and agencies in eight allied nations warns that Russia's FSB Center 16 group is…
Attackers Exploit Critical Auth Bypass in Gitea’s Official Docker Image
A misconfigured default in Gitea's Docker image lets unauthenticated attackers impersonate any user, including admins, and exploitation began before public disclosure.
Anthropic Extends Free Claude Fable 5 Access for Paid Users to July 19
Anthropic has pushed back the deadline for included Fable 5 usage on paid Claude plans for a second time, giving subscribers another…
Six New U-Boot Bugs Could Crash Devices or Enable Boot-Time Code Execution
Firmware security firm Binarly has disclosed six flaws in the widely used U-Boot bootloader, four that can crash affected devices and two…
Supreme Court Location Ruling Could Reshape License Plate Camera Surveillance
A landmark Fourth Amendment decision on cell phone geofence warrants is fueling legal arguments that automated license plate reader networks like Flock…
Injective Labs GitHub Breach Spawns Malicious npm Package to Steal Crypto Wallets
Attackers compromised the Injective Labs SDK repository on GitHub and published a tampered npm package designed to exfiltrate wallet private keys and…
RedHook Android Malware Abuses Wireless ADB to Gain Shell Access
A new RedHook variant tricks victims into enabling Wireless Debugging, then uses a Shizuku-based framework to run shell-level commands and expand its…
Ryuk Ransomware Operator Pleads Guilty as BlackCat Insider Gets Nearly 6 Years
U.S. prosecutors notched two wins against ransomware ecosystems this week: an Armenian national admitted deploying Ryuk against victims including a Michigan firm…
Armenian Man Pleads Guilty to Deploying Ryuk Ransomware in US Attacks
Karen Serobovich Vardanyan admitted to helping breach US companies and deploy Ryuk ransomware in 2019 and 2020, part of a scheme that…