Category: Exploits
Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases
The fintech parent of Rent-A-Center and Acima told the SEC that attackers used stolen customer data to obtain goods through fraudulent lease-to-own…
Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks
Microsoft says attackers ramped up ACR Stealer campaigns between late April and mid-June, using ClickFix social engineering, WebDAV shares, and MSHTA to…
Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat
Abbott Laboratories is probing unauthorized access to legacy Exact Sciences systems claimed by ShinyHunters, plus a second alleged breach of its LabCentral…
North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images
The Contagious Interview campaign is using steganography in SVG files to sneak a four-stage payload past victims lured by fake job postings…
Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
The Inc ransomware group is exploiting two previously unknown vulnerabilities in SonicWall's Secure Mobile Access appliances, chaining the flaws to achieve root-level…
Researcher Drops Second Windows Zero-Day PoC in a Month
A security researcher who previously published a Windows Defender exploit has now released a proof-of-concept for a User Profile Service privilege escalation…
US Unseals Indictment, Offers $10M Bounty Over Russian Bulletproof Hosting Ring
Federal prosecutors have unsealed charges against three Russian nationals accused of running Media Land and ML Cloud, bulletproof hosting services that allegedly…
US Treasury Sanctions VPN Provider and Cryptor Seller Tied to Ransomware Gangs
OFAC designated First VPN Service, its administrator, and a Belarusian crypter seller for supplying anonymity and detection-evasion tools that fueled ransomware attacks…
Malicious Jscrambler npm Package Backdoored With Infostealer for Two Hours
A threat actor published a rogue version of the Jscrambler npm package using stolen publishing credentials, planting an infostealer that harvested developer…
Australia Warns of Global Webshell Campaign Hitting Vulnerable CMS Platforms
The Australian Cyber Security Centre says a large-scale exploitation campaign is deploying webshells across WordPress, Craft CMS, Joomla and other platforms worldwide,…
Ex-Ransomware Negotiator Sentenced to 70 Months for Secretly Aiding BlackCat
A former DigitalMint negotiator who fed victim insurance limits and negotiation strategy to BlackCat operators has been sentenced to nearly six years…
Mount Royal University Hit by Data Theft and Wiping Attack
Calgary's Mount Royal University confirmed hackers stole files from its H drive and wiped a separate departmental drive in a June 17…