May 2025

Class action settlement following ransomware attack will cost Fred Hutchinson Cancer Center about $52 million

Elise Takahama reports a settlement in a lawsuit stemming from a ransomware attack on Fred Hutchinson Cancer Center in Seattle by the Hunter...

Sp123 31 May, 2025

Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025

From Hogan Lovells: The rapid development of data protection laws across the Asia-Pacific region indicates significant movement toward certa...

Sp123 31 May, 2025

Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump

Jessica Lyons reports:  A mystery whistleblower calling himself GangExposed has exposed key figures behind the Conti and Trickbot ransomware...

Sp123 31 May, 2025

Treasury Sanctions FUNNULL for Enabling Global Cybercrime

Back in October 2024, our analysts uncovered and exposed a sprawling network of domains routed through a China-based CDN service called FUNN...

Sp123 30 May, 2025

50,000+ Azure AD Users Exposed via Unsecured API: BeVigil Uncovers Critical Flaw

An unsecured API endpoint buried inside a JavaScript file gave attackers the keys to the kingdom—direct access to sensitive Microsoft Graph ...

Sp123 30 May, 2025

Here’s how to remove personal info from people search sites

It is not a secret that often personal information ends up on people search sites . Such websites collect personal data from publicly avai...

Sp123 30 May, 2025

Cybercriminals camouflaging threats as AI tool installers

Cisco Talos has discovered new threats, including the ransomware CyberLock, Lucky_Gh0$t, and a newly-discovered malware we call “Numero,” a...

Sp123 29 May, 2025

New Research Reveals Key TCP SYN Patterns for Detecting Malicious Activity

A groundbreaking study by NETSCOUT, utilizing data from their honeypot systems designed to capture unsolicited internet traffic, has shed li...

Sp123 29 May, 2025

Lights Out! A Malware Perspective on the Iberian Power Failure

When Spain and Portugal went dark from power outages, malware didn’t just pause. It told a story. And Bitsight caught it, live. Introducti...

Sp123 29 May, 2025

Quickpost: Airplanes & Radiation

When you’re flying high in a commercial airliner, you’re exposed to more radiation, because cosmic rays travel through less atmosphere befor...

Sp123 29 May, 2025

SOCRadar Named One of the 100 Most Loved Workplaces by Newsweek

SOCRadar Named One of the 100 Most Loved Workplaces by Newsweek Introduction to Malware Binary Triage (IMBT) Course Looking to level up y...

Sp123 28 May, 2025

CrowdStrike Named a Customers’ Choice in 2025 Gartner® Voice of the Customer for Endpoint Protection Platforms Report

Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any fla...

Sp123 28 May, 2025

Russian ‘Laundry Bear’ Hackers Breach Dutch Police Using Infostealers

A new Russian hacking group, “Laundry Bear” (aka “Void Blizzard”), breached the Dutch police in October 2024 , stealing contact details of t...

Sp123 28 May, 2025

Arm Mali GPU Vulnerability Enables Bypass of MTE and Arbitrary Kernel Code Execution

A critical vulnerability, identified as CVE-2025-0072, has been discovered in the Arm Mali GPU driver, posing a significant threat to device...

Sp123 27 May, 2025

My impression of Botconf 2025

This year was Botconf’s 12th edition, located in Angers, where I gave a four hour workshop diving into Ghidra. Some of talks were rated as T...

Sp123 27 May, 2025

Google Gemini: Everything You Need to Know About Google’s Powerful AI

Google Gemini is transforming the way we interact with technology, offering a smarter, more capable AI assistant that goes far beyond what...

Sp123 26 May, 2025

Sandfly Security Not Vulnerable to the Log4j Exploit

A recent disclosure of a severe bug in the log4j library (CVE-2021-44228) has made many web applications vulnerable to compromise. Sandfly S...

Sp123 26 May, 2025

Sandfly 3.0 Beta - Live Now

Sandfly 3.0 Beta is now available. Over the past few months we’ve made significant upgrades to Sandfly based on user feedback and our own pr...

Sp123 26 May, 2025

북한 코니(Konni)KB국민은행 외국환거래 소명자료 제출서 위장한 악성코드-소명자료 제출 안내서(2025.5.13)

오늘은 김일성, 김정일이 평화의 사도가 아니라 한반도 평화의 최대 위협이며 핵폭탄을 만들려고 하는지 가상화폐, 달러, 기타 외환 시장에서 외화를 획득해서 아무튼 대한민국 안보를 위협하는 수단의 재원을 확보하기 위해서… Introduction to ...

Sp123 25 May, 2025

Dutch Government: More forms of espionage to be a criminal offence from 15 May onwards

From the Government of the Netherlands: More forms of espionage, such as digital and diaspora espionage, are to be a criminal offence from 1...

Sp123 25 May, 2025

B.C. health authority faces class-action lawsuit over 2009 data breach

Brendan Shykora reports: B.C.’s Interior Health Authority (IH) has been served a class-action lawsuit over a data breach in 2009 that allege...

Sp123 24 May, 2025

PA: York County alerts residents of potential data breach

Sean Adams reports: York County officials have released a warning to residents that a “data privacy event” might have put their information ...

Sp123 24 May, 2025

Data Breach Lawsuits Against Chord Specialty Dental Partners Consolidated

Kathryn Rattigan of Robinson + Cole writes: Pennsylvania-based Chord Specialty Dental Partners is under fire after a September 2024 data bre...

Sp123 24 May, 2025

Private Industry Notification: Silent Ransom Group Targeting Law Firms

The following information is being provided by the FBI, with no guarantees or warranties, for potential use at the sole discretion of recipi...

Sp123 24 May, 2025

Three vulnerabilities in MegaBIP software

CERT Polska has received a report about 3 vulnerabilities (from CVE-2025-3893 to CVE-2025-3895) found in MegaBIP software. Introduction to...

Sp123 23 May, 2025

ViciousTrap Hackers Breaches 5,500+ Edge Devices from 50+ Brands, Turns Them into Honeypots

A sophisticated cyber threat actor, dubbed ViciousTrap by Sekoia.io’s Threat Detection & Research (TDR) team, has compromised over 5,500...

Sp123 23 May, 2025

CrowdStrike Collaborates with U.S. Department of Justice on DanaBot Takedown

Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any fla...

Sp123 23 May, 2025

Case of Larva-25004 Group (Related to Kimsuky) Exploiting Additional Certificate – Malware Signed with Nexaweb Certificate

AhnLab SEcurity intelligence Center (ASEC) has discovered malware signed with the certification of Nexaweb Inc. by investigating a file with...

Sp123 23 May, 2025

Scammers are using AI to impersonate senior officials, warns FBI

The FBI has issued a warning about an ongoing malicious text and voice messaging campaign that impersonates senior US officials. Introduct...

Sp123 22 May, 2025

Vulnerability in Poedit software

TCC Bypass vulnerability (CVE-2025-4280) has been found in MacOS version of Poedit software. Introduction to Malware Binary Triage (IMBT) ...

Sp123 22 May, 2025

80 arrests and more than 37 700 cultural goods seized in major art trafficking bust

Operational highlightsThe Italian Carabinieri Command for the Protection of Cultural Heritage (TPC) in coordination with the Italian Customs...

Sp123 22 May, 2025

Navigating the Maze: A Comprehensive Buyer’s Guide to MDR

Access Sygnia’s new Buyer’s Guide created to help you choose the right solution with critical factors to consider during the evaluation proc...

Sp123 21 May, 2025

Roblox chat ends in 10-year-old’s abduction

A girl from a small Californian city was allegedly kidnapped by a 27-year-old man. She met him on Roblox. The incident has once again rais...

Sp123 21 May, 2025