Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware

March 5, 2024 at 12:04PM North Korean threat actors have exploited ConnectWise ScreenConnect’s security flaws to launch TODDLERSHARK malware, overlapping with known Kimsuky malware BabyShark and ReconShark. Exploiting exposed setup wizard, threat actors execute VB-based malware, gaining ‘hands on keyboard’ access. Toddlershark exhibits polymorphic behavior and is used for reconnaissance. NIS accuses North Korea of … Read more

LockBit leaks expose nearly 200 affiliates and bespoke data-stealing malware

February 21, 2024 at 09:15AM The National Crime Agency revealed that nearly 200 “affiliates” were registered by the LockBit ransomware group over two years. The NCA took control of LockBit’s site, publicizing data revealing affiliates and exposing the StealBit tool. International efforts brought down the affiliate infrastructure, with the NCA warning against future misuse of … Read more

After Critical Bug Disclosures, TETRA Emergency Comms Code Goes Public

November 15, 2023 at 11:11AM The encryption algorithms used to secure emergency radio communications will be released to the public domain, after vulnerabilities were found in TETRA. The decision to go public is a complete turn from ETSI, which initially denied vulnerabilities. The algorithms will be open to academic research for independent reviews. No date … Read more

Former British Cyberespionage Agency Employee Gets Life in Prison for Stabbing an American Spy

November 1, 2023 at 07:09AM A former British cyberespionage employee, Joshua Bowles, was sentenced to life in prison for the attempted murder of an American intelligence worker. Bowles carried out a pre-meditated and politically motivated attack, targeting the woman solely because of her role with the National Security Agency. The attack was driven by Bowles’ … Read more

Pirate IPTV network in Austria dismantled and $1.74 million seized

October 29, 2023 at 08:00PM Austrian police have arrested 20 people involved in an illegal IPTV network that decrypted copyright-protected broadcasts and distributed them to customers. The investigation started in Germany and uncovered a criminal enterprise comprising 80 Turkish citizens. The network operated through suppliers and resellers, with customers being reached primarily via word of … Read more

iLeakage: New Safari Exploit Impacts Apple iPhones and Macs with A and M-Series CPUs

October 26, 2023 at 02:06PM A group of academics has discovered a new side-channel attack called iLeakage that targets Apple’s A- and M-series CPUs on iOS, iPadOS, and macOS devices. By exploiting a weakness in Safari, sensitive information can be extracted. The attack could be used to retrieve Gmail inbox content and autofilled passwords from … Read more