Daily Cyber News Feed
banner
bluecyber.bsky.social
Daily Cyber News Feed
@bluecyber.bsky.social
Daily Cyber News Feed on Blue
“The affected information appears to be mostly related to individuals involved with County law enforcement, court related matters, and/or other County business,” the county said.

therecord.media/union-county...
Hackers steal sensitive data from Pennsylvania county during ransomware attack
The government of Union County in central Pennsylvania said a recent ransomware attack exposed information related to law enforcement and other government business.
therecord.media
March 25, 2025 at 2:06 AM
An Asian telecommunications company was allegedly breached by Chinese government hackers who spent four years inside its systems.

The company said the hackers compromised home routers made by Zyxel to gain entry into the “major” telco’s environment.

therecord.media/chinese-hack...
Chinese hackers spent four years inside Asian telco’s networks
The hackers compromised home routers made by Zyxel to gain entry into a “major” telecommunications company's environment.
therecord.media
March 25, 2025 at 12:23 AM
The FBI is warning that fake online document converters are being used to steal peoples’ information and, in worst-case scenarios, to deploy ransomware on victims' devices.

www.bleepingcomputer.com/news/securit...
FBI warnings are true—fake file converters do push malware
The FBI is warning that fake online document converters are being used to steal people's information and, in worst-case scenarios, lead to ransomware attacks.
www.bleepingcomputer.com
March 23, 2025 at 2:49 PM
Cybercriminals are abusing Microsoft's Trusted Signing platform to code-sign malware executables with short-lived three-day certificates

www.bleepingcomputer.com/news/securit...
Microsoft Trust Signing service abused to code-sign malware
Cybercriminals are abusing Microsoft's Trusted Signing platform to code-sign malware executables with short-lived three-day certificates.
www.bleepingcomputer.com
March 22, 2025 at 4:34 PM
Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com.

The move prevents unencrypted API requests from being sent, even accidentally.

www.bleepingcomputer.com/news/securit...
Cloudflare now blocks all unencrypted traffic to its API endpoints
Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com.
www.bleepingcomputer.com
March 22, 2025 at 4:23 PM
Two now-patched security flaws impacting Cisco Smart Licensing Utility are seeing active exploitation attempts

CVE-2024-20439 (9.8)

CVE-2024-20440 (9.8)

thehackernews.com/2025/03/ongo...
Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility
Active exploitation of Cisco CVE-2024-20439 & 20440 in Smart Licensing forces urgent patching of vulnerable versions.
thehackernews.com
March 22, 2025 at 1:38 AM
The China-linked APT Aquatic Panda has been linked to a "global espionage campaign" targeting governments, catholic charities, NGOs and think tanks across Taiwan, Hungary, Turkey, Thailand, France, and the United States. The activity took place Jan-Oct 2022.

thehackernews.com/2025/03/chin...
China-Linked APT Aquatic Panda: 10-Month Campaign, 7 Global Targets, 5 Malware Families
China-linked APT Aquatic Panda targeted 7 organizations in a 10-month espionage campaign using five malware families.
thehackernews.com
March 22, 2025 at 1:09 AM
“We’re fighting a war right now one-handed. My job, and the role that I’m in is [to] give you both your hands, because you need them. Policies are in place, and yes, we need to modify some. We need more offensive capability”

defensescoop.com/2025/03/20/k...
Pentagon CIO calls for more offensive cyber capability
Katie Arrington said her role is to help alleviate policies that are hindering DOD personnel from countering adversaries.
defensescoop.com
March 22, 2025 at 1:01 AM
Reposted by Daily Cyber News Feed
CISA has warned U.S. federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO's Backup & Replication software.
CISA tags NAKIVO backup flaw as actively exploited in attacks
CISA has warned U.S. federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO's Backup & Replication software.
www.bleepingcomputer.com
March 20, 2025 at 9:13 PM
Reposted by Daily Cyber News Feed
Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations.
www.bleepingcomputer.com/news/securit...
Veeam RCE bug lets domain users hack backup servers, patch now
Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations.
www.bleepingcomputer.com
March 20, 2025 at 11:31 PM
Reposted by Daily Cyber News Feed
NEW: North Korea is reportedly launching a new cybersecurity research unit called Research Center 227, which will be housed within the intelligence agency Reconnaissance General Bureau (RGB), and will focus on AI-based hacking and stealing digital assets.

techcrunch.com/2025/03/20/n...
North Korea launches new unit with a focus on AI hacking, per report | TechCrunch
North Korea is reportedly launching a new cybersecurity unit called Research Center 227 within its intelligence agency Reconnaissance General Bureau (RGB).
techcrunch.com
March 20, 2025 at 8:09 PM
Reposted by Daily Cyber News Feed
Volt Typhoon spent more than 300 days inside the systems of the water and electricity utility for Littleton, Massachusetts, Dragos said today

therecord.media/volt-typhoon...
Volt Typhoon hackers were in Massachusetts utility’s systems for 10 months
The Littleton Electric Light & Water Department was one of a range of critical infrastructure organizations targeted by the Chinese nation-state hackers.
therecord.media
March 12, 2025 at 7:44 PM
Hackers with apparent ties to several China-based groups like Volt Typhoon are targeting critical infrastructure in Taiwan as part of an ongoing campaign.

therecord.media/taiwan-criti...
Taiwan critical infrastructure targeted by hackers with possible ties to Volt Typhoon
Researchers at Cisco Talos identified a hacking operation against Taiwan that appears to overlap with Chinese state-backed campaigns known as Volt Typhoon and Flax Typhoon.
therecord.media
March 21, 2025 at 1:43 AM
Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances unpatched against a vulnerability exposing a built-in backdoor admin account, CVE-2024-20439

www.bleepingcomputer.com/news/securit...
Critical Cisco Smart Licensing Utility flaws now exploited in attacks
Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances unpatched against a vulnerability exposing a built-in backdoor admin account.
www.bleepingcomputer.com
March 21, 2025 at 1:35 AM
NAKIVO's Backup & Replication software, CVE-2024-48248 (8.6), which can be exploited by unauthenticated attackers to read arbitrary files on vulnerable devices, added to CISA KEV.

www.bleepingcomputer.com/news/securit...
CISA tags NAKIVO backup flaw as actively exploited in attacks
CISA has warned U.S. federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO's Backup & Replication software.
www.bleepingcomputer.com
March 21, 2025 at 1:26 AM
As part of GSA’s new role, the administrator will be able to “defer or decline” being the executive agent of IT governmentwide contracts “when necessary to ensure continuity of service or as otherwise appropriate.”

fedscoop.com/trump-execut...
Trump executive order consolidates federal IT contracting under GSA
GSA will be given authority to "defer or decline" being the executive agent of IT governmentwide contracts "when necessary to ensure continuity of service or as otherwise appropriate."
fedscoop.com
March 21, 2025 at 1:15 AM
BeyondTrust completed an investigation into a recent cybersecurity incident that targeted some of the company's Remote Support SaaS instances by making use of a compromised API key.

The company said the breach involved 17 Remote Support SaaS customers.

thehackernews.com/2025/02/beyo...
BeyondTrust Zero-Day Breach Exposed 17 SaaS Customers via Compromised API Key
BeyondTrust breach impacted 17 SaaS customers via compromised API key linked to Silk Typhoon; U.S. Treasury affected.
thehackernews.com
February 1, 2025 at 6:10 PM
Reposted by Daily Cyber News Feed
Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity and to conduct research on potential infrastructure for attacks or for reconnaissance on targets.
Google says hackers abuse Gemini AI to empower their attacks
Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity and to conduct research on potential infrastructure for attacks or for reconnaissance on targets.
www.bleepingcomputer.com
February 1, 2025 at 5:15 PM
Meta said it disrupted a campaign that involved the use of spyware to target journalists and civil society members.

The campaign, which targeted around 90 members, involved the use of spyware from an Israeli company known as Paragon Solutions.

thehackernews.com/2025/02/meta...
Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists
Meta-owned WhatsApp disrupted a zero-click spyware campaign by Paragon Solutions, targeting 90 journalists and activists.
thehackernews.com
February 1, 2025 at 5:49 PM
Reposted by Daily Cyber News Feed
Reposted by Daily Cyber News Feed
Dragonforce Ransomware Targets SCP Building Products: A Growing Threat in Cybersecurity

2025-01-31 : On January 31, 2025, the Dark Web monitoring team at ThreatMon revealed a troubling new development in the world of ransomware attacks. The notorious hacker group, Dragonforce, has claimed a new…
Dragonforce Ransomware Targets SCP Building Products: A Growing Threat in Cybersecurity
2025-01-31 : On January 31, 2025, the Dark Web monitoring team at ThreatMon revealed a troubling new development in the world of ransomware attacks. The notorious hacker group, Dragonforce, has claimed a new victim: SCP Building Products. This breach is yet another indication of the escalating sophistication and frequency of cybercriminal activity targeting businesses. As ransomware attacks become increasingly prevalent, it is essential for organizations to stay vigilant and prepare for the possibility of a data breach.
undercodenews.com
January 31, 2025 at 7:58 PM
CISA) and Food and Drug Administration (FDA) released warnings on Thursday about an embedded function they found in the firmware of the Contec CMS8000 — hardware used to display information like vital signs, temperature, heartbeat and blood pressure.

therecord.media/contec-cms80...
FDA, CISA warn of backdoor in popular patient monitor used by US hospitals
The Contec CMS8000, a patient monitor made by a company based in China, has vulnerabilities in its firmware that directly expose it to unauthorized access.
therecord.media
January 31, 2025 at 8:25 PM
Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information.

thehackernews.com/2025/01/broa...
Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
Broadcom patches five VMware Aria Operations flaws, including CVE-2025-22218 (CVSS 8.5), preventing credential leaks and admin privilege abuse in vers
thehackernews.com
January 31, 2025 at 3:25 PM
Police in Norway have seized a ship suspected of sabotaging a communications cable running between Sweden and Latvia. The ship is the second of three that Latvian authorities consider suspects in the incident, and the third ship to be detained in recent weeks.

therecord.media/norway-seize...
Norway seizes ship suspected of sabotage, says crew are Russian nationals
The Silver Dania is the third ship detained in recent weeks over concerns of intentional damage to subsea infrastructure in the Baltic Sea.
therecord.media
January 31, 2025 at 3:24 PM