π Inside DragonForce, the Group Tied to M&S, Co-op and Harrods Hacks π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Individuals allegedly linked to the DragonForce cybercriminal syndicate have claimed the attack on the three UK retailers.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Inside DragonForce, the Group Tied to M&S, Co-op and Harrods Hacks
Individuals allegedly linked to the DragonForce cybercriminal syndicate have claimed the attack on the three UK retailers
π Darcula Phishing as a Service Operation Snares 800,000+ Victims π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Prolific PhaaS operation Darcula uses Magic Cat software to steal over 800,000 cards in a sevenmonth period.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Darcula Phishing as a Service Operation Snares 800,000+ Victims
Prolific PhaaS operation Darcula uses Magic Cat software to steal over 800,000 cards in a seven-month period
π UKβs NCSC Offers Security Tips as Co-op Confirms Data Loss π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The National Cyber Security Centre has published advice for retailers while the Coop admits customer data was stolen.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
UKβs NCSC Offers Security Tips as Co-op Confirms Data Loss
The National Cyber Security Centre has published advice for retailers while the Co-op admits customer data was stolen
π What Are Managed Cybersecurity Services? π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Managed cybersecurity services are delivered by a thirdparty cybersecurity service provider who monitors, detects, and responds to cyber threats across an organizations systems, networks, and applications. Managed security services MSS include a full spectrum of cybersecurity as a service offerings, from realtime system monitoring and threat detection to incident response, vulnerability management, and compliance support. The post What Are Managed Cybersecurity Services? appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
What Are Managed Cybersecurity Services?
Managed cybersecurity services are provided by a third-party security expert who monitors, detects, and responds to cyber threats.
π1
π΅οΈββοΈ Addressing the Top Cyber-Risks in Higher Education π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
As attacks accelerate, security leaders must act to gain visibility across their entire institution's network and systems and continuously educate their users on best practices.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Addressing the Top Cyber-Risks in Higher Education
As attacks accelerate, security leaders must act to gain visibility across their entire institution's network and systems and continuously educate their users on best practices.
π¦
Ransomware Attacks April 2025: Qilin Emerges from Chaos π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Ransomware Attacks April 2025 Qilin Emerges from Chaos " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202505RansomwareAttacksApril2025QilinEmergesfromChaos300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202505RansomwareAttacksApril2025QilinEmergesfromChaos.jpg" title"Ransomware Attacks April 2025 Qilin Emerges from Chaos 1" Global ransomware attacks in April 2025 declined to 450 from 564 in March the lowest level since November 2024 as major changes among the leading RansomwareasaService RaaS groups caused many affiliates to align with new groups. Still, the longterm trend for ransomware attacks remains decidedly upward chart below so Aprils decline could be reversed as soon as new RaaS leaders are established. Rasomware attacks by month 20212025 Fo...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
π¦Ώ App Used by Trump Adviser Suspends Services After Hack Taking β15-20 Minutesβ π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TeleMessage, a messaging app used by Trump adviser Mike Waltz, has suspended services after a hacker accessed sensitive government and corporate data.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
App Used by Trump Adviser Suspends Services After Hack Taking β15-20 Minutesβ
TeleMessage, a messaging app used by Trump adviser Mike Waltz, has suspended services after a hacker accessed sensitive government and corporate data.
π΅οΈββοΈ CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
The vulnerabilities affect SonicWall's SMA devices for secure remote access, which have been heavily targeted by threat actors in the past.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
2 SonicWall Vulnerabilities Under Active Exploit
The vulnerabilities affect SonicWall's SMA devices for secure remote access, which have been heavily targeted by threat actors in the past.
π Smishing Triad Upgrades Tools and Tactics for Global Attacks π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Global smishing campaigns linked to Chinese cybercriminals escalate with Smishing Triads new tools and techniques.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Smishing Triad Upgrades Tools and Tactics for Global Attacks
Global smishing campaigns linked to Chinese cybercriminals escalate with Smishing Triadβs new tools and techniques
ποΈ Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Threat actors have been observed actively exploiting security flaws in GeoVision endoflife EoL Internet of Things IoT devices to corral them into a Mirai botnet for conducting distributed denialofservice DDoS attacks. The activity, first observed by the Akamai Security Intelligence and Response Team SIRT in early April 2025, involves the exploitation of two operating system command.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Texas School District Notifies Over 47,000 People of Major Data Breach π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The Alvin Independent School District in Texas has notified over 47,000 individuals affected by a data breach exposing sensitive personal information.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Texas School District Notifies Over 47,000 People of Major Data Breach
The Alvin Independent School District in Texas has notified over 47,000 individuals affected by a data breach exposing sensitive personal information
π’ Russian hackers tried to lure diplomats with wine tasting β sound familiar? Itβs an update to a previous campaign by the notorious Midnight Blizzard group π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The Midnight Blizzard threat group has been targeting European diplomats with malicious emails offering an invite to wine tasting events, according to Check Point.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Russian hackers tried to lure diplomats with wine tasting β sound familiar? Itβs an update to a previous campaign by the notoriousβ¦
The latest Midnight Blizzard campaign sought to lure politicians with a swanky night out
π΅οΈββοΈ Researcher Says Patched Commvault Bug Still Exploitable π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
CISA added CVE202534028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Researcher Says Fixed Commvault Bug Still Exploitable
CISA added CVE-2025-34028 to its Known Exploited Vulnerabilities catalog, citing active attacks in the wild.
π΅οΈββοΈ 'Easily Exploitable' Langflow Vulnerability Requires Immediate Patching π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
'Easily Exploitable' Langflow Flaw Requires Patching
The vulnerability, which has a CVSS score of 9.8, is under attack and allows threat actors to remotely execute arbitrary commands on servers running the agentic AI builder.
π’ Almost a third of workers are covertly using AI at work β hereβs why thatβs a terrible idea π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Employers need to get wise to the use of unauthorized AI tools and tighten up policies.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Almost a third of workers are covertly using AI at work β hereβs why thatβs a terrible idea
Employers need to get wise to the use of unauthorized AI tools and tighten up policies
π€1
π’ Cyber attacks are costing UK firms billions every year β ransom payments, staff overtime, and lost business are crippling victims π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
New research from ESET shows the cost of cyber attacks against UK businesses is surging, with many victims struggling to remediate breaches.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Cyber attacks are costing UK firms billions every year β ransom payments, staff overtime, and lost business are crippling victims
With more than half of firms hit by cyber attacks every year, one-in-eight victims enters administration
π’ 96% of businesses have low cyber-readiness, claims Cisco π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The 2025 Cisco Cybersecurity Readiness Index shows a concerning number of businesses globally are unprepared for rising AIrelated threats.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
96% of businesses have low cyber-readiness, claims Cisco
A tiny increase in the number of βmatureβ organizations shows growing problems with AI
π΅οΈββοΈ Infrastructure as Code: An IaC Guide to Cloud Security π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
IaC is powerful. It brings speed, scale, and structure to cloud infrastructure. But none of that matters if your security can't keep up.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Infrastructure as Code: An IaC Guide to Cloud Security
IaC is powerful. It brings speed, scale, and structure to cloud infrastructure. But none of that matters if your security can't keep up.
ποΈ Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Europol has announced the takedown of distributed denial of service DDoSforhire services that were used to launch thousands of cyberattacks across the world. In connection with the operation, Polish authorities have arrested four individuals and the United States has seized nine domains that are associated with the nowdefunct platforms. "The suspects are believed to be behind six separate.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π1
ποΈ OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A second security flaw impacting the OttoKit formerly SureTriggers WordPress plugin has come under active exploitation in the wild. The vulnerability, tracked as CVE202527007 CVSS score 9.8, is a privilege escalation bug impacting all versions of the plugin prior to and including version 1.0.82. "This is due to the createwpconnection function missing a capability check and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed multiple security flaw in the onpremise version of SysAid IT support software that could be exploited to achieve preauthenticated remote code execution with elevated privileges. The vulnerabilities, tracked as CVE20252775, CVE20252776, and CVE20252777, have all been described as XML External Entity XXE injections, which occur when an attacker is.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity