π¦
Ransomware Landscape May 2025: SafePay, DevMan Emerge as Major Threats π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats " dataimagecaption"Cyble Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats " datamediumfile"httpscyble.comwpcontentuploads202506CybleBlogsRansomwareSafePay300x150.png" datalargefile"httpscyble.comwpcontentuploads202506CybleBlogsRansomwareSafePay1024x512.png" title"Ransomware Landscape May 2025 SafePay, DevMan Emerge as Major Threats 1" SafePay took the top spot among ransomware groups in May 2025, solidifying the groups status as a major threat. Overall, ransomware groups claimed 384 victims in May chart below, the third straight monthly decline, as leadership continues to shift after RansomHub the top group for more than a year went offline at the end of March in what may have been an inf...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
ποΈ Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a critical security flaw in the Roundcube webmail software that has gone unnoticed for a decade and could be exploited to take over susceptible systems and execute arbitrary code. The vulnerability, tracked as CVE202549113, carries a CVSS score of 9.9 out of 10.0. It has been described as a case of postauthenticated remote code execution via.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π΅οΈββοΈ Is Your CISO Navigating Your Flight Path? π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
If your CISO isn't wielding influence with the CEO and helping top leaders clearly see the flight path ahead, your company is dangerously exposed.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Is Your CISO Navigating Your Flight Path?
If your CISO isn't wielding influence with the CEO and helping top leaders clearly see the flight path ahead, your company is dangerously exposed.
π #Infosec2025: Good Cybersecurity Enabled Ukraineβs Surprise Attack on Russia, Says NCSC π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Effective cybersecurity played a key role Ukraine drone attack on Russian strategic bombers, a leading government security expert has claimed.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
ποΈ Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Threat hunters are alerting to a new campaign that employs deceptive websites to trick unsuspecting users into executing malicious PowerShell scripts on their machines and infect them with the NetSupport RAT malware. The DomainTools Investigations DTI team said it identified "malicious multistage downloader Powershell scripts" hosted on lure websites that masquerade as Gitcode and DocuSign. ".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π #Infosec2025: Channel Bridges Security Skills Gap π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Resellers and channel partners can add value, fill gaps in security teams and offer expertise in niche markets.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
#Infosec2025: Channel Bridges Security Skills Gap
Resellers and channel partners can add value, fill gaps in security teams and offer expertise in niche markets
π’ Email spoofing attacks are still a major threat for FTSE 100 companies β despite a simple fix being widely available π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Improper configuration of DMARC and other email authentication protocols opens organizations to major threats.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Email spoofing attacks are still a major threat for FTSE 100 companies β despite a simple fix being widely available
Improper configuration of DMARC and other email authentication protocols opens organizations to major threats
π¦Ώ Apple Appeals DMA, Says EU Has βDeeply Flawed Rulesβ That βStifle Innovationβ π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Apple is appealing EU demands to open iOS to thirdparty devices, arguing interoperability threatens privacy, security, and user experience.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Apple Appeals DMA, Says EU Has βDeeply Flawed Rulesβ That βStifle Innovationβ
Apple is appealing EU demands to open iOS to third-party devices, arguing interoperability threatens privacy, security, and user experience.
π¦Ώ Cyber Attacks Are Up 47% in 2025 β AI is One Key Factor π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Another key factor is that ransomware has turned into a business model, Check Point researchers report.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Cyber Attacks Are Up 47% in 2025 β AI is One Key Factor
Another key factor is that ransomware has turned into a business model, Check Point researchers report.
π’ βI take pleasure in thinking I can rid society of at least some of themβ: A cyber vigilante is dumping information on notorious ransomware criminals β and security experts say police will be keeping close tabs π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
βI take pleasure in thinking I can rid society of at least some of themβ: A cyber vigilante is dumping information on notoriousβ¦
An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs
π΅οΈββοΈ 'Crocodilus' Sharpens Its Teeth on Android Users π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
The datastealing malware initially targeted users in Turkey but has since evolved into a global threat.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
'Crocodilus' Sharpens Its Teeth on Android Users
The data stealing malware initially targeted users in Turkey but has since evolved into a global threat.
β€1
π΅οΈββοΈ Victoria's Secret Delays Earnings Call Due to Cyber Incident π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
But that didn't stop the clothing retailer from issuing preliminary results for the first quarter of 2025.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Victoria's Secret Delays Earnings Call After Incident
Alongside the postponement announcement, the retailer released preliminary results for the first quarter of 2025.
π΅οΈββοΈ Chrome Drops Trust for Chunghwa, Netlock Certificates π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Digital certificates authorized by the authorities will no longer have trust by default in the browser starting in August, over what Google said is a loss of integrity in actions by the respective companies.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Chrome Drops Trust for Chunghwa, Netlock Certificates
Digital certificates authorized by the authorities will no longer have trust by default in the browser starting in August, over what Google said is a loss of integrity in actions by the respective companies.
π΅οΈββοΈ LummaC2 Fractures as Acreed Malware Becomes Top Dog π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
LummaC2 formerly accounted for almost 92 of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
LummaC2 Fractures as Acreed Malware Becomes Top Dog
LummaC2 formerly accounted for almost 92% of Russian Market's credential theft log alerts. Now, the Acreed infostealer has replaced its market share.
π¦Ώ This $35 Training Pack May Help You Land a Cybersecurity Job π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Unlock lifetime access to 11 beginnerfriendly cybersecurity and networking courses taught by real experts.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
This $35 Training Pack May Help You Land a Cybersecurity Job
Unlock lifetime access to 11 beginner-friendly cybersecurity and networking courses taught by real experts
π΅οΈββοΈ Cutting-Edge ClickFix Tactics Snowball, Pushing Phishing Forward π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Several widespread ClickFix campaigns are underway, bent on delivering malware to business targets, and they represent a new level of phishing sophistication that defenders need to be prepared for, researchers warn.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
Cutting-Edge ClickFix Tactics Snowball
Several widespread ClickFix campaigns are underway, bent on delivering malware to business targets, and they represent a new level of phishing sophistication that defenders need to be prepared for, researchers warn.
π΅οΈββοΈ F5 Acquires Agentic AI Security Startup Fletch π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Agentic AI technology will be integrated into the recently launched F5 Application Delivery and Security Platform.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Darkreading
F5 Acquires Agentic AI Security Startup Fletch
Agentic AI technology will be integrated into the recently launched F5 Application Delivery and Security Platform.
π Scattered Spider Uses Tech Vendor Impersonation and Phishing Kits to Target Helpdesks π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The ransomware group combines IT vendor impersonation and phishing frameworks like Evilginx to breach its targets.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π1
π¦Ώ FBI Issues Play Ransomware Security Advisory & Mitigation Steps to Take Now π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
The Play ransomware group has hit about 900 organizations globally so far and uses double extortion after data theft.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
FBI Issues Play Ransomware Security Advisory & Mitigation Steps to Take Now
The Play ransomware group has hit about 900 organizations globally so far and uses βdouble extortionβ after data theft.
π¦
Over 20 Crypto Phishing Applications Found on the Play Store Stealing Mnemonic Phrases π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble Over 20 Crypto Phishing Applications Found on the Play Store Stealing Mnemonic Phrases " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202506CybleCryptophishingPlayStore300x150.jpg" datalargefile"httpscyble.comwpcontentuploads202506CybleCryptophishingPlayStore1024x512.jpg" title"Over 20 Crypto Phishing Applications Found on the Play Store Stealing Mnemonic Phrases 1" Key Takeaways Over 20 malicious applications have been discovered actively targeting crypto wallet users. The apps impersonate popular wallets such as SushiSwap, PancakeSwap, Hyperliquid, and Raydium. They prompt users to enter their 12word mnemonic phrase to access fraudulent wallet interfaces. These apps are distributed through the Play Store under compromised or repurposed developer acco...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
Crypto Phishing Applications On The Play Store
CRIL discovers over 20 malicious apps targeting crypto wallet users with phishing tactics and Play Store distribution under compromised developer accounts.
ποΈ New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers are alerting to a new malware campaign that employs the ClickFix social engineering tactic to trick users into downloading an information stealer malware known as Atomic macOS Stealer AMOS on Apple macOS systems. The campaign, according to CloudSEK, has been found to leverage typosquat domains mimicking U.S.based telecom provider Spectrum. "macOS users are served a.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity