The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek.
The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs.
The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek.
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWeek.
The Android malware allows its operators to take control of infected devices and harvest sensitive information.
The post Rokarolla Banking Trojan Targets 200 Applications appeared first on SecurityWeek.
The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.
The post Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack appeared first on SecurityWeek.
Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR.
The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek.
Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.
The post OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month appeared first on SecurityWeek.
The most recent variants of the self-propagating attacks are named Miasma and Hades.
The post Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks appeared first on SecurityWeek.
Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities.
The post Chinese Cybercrime Group in Spotlight for Record Campaign Pace appeared first on SecurityWeek.
The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months.
The post Hackers Target Global Stock Exchange in Espionage Operation appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attacks.
The post In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks appeared first on SecurityWeek.