Aggregator
CVE-2025-32738 | I-O DATA DEVICE HDL-TC1 up to 1.21 Setting missing authentication (EUVD-2025-15147)
CVE-2025-32002 | I-O DATA DEVICE HDL-TC1 up to 1.21 os command injection (EUVD-2025-15148)
Russia-linked hackers target webmail servers in Ukraine-related espionage operation
ESET researchers have uncovered RoundPress, a Russia-aligned espionage operation targeting webmail servers via XSS vulnerabilities. Behind it is most likely the Russia-aligned Sednit (also known as Fancy Bear or APT28) cyberespionage group, holding the ultimate goal of stealing confidential data from specific email accounts. Operation RoundPress compromise chain (Source: ESET) Targets Most of the targets are related to the current war in Ukraine. They are either Ukrainian governmental entities or defense companies in Bulgaria and … More →
The post Russia-linked hackers target webmail servers in Ukraine-related espionage operation appeared first on Help Net Security.
Meta Faces More European Legal Hurdles Over AI Data Training
Social media giant Meta is likely to face more legal hurdles over its plans to use the personal data of European Facebook and Instagram users to train artificial intelligence models. Meta paused efforts to train AI with European data in June 2024.
North Korea’s Hidden IT Workforce Exposed in New Report
A new report details how North Korea’s cybercrime network is infiltrating global tech firms with fake IT workers who exploit trusted access to steal millions in cryptocurrency, launder funds through international fronts and channel proceeds into weapons development and espionage missions.
RFK Jr to Lean on AI to Bolster Cyber, Health IT at Agencies
The U.S. Department of Health and Human Services aims to bolster cybersecurity and health IT through the aid of artificial intelligence that will be used at federal health agencies, said Robert F. Kennedy Jr., secretary of HHS during House and Senate committee budget hearings on Wednesday.
CISA Cancels $2.4 Billion Cybersecurity Procurement
A multi-billion dollar vision by the Cybersecurity and Infrastructure Security Agency for its government-wide network intrusion detection and prevention system went kaput on Friday, court documents show. It withdrew an offer to contractor Leidos to support the National Cybersecurity Protection System.
Fancy Bear campaign sought emails of high-level Ukrainians and their military suppliers
Russian hackers aren’t just targeting Ukraine — they also appear to be going after their defense contractors in other countries, new ESET research surmises.
The post Fancy Bear campaign sought emails of high-level Ukrainians and their military suppliers appeared first on CyberScoop.