Aggregator
Ryuk ransomware operator extradited to US, faces five years in federal prison
Karen Vardanyan and his co-conspirators allegedly deployed ransomware on hundreds of machines in 2019 and 2020, extorting more than $15 million from victims at the time.
The post Ryuk ransomware operator extradited to US, faces five years in federal prison appeared first on CyberScoop.
Threat Actors Weaponize WordPress Websites to Redirect Visitors to Malicious Websites
Cybersecurity researchers have uncovered a sophisticated malware campaign targeting WordPress websites through an ingenious ZIP archive-based attack mechanism. The malware, first reported in July 2025, represents a significant evolution in web-based threats, utilizing advanced obfuscation techniques and stealthy persistence methods to redirect unsuspecting visitors to malicious domains while simultaneously conducting search engine optimization poisoning operations. […]
The post Threat Actors Weaponize WordPress Websites to Redirect Visitors to Malicious Websites appeared first on Cyber Security News.
U.S. Army soldier pleads guilty to extorting 10 tech, telecom firms
Welcoming Aura to Have I Been Pwned's Partner Program
One of the greatest fears we all have in the wake of a data breach is having our identity stolen. Nefarious parties gather our personal information exposed in the breach, approach financial institutions and then impersonate us to do stuff like this:
So I recently somewhat had my identity stolen,House hearing will use Stuxnet to search for novel ways to confront OT cyberthreats
The House Homeland Committee will revisit the malware to use the knowledge from the spy effort to explore the domestic threats facing the U.S. in 2025.
The post House hearing will use Stuxnet to search for novel ways to confront OT cyberthreats appeared first on CyberScoop.
Elite 'Matanbuchus 3.0' Loader Spruces Up Ransomware Infections
CVE-2025-6982 | TP-Link Archer C50 V3/Archer C50 V4/Archer C50 V5 hard-coded credentials
CVE-2025-6983 | TP-Link Archer C1200 up to 1.1.5 Web Management Page ui layer (EUVD-2025-21737)
CVE-2025-53908 | rommapp romm up to 3.10.2/4.0.0-beta2 /api/raw path traversal (GHSA-fx9g-xw4j-jwc3)
CVE-2025-7729 | Scada-LTS up to 2.7.8.1 usersProfiles.shtm Username cross site scripting
CVE-2025-7728 | Scada-LTS up to 2.7.8.1 users.shtm Username cross site scripting
Submit #607950: SCADA-LTS 2.7.8.1 Cross Site Scripting [Accepted]
Submit #607949: SCADA-LTS 2.7.8.1 Cross Site Scripting [Accepted]
Chinese ‘Salt Typhoon’ Hackers Hijacked US National Guard Network for Nearly a Year
Chinese state-sponsored hackers known as Salt Typhoon successfully infiltrated and maintained persistent access to a U.S. state’s Army National Guard network for nearly ten months, from March 2024 through December 2024, according to a Department of Homeland Security memo obtained by NBC News. The sophisticated cyberespionage campaign represents a significant escalation in Beijing’s ongoing cyber […]
The post Chinese ‘Salt Typhoon’ Hackers Hijacked US National Guard Network for Nearly a Year appeared first on Cyber Security News.
CVE-2025-4941
Qilin
You must login to view this content
Cracked Apps Delivering Infostealers Identified as Leading Attack Vector in June 2025
The AhnLab Security Intelligence Center (ASEC) published a thorough analysis in June 2025 that identified infostealer malware masquerading as keygens and cracked software as a primary attack vector. This malware uses advanced search engine optimization (SEO) poisoning to elevate malicious distribution sites in search results. ASEC’s automated malware collection systems, including crack monitoring, email honeypots, […]
The post Cracked Apps Delivering Infostealers Identified as Leading Attack Vector in June 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.