Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The DeadLock ransomware operation employs a decentralized infrastructure built on blockchain-backed services. This approach protects its communication with victims and data-leak activities from takedown efforts.
AWS announced a new independent assessment report for Landing Zone Accelerator that evaluates its coverage of C5:2020 requirements. The report is available on AWS Artifact and helps customers accelerate their compliance journey.
Microsoft's August Patch Tuesday continues the trend of a deluge of updates with a massive volume of CVEs. Security experts advise that prioritization should be the main focus, not the sheer number of updates.
Microsoft released updates fixing 398 security vulnerabilities, with 42 critical and one actively exploited. The large patch volume is attributed to AI-assisted discovery, and users are advised to apply updates promptly.
The Gunra ransomware-as-a-service operation is successfully targeting critical infrastructure by exploiting old Fortinet flaws and bypassing multi-factor authentication. The gang uses leaked Conti code and exploits vulnerabilities in firewalls and VPN appliances.
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals since at least May. They use fake job offers to lure victims into installing a trojanized WireGuard VPN client.