Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Joint advisory from US and South Korean agencies warns of Gunra ransomware attacks against government and critical infrastructure organizations worldwide. The ransomware exploits security flaws in internet-facing Fortinet and Schneider Electric appliances to gain initial access, then deploys double extortion tactics.
Gunra ransomware attacks target critical infrastructure sectors globally, exploiting Fortinet vulnerabilities. It uses a double extortion model combining data exfiltration and encryption.
Detailed analysis of Gunra ransomware reveals exploitation of CVE-2024-5559 and CVE-2025-24472 in Schneider Electric and Fortinet appliances for initial access, followed by double extortion. The group uses Impacket tools for lateral movement, deletes logs, and employs session hijacking and MFA bypass techniques.
Fake TikTok Shop websites closely mimic the real feature to trick users into paying for products or entering payment details. These unverified sites use copied branding and trust badges to appear legitimate.
Attackers create convincing fake websites for popular apps like CNN and Avast to trick Windows users into downloading a legitimate remote management tool called O&O Syspectr. This tool, once installed and linked to the attacker's account, gives them full remote control over the victim's computer.
Hackers breached a Polish combined heat and power plant by exploiting a private cellular network (APN) that allowed communication between devices. They leveraged default credentials on a controller and pivoted from a compromised wind farm to shut down a steam turbine and water treatment system.