Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Trezor reported that 347,000 users were targeted in phishing attacks following a breach at their email service provider, Brevo. The attackers sent convincing emails impersonating Trezor to steal hardware wallet recovery seeds, though no funds were stolen.
Attackers have been observed chaining two distinct vulnerabilities in JFrog Artifactory, a widely-used software repository manager, to escalate privileges and gain full administrative control. With admin access secured, the attackers can plant backdoored artifacts that compromise downstream consumers of the repository.
A China-linked advanced persistent threat group identified as UNC3569 has been exploiting a vulnerability in Sogou Input Method, a near-ubiquitous Chinese keyboard application, to deploy the GRAYRABBIT backdoor on targeted systems. The compromise leverages the software's widespread installation and trusted system-level access to establish persistence with minimal detection risk.
A former member of the Conti ransomware gang was sentenced to 4 years in prison for his role in attacks that caused hundreds of millions in damages globally. The individual is one of several Conti members to face prosecution, reflecting ongoing efforts to combat ransomware.
PaperCut released new security maintenance updates replacing emergency patches for two actively exploited vulnerabilities in its print management software. The original emergency patches were interim measures, and the new permanent fixes address the underlying flaws more comprehensively.
Cisco has confirmed that three separate threat clusters — including both ransomware operators and state-sponsored hackers — are actively exploiting two flaws in Cisco Firepower Management Center to steal credentials and deploy the Qilin ransomware payload. The vulnerabilities bypass authentication on the security management appliance, giving attackers administrative control over the organization's own defense infrastructure.