Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Key Takeaways Case Summary This intrusion began in November 2024 with a password spray attack targeting an internet-facing RDP server. Over the course of several hours, the threat actor attempted logins against multiple accounts using known malicious IPs (based on OSINT).
This DFIR Report analysis covers ransomware threats including attack chains, indicators of compromise, and recommended defensive measures. Ransomware continues to be a primary cyber risk for organizations across all sectors.
Key Takeaways Case Summary This intrusion began in November 2024 with a password spray attack targeting an internet-facing RDP server. Over the course of several hours, the threat actor attempted logins against multiple accounts using known malicious IPs (based on OSINT).
This DFIR Report analysis covers ransomware threats including attack chains, indicators of compromise, and recommended defensive measures. Ransomware continues to be a primary cyber risk for organizations across all sectors.
CISA released an advisory about ransomware actors leveraging unpatched SimpleHelp RMM vulnerabilities to compromise a utility billing software provider. The campaign has targeted organizations since January 2025 using SimpleHelp versions 5.5.7 and earlier.
CISA released this advisory in response to ransomware actors leveraging unpatched SimpleHelp RMM vulnerabilities to compromise customers of a utility billing software provider. The actors likely used CVE-2024-57727, a path traversal vulnerability, for double extortion.