An access control misconfiguration on Oracle NetSuite ecommerce sites exposes customer data to unauthorized access, with many businesses unaware of deployed default instances.
Ransomware attack campaign targeted an old (and previously patched) vulnerability in VMware servers, and that it has grown to become the largest attack of its type, compromising at least 3,200 VMware servers.
IntelBroker claims to have broken into General Electric (GE) and stolen sensitive military files belonging to DARPA. GE has yet to confirm the data theft, only saying that it is still investigating the incident.
A threat actor linked to Babuk and Groove ransomware gangs leaked login credentials of 500,000 Fortinet VPN accounts to promote a new underground hacking forum.
Security researchers have discovered a network of over 3,000 GitHub accounts involved in an extensive malware distribution campaign.
Director of National Intelligence John Ratcliffe has issued a statement that Iranian and Russian actors have US voter data and are using it to engage in election interference.
Threat Actors Lurked on a Government Agency Network for 6 Months Before Deploying LockBit Ransomware
A novice hacker lingered on a government agency network for five months before transferring control to an experienced threat actor who deployed LockBit ransomware.
Threat group commits financial theft by hiding inside the victims’ networks for months while studying their financial systems and injecting fraudulent transactions into regular activity.
Nokia's Threat Intelligence Report noted an increase in IoT attacks stemming from poor security practices, the use of automated tools by attackers, and Internet visibility of devices.
While the frequency, intensity, and sophistication of DDoS attacks continues to rise, enterprises do have one factor on their side: the loud, distributed nature of DDoS attacks.










