
New North Korean campaign uses fake coding interviews to steal developer credentials
DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.
2432 articles

DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.

Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.

A new ransomware strain named Spirals was identified in an attack against an IT services company in South Asia. Attackers were able to transition from gaining initial access to stealing data and encrypting the network in under 24 hours. Developed in Rust, Spirals quickly encrypts files using a unique AES-128 key for each file, with each key protected by an attacker-controlled ECDH. This rapid execution highlights the growing sophistication of ransomware attacks.

A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.

Apple has issued a warning to iPhone and iPad users about a new scam involving FaceTime calls. Fraudsters are impersonating trusted organizations to deceive users into sharing sensitive information such as account passwords, security codes, and financial details. They can even spoof phone numbers, making it appear as though the call is coming from legitimate sources like Apple or banks, enhancing their scam’s plausibility. Users are urged to remain vigilant against such tactics.

Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years.

U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams.

CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.