Advertisement · 728 × 90

Posts by CyberNetSecIO

CISA Mandates Urgent Patching for Eight Actively Exploited Flaws in Cisco, JetBrains, and More CISA has added eight new actively exploited vulnerabilities to its KEV catalog, affecting products from Cisco, PaperCut, and JetBrains. Learn about the CVEs and CISA

🚨 CISA adds 8 actively exploited vulnerabilities to its KEV catalog! Flaws in Cisco, PaperCut, & JetBrains products require urgent patching. Federal agencies are mandated to remediate, and all orgs are strongly urged to act now. #KEV #CyberSecurity...

16 hours ago 0 0 1 0
Ex-FBI Official Urges Terror Designations for Ransomware Gangs Attacking Hospitals A former FBI cyber official has called for the U.S. government to consider designating ransomware groups that target hospitals as terrorist organizations and to pursue homicide charges in cases of patient death.

A former FBI official is urging the U.S. government to designate ransomware groups that attack hospitals as TERRORIST organizations. The proposal could open the door to homicide charges if attacks lead to patient deaths. ⚖️ #Ransomware #Healthcare #...

16 hours ago 0 0 0 0
Semperis Extends Purple Knight AD Security Tool to US Government Clouds Semperis announced that its free Active Directory and Entra ID security assessment tool, Purple Knight, now fully supports Microsoft

✅ Semperis' Purple Knight tool now supports Microsoft GCC High environments! U.S. federal agencies & defense contractors can now use the free tool to assess their Entra ID security posture in the high-compliance cloud. 🛡️ #ActiveDirectory #EntraID ...

16 hours ago 0 0 0 0
Chinese APT Mustang Panda Targets Indian Banks, Korean Policy Experts in Espionage Campaign The Chinese APT group Mustang Panda (TA416) is targeting the Indian financial sector and policy experts in Korea and the US with its custom LotusLite backdoor in a new espionage campaign.

🇨🇳 APT UPDATE: Mustang Panda targets Indian banks & Korean policy experts in a new espionage campaign. The group uses spear-phishing & DLL sideloading to deploy the LotusLite backdoor for intelligence gathering. 🕵️ #APT #MustangPanda #CyberEspion...

16 hours ago 0 0 0 0
Gentlemen RaaS Expands with SystemBC Botnet for Covert Attacks The Gentlemen ransomware-as-a-service (RaaS) operation has been linked to the SystemBC proxy malware botnet, enabling affiliates to conduct more stealthy and resilient attacks.

Gentlemen RaaS is upgrading its toolkit, using the SystemBC botnet for covert SOCKS5 proxying. The combo enables stealthy C2 and payload delivery for attacks on Windows, Linux, and ESXi. 💣 #Ransomware #SystemBC #Gentlemen #CyberSecurity

16 hours ago 0 0 0 0
Qilin Ransomware Blinds Defenses with Advanced EDR Killer, Abusing Vulnerable Drivers The Qilin ransomware group is using a sophisticated, multi-stage attack with a "bring your own vulnerable driver" (BYOVD) technique to disable hundreds of EDR solutions before encryption.

🔥 Qilin ransomware deploys a sophisticated EDR killer, using a vulnerable signed driver (BYOVD) to disable over 300 security products at the kernel level. A major escalation in defense evasion tactics. #Ransomware #Qilin #EDR #CyberSecurity #BYOVD

16 hours ago 0 0 0 0
ShinyHunters Breach at Canada Life Exposes Data of 70,000 Customers The Canada Life Assurance Company confirms a cyberattack by the ShinyHunters extortion group, which exposed the personal data of up to 70,000 individuals after gaining access via a compromised employee account.

Insurance giant Canada Life confirms a data breach by the ShinyHunters group, impacting 70,000 individuals. Attackers gained access via a compromised employee account. 🛡️ #DataBreach #ShinyHunters #CyberSecurity #Insurance

16 hours ago 2 0 0 0
Progress Patches Critical Command Injection Flaws in MOVEit WAF and LoadMaster Progress Software patches multiple command injection vulnerabilities (CVE-2026-3517, CVE-2026-3519, etc.) and a WAF bypass flaw in its MOVEit WAF and LoadMaster products.

PATCH NOW: Progress Software fixes multiple command injection & WAF bypass flaws in MOVEit WAF and LoadMaster. Vulnerabilities (CVE-2026-3517, etc.) could lead to RCE. Update to the latest versions immediately! 🔒 #Vulnerability #PatchTuesday #MOVEit

16 hours ago 0 0 0 0
Nearly 600,000 Patients Affected by Data Breaches at Three U.S. Healthcare Providers Three U.S. healthcare providers—North Texas Behavioral Health Authority, Southern Illinois Dermatology, and Saint Anthony Hospital—disclose data breaches affecting nearly 600,000 individuals.

🏥 Nearly 600,000 patients impacted by data breaches at three U.S. healthcare providers in IL & TX. Incidents involve network intrusions and email compromise, with one linked to the Insomnia ransomware group. #Healthcare #DataBreach #HIPAA

16 hours ago 0 0 0 0
Ransomware Industrialized: Vect RaaS Partners with BreachForums and TeamPCP The Vect ransomware group has formalized an alliance with BreachForums and TeamPCP to create an industrialized model for ransomware deployment, leveraging stolen credentials for scalable attacks.

🚨 Ransomware Industrialized: Vect RaaS forms a strategic alliance with BreachForums & TeamPCP. The partnership weaponizes stolen credentials for large-scale attacks. Guesty & USHA already hit. A new era of scalable cybercrime. 🏭 #Ransomware #Vect ...

16 hours ago 0 0 0 0
Advertisement
ShinyHunters Claims Amtrak Breach, Threatens to Leak 9.4M Records The hacking group ShinyHunters has claimed a breach of Amtrak, alleging the theft of 9.4 million records via the company

Hacking group ShinyHunters claims a massive breach of Amtrak, threatening to leak 9.4M records. 🚂 The group alleges access was gained via Amtrak's Salesforce systems, highlighting major third-party risk. #DataBreach #ShinyHunters #Amtrak

4 days ago 0 0 0 0
Critical Researchers have discovered a critical vulnerability chain,

Critical 'NomShub' vulnerability in the Cursor AI coding editor could allow attackers to hijack a developer's machine just by opening a malicious repository. 💻 #Vulnerability #AI #DevSecOps #RCE

4 days ago 0 0 1 0
Two U.S. Senior Care Providers Disclose Data Breaches by Sinobi and Worldleaks Ransomware Gangs U.S. senior care providers Windward Life Care and Legend Senior Living have reported data breaches stemming from 2025 ransomware attacks by the Sinobi and Worldleaks groups, exposing patient PII and PHI.

Two U.S. senior care providers, Windward Life Care & Legend Senior Living, disclose data breaches from ransomware attacks by Sinobi and Worldleaks gangs. Sensitive patient data was leaked. 🏥 #Ransomware #DataBreach #Healthcare

4 days ago 0 0 0 0
Phishing Campaign Abuses Legitimate SimpleHelp RMM Tool via Fake DHL A new phishing campaign impersonates DHL to trick users into installing a malicious, pre-configured version of the legitimate SimpleHelp RMM tool, providing attackers with backdoor access.

⚠️ Phishing Alert: Fake DHL 'shipment arrived' emails are dropping a malicious installer for the SimpleHelp RMM tool, giving attackers a backdoor into victim networks. Be cautious with attachments! 📦 #Phishing #Malware #SimpleHelp #RMM

4 days ago 0 0 0 0
Mozambique Passes Sweeping Cybersecurity and Cybercrime Laws to Combat Rising Digital Threats The Parliament of Mozambique has approved new cybersecurity and cybercrime laws to create a national framework, establish a regulatory authority, and mandate security measures for public and private sectors.

Mozambique's Parliament approves new national cybersecurity and cybercrime laws, establishing a regulatory authority and mandating security measures for all organizations to combat rising cyber threats. 🇲🇿 #Cybersecurity #Law #Regulation #Mozambique

4 days ago 0 0 0 0
Stealthy Researchers at Cisco Talos have identified

Cisco Talos uncovers 'PowMix,' a new botnet targeting the Czech Republic. Uses randomized C2 beaconing and embeds data in URL paths to evade detection. 🇨🇿 #Botnet #PowMix #Malware #ThreatIntel #CiscoTalos

4 days ago 0 0 0 0
New Security researchers from CYFIRMA have analyzed a new ransomware strain called NBLOCK, which uses AES-256 encryption and a Tor-based portal for anonymous ransom negotiations.

New ransomware strain 'NBLOCK' discovered. Encrypts files with AES-256, adds '.NBLock' extension, and uses a Tor portal for ransom negotiations. 🔒 #Ransomware #NBLOCK #Malware #ThreatIntel

4 days ago 0 0 0 0
Advertisement
McGraw Hill Data Breach Exposes 13.5 Million Accounts After Salesforce Misconfiguration Education publisher McGraw Hill suffered a data breach exposing 13.5 million user accounts. The incident, claimed by the ShinyHunters group, was caused by a misconfigured Salesforce environment.

⚠️ Data Breach: Education giant McGraw Hill confirms 13.5M accounts exposed due to a Salesforce misconfiguration. ShinyHunters claims responsibility and has leaked the data. 📚 #DataBreach #McGrawHill #Salesforce #ShinyHunters

4 days ago 0 0 0 0
Ransomware Market Consolidation: Qilin, Akira, and DragonForce Dominate March 2026 Attacks A Check Point report reveals that three ransomware gangs—Qilin, Akira, and DragonForce—are dominating the threat landscape, accounting for 40% of all attacks in March 2026.

Ransomware market consolidation: Just 3 groups—Qilin, Akira, and DragonForce—were behind 40% of all attacks in March 2026, per Check Point. 📈 Qilin led the charge with 20% of incidents. #Ransomware #ThreatIntel #Qilin #Akira

5 days ago 0 0 0 0
Critical Auth Bypass in nginx-ui (CVE-2026-33032) Actively Exploited for Full Nginx Takeover A critical authentication bypass vulnerability (CVE-2026-33032) in the nginx-ui management tool is under active exploit, allowing for unauthenticated remote code execution. Update to version 2.3.4 now.

🚨 CRITICAL FLAW: nginx-ui is being actively exploited via an auth bypass (CVE-2026-33032, CVSS 9.8). Unauthenticated attackers can gain full RCE. Patch to version 2.3.4+ immediately! #nginx #CyberSecurity #Vulnerability

5 days ago 0 0 0 0
Booking.com Warns Customers of Data Breach Exposing Reservation Details and Personal Info Online travel agency Booking.com has warned customers of a data breach exposing personal and reservation details, increasing the risk of sophisticated phishing attacks.

Booking.com confirms a data breach where hackers accessed reservation details and personal info. ✈️ No financial data was exposed, but users should be on high alert for targeted phishing scams. PINs have been reset. #BookingCom #DataBreach #Phishing

5 days ago 0 0 0 0
Fortinet Patches Critical Authentication Bypass and RCE Flaws in FortiSandbox Fortinet has patched two critical, unauthenticated vulnerabilities (CVE-2026-39813 and CVE-2026-39808) in its FortiSandbox product that could lead to auth bypass and RCE. Immediate patching is advised.

Fortinet patches two critical (CVSS 9.1) flaws in FortiSandbox. 🚨 CVE-2026-39813 (auth bypass) & CVE-2026-39808 (RCE) can be exploited by an unauthenticated attacker. Patch immediately! #Fortinet #Vulnerability #CyberSecurity

5 days ago 0 0 0 0
RCI Hospitality Data Breach Exposes Sensitive Information of Contractors RCI Hospitality Holdings has reported a data breach exposing the personal information of contractors, including SSNs, due to an IDOR vulnerability on a web server.

RCI Hospitality Holdings discloses a data breach exposing contractor PII, including SSNs. ‼️ The breach was caused by an Insecure Direct Object Reference (IDOR) vulnerability on a web server. #DataBreach #IDOR #Vulnerability

5 days ago 0 0 0 0
ShinyHunters Claims Amtrak Breach, Threatens to Leak 9.4M Records The hacking group ShinyHunters has claimed a breach of Amtrak, alleging the theft of 9.4 million records via the company

Hacking group ShinyHunters claims a massive breach of Amtrak, threatening to leak 9.4M records. 🚂 The group alleges access was gained via Amtrak's Salesforce systems, highlighting major third-party risk. #DataBreach #ShinyHunters #Amtrak

5 days ago 0 0 0 0
Bank3 Discloses Data Breach, Exposing Customer SSNs and Financial Data Tennessee-based Bank3 has disclosed a data breach exposing customer Social Security numbers and financial data, following a claim by the Qilin ransomware group in late 2025.

Bank3 discloses data breach exposing customer SSNs & financial data. 🏦 The notice follows claims by the Qilin ransomware group to have stolen 149GB of data from the Tennessee bank. #DataBreach #Ransomware #Qilin #Finance

5 days ago 0 0 0 0
Critical Flaw in Axios Library Puts Countless Web Apps at Risk of RCE A critical SSRF vulnerability (CVE-2026-40175) with a CVSS score of 10.0 has been found in the popular Axios JavaScript library, allowing for RCE and cloud compromise. A PoC is available.

🚨 CRITICAL VULNERABILITY (CVSS 10.0) in Axios JS library! CVE-2026-40175 is an SSRF flaw that can lead to RCE and full cloud compromise. PoC is public. If you use Axios, update to v1.13.2 NOW! 🌐 #SupplyChain #RCE #SSRF

5 days ago 0 0 0 0
Advertisement
Obsidian Plugin Abused in Social Engineering Campaign to Deliver New PHANTOMPULSE RAT A sophisticated campaign is abusing the Obsidian note-taking app to deliver a new RAT, PHANTOMPULSE, to targets in the finance and crypto sectors using social engineering and malicious plugins.

New campaign REF6598 targets finance & crypto pros using the Obsidian app! ⚠️ Attackers use malicious community plugins to deploy PHANTOMPULSE, a new RAT that uses the Ethereum blockchain for C2. ⛓️ #Malware #Obsidian #Crypto #CyberSecurity

5 days ago 0 0 0 0
Autovista Ransomware Attack Disrupts Automotive Data Services Across Europe and Australia Automotive data and analytics firm Autovista has confirmed a ransomware attack is disrupting its services and applications across Europe and Australia. The company is investigating the incident.

🚗 Ransomware attack hits Autovista, a major automotive data firm. Services for vehicle valuation and analytics are disrupted across Europe & Australia. Investigation is ongoing. #Ransomware #Automotive #CyberAttack #DataBreach

5 days ago 0 0 0 0
NIST Overhauls NVD, Will No Longer Enrich All CVEs Amidst NIST announces a major policy change for the National Vulnerability Database (NVD), prioritizing CVE enrichment for critical flaws and leaving others unenriched due to a surge in reports.

Major shift for vulnerability management: NIST will no longer enrich all CVEs in the NVD due to overwhelming volume. 📢 Focus will be on critical & exploited flaws. Time to re-evaluate your VT processes! #NIST #NVD #CVE #CyberSecurity

5 days ago 0 0 0 0
Mirax Android RAT Infects 220,000+ Devices via Meta Ads, Sold as Exclusive MaaS A new Android RAT named Mirax is spreading via malicious ads on Facebook and Instagram, infecting over 220,000 users and turning their devices into SOCKS5 proxies as part of a Malware-as-a-Service operation.

📱 New Android RAT 'Mirax' infects 220k+ devices via Meta ads! The malware turns phones into SOCKS5 proxies and is sold as a private MaaS. Beware of sideloading apps from ads. #Android #Malware #CyberSecurity #Mirax

6 days ago 0 0 0 0