CyberScoop

Researchers determine old vulnerabilities pose real-world threat to sensitive data in public clouds

The vulnerability poses a significant threat to public cloud providers, whose business model involves offering remote code execution as a service and renting out shared hardware resources.

SonicWall pins firewall attack spree on year-old vulnerability

A recent surge in ransomware attacks targeting SonicWall Gen 7 firewalls has been attributed to CVE-2024-40766, a critical improper access control vulnerability in SonicOS. SonicWall has denied the presence of a zero-day vulnerability.

Research reveals possible privacy gaps in Apple Intelligence’s data handling

Findings indicate that Siri and related services may transmit sensitive user data to Apple servers beyond what is disclosed in Apple’s privacy policies, raising questions about user consent, data handling transparency, and more.

Nigerian accused of hacking tax preparation businesses extradited to US

A Nigerian national, Chukwuemeka Victor Amachukwu, was extradited from France to the US to face charges related to a multi-year cyber-enabled fraud campaign. The scheme involved spearphishing attacks, identity theft, and fraudulent filings.

China accuses US of exploiting Microsoft zero-day in cyberattack

China has accused U.S. intelligence agencies of conducting cyberattacks on two Chinese military enterprises, including the exploitation of a Microsoft Exchange zero-day vulnerability.

Feds still trying to crack Volt Typhoon hackers’ intentions, goals

Federal cybersecurity officials are continuing to assess the strategic threat posed by the Chinese state-sponsored threat actor Volt Typhoon, which has infiltrated U.S. critical infrastructure networks, including systems on the island of Guam.

FBI alerts tie together threats of cybercrime, physical violence from The Com

The FBI has issued a series of public service announcements (PSAs) warning about “The Com,” a rapidly growing and decentralized cybercriminal network composed primarily of minors and young adults aged 11 to 25.

Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups

Two critical zero-day vulnerabilities in Microsoft SharePoint—CVE-2025-53770 and CVE-2025-53771—are being actively exploited by China-linked threat actors Linen Typhoon, Violet Typhoon, and Storm-2603.

After website hack, Arizona election officials unload on Trump’s CISA

Arizona election officials reported a cyberattack on the state’s online candidate portal, where attacker(s) replaced candidate photos with images of the late Iranian Ayatollah Ruhollah Khomeini.

Ryuk ransomware operator extradited to US, faces five years in federal prison

Karen Serobovich Vardanyan, a 33-year-old Armenian national, has been extradited to the United States and charged for his alleged involvement in Ryuk ransomware attacks that occurred between March 2019 and September 2020.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags