cyberscoop

FBI alerts tie together threats of cybercrime, physical violence from The Com

The FBI has issued a series of public service announcements (PSAs) warning about “The Com,” a rapidly growing and decentralized cybercriminal network composed primarily of minors and young adults aged 11 to 25.

Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups

Two critical zero-day vulnerabilities in Microsoft SharePoint—CVE-2025-53770 and CVE-2025-53771—are being actively exploited by China-linked threat actors Linen Typhoon, Violet Typhoon, and Storm-2603.

After website hack, Arizona election officials unload on Trump’s CISA

Arizona election officials reported a cyberattack on the state’s online candidate portal, where attacker(s) replaced candidate photos with images of the late Iranian Ayatollah Ruhollah Khomeini.

Ryuk ransomware operator extradited to US, faces five years in federal prison

Karen Serobovich Vardanyan, a 33-year-old Armenian national, has been extradited to the United States and charged for his alleged involvement in Ryuk ransomware attacks that occurred between March 2019 and September 2020.

Why skipping security prompting on Grok’s newest model is a huge mistake

Researchers identified critical vulnerabilities in Grok 4, particularly when deployed without system-level security prompting. The model was found to be highly susceptible to prompt injection attacks and capable of generating harmful content.

Treasury slaps sanctions on people, companies tied to North Korean IT worker schemes

The U.S. Department of the Treasury has imposed sanctions on individuals and entities involved in a North Korean IT worker scheme designed to covertly fund DPRK weapons of mass destruction and ballistic missile programs.

China-linked attacker hit France’s critical infrastructure via trio of Ivanti zero-days last year

A China-linked threat actor, UNC5174, exploited three Ivanti CSA zero-days (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) to target French critical infrastructure sectors from September to November 2024.

Massachusetts man will plead guilty in PowerSchool hack case

A 19-year-old Massachusetts student has agreed to plead guilty in connection with a major cyberattack on PowerSchool, an education software provider serving over 60 million students.

Vulnerability in Popular AI Developer Could ‘Shut Down Essentially Everything You Own’

The flaw in Lightning.AI’s platform, which has been patched, would have given root access to an attacker and broad control over a victim’s cloud-based studio and connected systems.
January 14, 2025

Fancy Bear spotted using real Kazak government documents in spearpishing campaign

A hacking group linked to Russian intelligence has been observed leveraging seemingly legitimate documents from the Kazakhstan government as phishing lures to infect and spy on government officials in Central Asia.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags