Tag Sophos

Nation-State Actors Capitalize on Gemini AI Application

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Google Identifies Iranian and Chinese Threat Groups as Most Active Users of AI Tools Akshaya Asokan (asokan_akshaya) • January 30, 2025 Image: Shutterstock Recent disclosures from Google reveal that Iranian and Chinese threat actors are leveraging the company’s artificial intelligence…

Read MoreNation-State Actors Capitalize on Gemini AI Application

Addressing Vulnerability Lags Exploited by Salt Typhoon

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Chinese Hackers Target Unpatched Microsoft, Sophos, Fortinet, and Ivanti Products Mathew J. Schwartz (euroinfosec) • January 24, 2025 Image: Shutterstock In a significant breach, Chinese state-sponsored hackers have been exploiting vulnerabilities in the telecommunications networks of the U.S. and…

Read MoreAddressing Vulnerability Lags Exploited by Salt Typhoon

US Discovers Hacking Group Responsible for Salt Typhoon Telecom Breaches

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime, Standards, Regulations & Compliance U.S. Treasury Implements Sanctions Amid Cybersecurity Breaches David Perera (@daveperera) • January 17, 2025 Image: Shutterstock On January 17, 2025, the U.S. federal government announced that it has successfully traced intrusions by Chinese hackers targeting telecommunications networks back…

Read MoreUS Discovers Hacking Group Responsible for Salt Typhoon Telecom Breaches

Chinese Hack Compromises US Sanctions Office in Treasury Breach

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Chinese Hackers Allegedly Target U.S. Treasury Department Offices Related to Economic Sanctions By Chris Riotta (@chrisriotta) • January 2, 2025 Chinese nation-state hackers infiltrated several U.S. Treasury Department offices. (Image: Shutterstock) A recent cyber intrusion linked to Chinese hackers has successfully breached…

Read MoreChinese Hack Compromises US Sanctions Office in Treasury Breach

Turmoil Strikes the Rockstar 2FA Phishing-as-a-Service Toolkit

As 2024 draws to a close, cybersecurity firms are reporting significant upheaval in the cybercrime landscape, particularly relating to phishing-as-a-service operations. Recent assessments by Sophos indicate that the once-prominent phish-tool Rockstar 2FA, notorious for its sophisticated phishing campaigns, has reportedly ceased operations. Following this disruption, many of its users have…

Read MoreTurmoil Strikes the Rockstar 2FA Phishing-as-a-Service Toolkit

Vulnerable Cleo Managed File Transfer Software Without Updates

Attack Surface Management, Governance & Risk Management, Patch Management Over 200 Vulnerable Servers Targeted by Ransomware Group Amid Growing Exploits Mathew J. Schwartz (euroinfosec) • December 18, 2024 Recent reports indicate over 200 Cleo managed file-transfer servers remain publicly accessible and without necessary updates, posing significant risks in light of…

Read MoreVulnerable Cleo Managed File Transfer Software Without Updates

A Sneak Peek at Black Hat Europe 2024 in London: 20 Must-See Sessions

Black Hat, Events Exploring Automotive Vulnerabilities, Bootloader Flaws, and Cyber Threats at Black Hat Europe 2024 Mathew J. Schwartz (euroinfosec) • December 9, 2024 Image: Shutterstock The Black Hat Europe conference is once again convening in London, promising a diverse agenda that delves into the myriad challenges facing cybersecurity today.…

Read MoreA Sneak Peek at Black Hat Europe 2024 in London: 20 Must-See Sessions

Krispy Kreme Doughnut Cyber Attack Could Impact Holiday Sales

Krispy Kreme Faces Cyber Attack During Holiday Season In a significant cybersecurity incident, Krispy Kreme, the prominent American doughnut and coffee chain, experienced a sophisticated attack that disrupted its sales operations amidst the crucial Christmas season. The breach occurred in November 2024 and primarily affected the company’s online ordering system,…

Read MoreKrispy Kreme Doughnut Cyber Attack Could Impact Holiday Sales