Kimsuky Expands Cyber Arsenal with New Malware Campaigns

The North Korean threat actor Kimsuky has launched new cyber attacks targeting South Korean entities, deploying sophisticated malware techniques.

The North Korean threat actor Kimsuky has launched new cyber attacks targeting South Korean entities, deploying sophisticated malware techniques.

A serious vulnerability in Gogs, an open-source Git service, enables authenticated users to execute arbitrary code, raising significant security concerns.

The conflict between Microsoft and a researcher known as Nightmare Eclipse intensifies, with threats of further zero-day exploit disclosures looming.

The Iranian hacking group MuddyWater has launched a cyber espionage campaign affecting organizations across nine countries, employing DLL side-loading techniques to infiltrate networks.

A former employee's unmonitored account allowed unauthorized access to critical city utilities, raising significant security concerns.

Grafana Labs has reported a breach of its GitHub environment, revealing source code and internal information but confirming no compromise of customer production systems.

Recent campaigns targeting developer environments highlight the need for enhanced security measures around developer workstations as they become critical points in the software supply chain.

The Russian hacking group Turla has upgraded its Kazuar backdoor into a modular peer-to-peer botnet, enhancing its stealth and persistence capabilities.

Instructure has acknowledged two unauthorized intrusions affecting its Canvas platform, with data potentially belonging to over 275 million users at risk.

In response to the potential threats posed by Anthropic's AI model Mythos, Japan's Prime Minister Sanae Takaichi has ordered a comprehensive review of the nation's cybersecurity strategy.