Jareh Sebastian Dalke, 32, of Colorado Springs, was sentenced today to 262 months in prison for attempted espionage in connection with his efforts to transmit classified National Defense Information (NDI) to an agent of the Russian Federation. According to the …
Safari is Not So Private! Safari Flaw Exposing EU iPhone Users to Trackers
A significant security flaw has been identified in Apple’s Safari browser that could potentially expose iPhone users in the European Union to unauthorized tracking. This vulnerability stems from a new feature introduced in iOS 17.4, designed to facilitate the installation …
Linux Kernel Vulnerability (CVE-2024-26925) Let Hackers Access Unauthorized Data
In a significant update from the Linux kernel’s security team, a critical vulnerability identified as CVE-2024-26925 has been addressed to bolster the security of systems worldwide. The flaw was found in the netfilter subsystem, specifically within the nf_tables component, which …
A Costly Mistake: How an Empty S3 Bucket Led to a Massive AWS Bill
AWS Customer Faces Massive Bill Due to Open-Source Tool Misconfiguration. In a startling incident, an AWS customer faced a staggering $1,300 bill for S3 usage, despite creating a single, empty bucket for testing purposes. The culprit? A popular open-source tool …
Gemini 1.5 Pro – Powered With Automated Malware Analysis To Detect Zero-Day
Google has introduced Gemini 1.5 Pro for malware analysis, an advanced AI tool capable of processing up to 1 million tokens. This tool revolutionizes automated malware analysis and marks a significant leap forward in the ongoing battle against the ever-evolving …
Rutger Stealer Hijacking Logins from Discord, Skype & other Apps
Cybersecurity experts have identified a new malware, Rutger Stealer, specifically designed to hijack login credentials from users of popular communication platforms such as Discord, Skype, and other applications. This development poses a significant threat to both individual privacy and organizational …
Token Infrastructure Platform Hacked: $44.5 Million Stolen in Cryptos
Hedgey Finance, a prominent token infrastructure platform, has reported a massive theft of approximately $44.5 million in cryptocurrencies. This incident unfolded rapidly over two hours, affecting operations on Ethereum’s layer-2 network Arbitrum and Binance Smart Chain. Overview of the Attack …
Judge0 Security Flaw Let Attackers Run Arbitrary Code & Gain Root Access
Tanto Security has disclosed critical vulnerabilities in the widely-used open-source service Judge0, which could allow attackers to perform a sandbox escape and gain root access to the host machine. The vulnerabilities, identified as CVE-2024-29021, CVE-2024-28185, and CVE-2024-28189, pose a significant …
HookChain – A New Sophisticated Technique Evades EDR Detection
In the rapidly evolving, complex threat landscape, EDR companies are constantly racing against new vectors. Recently, Helvio Benedito Dias de Carvalho Junior (aka M4v3r1ck) from Sec4US has developed an innovation called “HookChain.” It is an IAT hooking-based technique that utilizes …
Hackers Took Just 29-Days From IcedID Infection to Dagon Locker Ransomware
In a sophisticated cyberattack that unfolded over 29 days, cybersecurity analysts have meticulously traced the steps of threat actors from the initial infection with IcedID malware to the eventual deployment of Dagon Locker ransomware. The detailed account of this cyber …




