Cyber Threat Intelligence
Cyber Attack News
Today's cyber attacks, data breaches and hacking news, from ransomware crews to state-backed intrusions and law-enforcement takedowns. Every story is reported from official government advisories and analysed for what defenders should do next.
All attack news
-
ACTIVE EXPLOITATIONExploited Zammad helpdesk chain runs from session hijack to root
CISA added two chained Zammad flaws to its KEV catalog: a session hijack giving code execution and a local root escalation, with a 5 October federal deadline.
-
LAW ENFORCEMENTTwo get 189 months combined for US business email wire-fraud scheme
Two Delaware men who phished business mailboxes and redirected wires, including a $1.68M payment, got 189 months combined. What finance teams should change.
-
ACTIVE EXPLOITATIONExploited FortiMail flaw lets attackers write files with no fix out yet
CISA added an unauthenticated FortiMail path traversal to its KEV catalog with a three-day deadline and a compromise check, while fixed builds are still pending.
-
ACTIVE EXPLOITATIONApple CoreGraphics zero-day exploited in targeted attacks, CISA says
CISA added an Apple CoreGraphics memory flaw to its KEV catalog after reports of targeted attacks, with a 2 October deadline and forensic triage for iOS and macOS.
-
ACTIVE EXPLOITATIONExploited Cisco SD-WAN Manager flaw gives attackers admin API access
CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass to its KEV catalog with a three-day federal deadline and a required compromise check.
-
ACTIVE EXPLOITATIONTwo Citrix NetScaler zero-days under active attack, CISA and NCSC warn
CISA and the UK NCSC confirm attackers are exploiting two critical NetScaler ADC and Gateway flaws as zero-days. Check for compromise, then patch by 30 September.
-
ACTIVE EXPLOITATIONCISA confirms exploitation of SharePoint and MikroTik RouterOS flaws
CISA added a SharePoint code injection flaw and a MikroTik RouterOS SSH bug that completes a known router takeover chain to KEV, with a 28 September deadline.
-
ACTIVE EXPLOITATIONCISA flags six exploited flaws in VPN, SD-WAN and commerce platforms
CISA added six actively exploited CVEs in Check Point, F5 BIG-IP APM, Arista VeloCloud, WSO2 and Adobe Commerce to KEV this week, with deadlines of 25 and 27 September.
-
ACTIVE EXPLOITATIONCISA confirms attacks on WordPress core file inclusion flaw
CISA added a WordPress core file inclusion bug that can lead to code execution to its KEV catalog, set a three-day federal deadline and required forensic triage.
-
ADVISORYFBI and CISA warn ICS integrators are a path into critical infrastructure
An FBI and CISA fact sheet cites an intrusion at a US industrial automation integrator where attackers packaged about 800 files, including customer SCADA data.
-
LAW ENFORCEMENTOperator of Rydox stolen-data marketplace pleads guilty in US case
A Kosovar national pleaded guilty to running Rydox, a marketplace that sold stolen US identities and cybercrime tools in over 7,600 transactions since 2016.
Attack types we report on
- Data breach
- An incident in which data is accessed or taken by someone not authorised to have it. A security breach does not always mean data left the network; a data breach does.
- Ransomware
- Malware that encrypts a victim’s files and demands payment for the key. Most crews now also steal the data first and threaten to leak it.
- Phishing
- A message that impersonates someone trusted to get the reader to open a malicious file, follow a link or hand over credentials. Spearphishing is the targeted version.
- DDoS
- A denial-of-service (DoS) attack floods or crashes a service so legitimate users cannot reach it. A distributed denial-of-service (DDoS) attack does it from many machines at once, usually a botnet.
- Supply chain
- An attack delivered through something the victim trusts, such as a software package, update or service provider, rather than against the victim directly.