Skip to content

Latest alerts

RSS feed

Ransom Cartel mastermind gets 16 years in prison

A US court sentenced Maksim Silnikau, the alleged creator behind the Ransom Cartel ransomware, to 16 years in prison. The case details a network of stolen credentials, encryption tools, and secret infrastructure.

Oracle SQLi to SYSTEM access via stored Java

Attackers used an Oracle SQL injection in a public web form to compile Java inside the database and pivot to Windows SYSTEM. The post-exploitation toolkit, dubbed khunt, leaves specific hunting clues.

Agent Tool-Call Bypass in AWS, Google, Vercel

Security researchers documented an agent tool-call bypass pattern across AWS, Google, and Vercel. In multiple cases, attackers could trigger tool execution without the model ever running.

Backdoor in Zbtlink routers: root shell possible

Researchers discovered a backdoor in Zbtlink routers that, during startup, connects to C2 domains and can provide an interactive root shell without authentication. Extra attention is needed for firmware, processes, and outbound connections.

Cisco Patches Critical SD-WAN, IOS XE, FMC Flaws

Cisco has released patches for multiple high-impact vulnerabilities across Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The update includes critical issues such as authentication bypass and command injection.

Snowflake breach: hacker pleads guilty over huge impact

In the Snowflake breach case, Connor Riley Moucka pleaded guilty to multiple federal charges tied to 2024 account intrusions. Prosecutors say outdated credentials and disabled MFA enabled access affecting at least 100 million people.

Ransom Cartel Creator Gets 16-Year Prison Sentence

A Belarusian national linked to the Ransom Cartel ransomware operation received a 16-year prison sentence. U.S. prosecutors describe his role in recruiting affiliates, providing tools, and managing ransom activity.

Exploit chain links Samsung Members to Bixby

Researchers demonstrated an exploit chain that can lead from a user click to Samsung Members, then Samsung Account, and finally Bixby. The chain enabled system-level compromise and further remote control on affected Galaxy models.

OpenAI disrupts Poipet scam network with ChatGPT

OpenAI says it disrupted a Cambodia-based Poipet scam network that used ChatGPT to scale fake personas and messages across multiple fraud schemes. The operation relied on coordinated accounts and AI-generated content to trick victims into payments.