Tag

Cyberattack

All articles tagged with #cyberattack

Malicious npm Packages Exploit Phishing to Steal Login Credentials

Originally Published 13 days ago — by The Hacker News

Featured image for Malicious npm Packages Exploit Phishing to Steal Login Credentials
Source: The Hacker News

Cybersecurity researchers uncovered a targeted spear-phishing campaign using 27 malicious npm packages to host browser-based phishing lures mimicking document-sharing portals and Microsoft sign-in pages, primarily targeting organizations in critical infrastructure sectors across multiple countries. The campaign leverages package CDNs for resilient hosting, employs anti-analysis techniques, and hard-codes specific email addresses, with the goal of stealing login credentials. The activity highlights ongoing threats in the software supply chain, emphasizing the need for stringent dependency verification and monitoring.

Cyberattack Disrupts France's Postal Service and Banking During Holiday Season

Originally Published 20 days ago — by Euronews.com

Featured image for Cyberattack Disrupts France's Postal Service and Banking During Holiday Season
Source: Euronews.com

France's postal service and banking division, La Poste and La Banque Postale, were hit by a suspected DDoS cyberattack during the Christmas period, disrupting package deliveries and online banking services. The incident follows previous attacks on La Poste and recent cyber breaches involving France's government and a suspected international ferry hacking plot, highlighting ongoing concerns about cyber threats and foreign interference in France.

Denmark Accuses Russia of Cyberattacks on Water and Election Systems

Originally Published 23 days ago — by Euronews.com

Featured image for Denmark Accuses Russia of Cyberattacks on Water and Election Systems
Source: Euronews.com

Denmark publicly blames Russia for cyberattacks in 2024 and 2025 targeting a water utility and government websites, linked to pro-Russian hacking groups, as part of Russia's broader hybrid warfare against the West, causing limited damage but highlighting vulnerabilities in critical infrastructure.

SonicWall Addresses Zero-Day Exploit in SMA 1000 Devices

Originally Published 25 days ago — by BleepingComputer

Featured image for SonicWall Addresses Zero-Day Exploit in SMA 1000 Devices
Source: BleepingComputer

SonicWall has issued a warning about a new zero-day vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in attacks to escalate privileges. The flaw is being exploited in conjunction with another critical vulnerability (CVE-2025-23006) to execute remote code with root privileges. SonicWall advises users to update to the latest firmware to mitigate the risk, as over 950 appliances are exposed online. This follows recent security breaches and malware attacks targeting SonicWall devices.

Data Breaches Expose Millions' Information Amid Privacy Concerns

Originally Published 26 days ago — by theregister.com

Featured image for Data Breaches Expose Millions' Information Amid Privacy Concerns
Source: theregister.com

Multiple companies including Pornhub, SoundCloud, and Askul experienced data breaches affecting millions, primarily involving exposure of email addresses and user information through compromised analytics tools or ransomware attacks, with most sensitive data like passwords and payment details remaining secure.

ClickFix Threat Evolves, Signaling New Wave of Malicious Copy-and-Paste Attacks

Originally Published 2 months ago — by Ars Technica

Featured image for ClickFix Threat Evolves, Signaling New Wave of Malicious Copy-and-Paste Attacks
Source: Ars Technica

ClickFix is a sophisticated scam campaign targeting Windows and macOS users by exploiting trust in online travel bookings and using social engineering tactics, such as fake CAPTCHA prompts and device-adaptive payloads, to infect devices with malware like PureRAT. The attacks leverage native OS capabilities and often bypass security tools, making awareness and cautious behavior the best defenses, especially during holiday gatherings when family members may be less vigilant.

Security Threats Emerge from Malicious and AI-Generated Extensions on Developer Platforms

Originally Published 2 months ago — by The Hacker News

Featured image for Security Threats Emerge from Malicious and AI-Generated Extensions on Developer Platforms
Source: The Hacker News

Cybersecurity researchers have identified three malicious VS Code extensions linked to the GlassWorm campaign, which uses invisible Unicode characters to hide malware, steal credentials, and spread in a worm-like fashion. Despite removal efforts, the threat has resurfaced, leveraging blockchain-based command-and-control infrastructure to maintain resilience. The attack has affected victims worldwide, including a major Middle Eastern government, and has expanded to target GitHub repositories.