Critical Windows NTLM Zero-Day Vulnerability Left Unpatched Until April 2024
A severe security flaw affecting all Windows versions allows attackers to capture NTLM credentials through malicious files in Windows Explorer. Microsoft plans to address this zero-day vulnerability in April 2024, leaving systems potentially exposed for months.
Critical Security Breach: Popular Python AI Library Compromised with Crypto Mining Malware
The Ultralytics AI library was discovered distributing malicious cryptocurrency mining code through compromised versions on PyPI. The attack, which exploited GitHub Actions workflows, potentially impacted thousands of AI developers worldwide and highlights growing concerns around supply chain security.
Croatian Port Operator Successfully Blocks 8Base Ransomware Attack
Luka Rijeka, a major Croatian port operator, thwarted a ransomware attack through rapid incident response and system shutdowns. The company's IT team successfully restored operations within days, preventing data loss despite threats from the 8Base ransomware group.
Critical Prompt Injection Flaws Discovered in Leading AI Chatbots
Security researchers uncover dangerous vulnerabilities in DeepSeek and Claude AI chatbots that could enable account hijacking and malicious code execution. The findings highlight significant security risks in AI systems, prompting companies to strengthen defenses against prompt injection attacks.
Massive Socks5Systemz Botnet Fuels Illegal Global Proxy Service Network
BitSight uncovers a sprawling botnet operation that has compromised over 85,000 devices to power an illicit proxy service called PROXY.AM. The network, active since 2013, allows cybercriminals to rent infected machines as proxy servers for monthly fees up to $700.
Critical Buffer Overflow Vulnerability Discovered in Curl Web Tool
A serious security flaw in Curl, the widely-used data transfer tool, could allow attackers to exploit buffer overflow vulnerabilities when processing IP addresses. The issue affects both IPv4 and IPv6 address handling, putting countless websites and applications at risk.
Michigan School District Battles Cyberattack While Managing Budget Crisis
Wayne-Westland Community Schools faces service disruptions and parent concerns following a cyberattack that knocked out internet and phone services. Despite the challenges, officials confirm student data remains secure while working to restore services and rebuild community trust.
Russian Hackers Exploit Cloudflare Tunnels to Conceal Advanced GammaDrop Malware Campaign
Russian state-backed hacking group Gamaredon is using Cloudflare Tunnels and DNS fast-flux techniques to mask their malware distribution targeting Ukrainian organizations. The sophisticated campaign deploys GammaDrop malware through spear-phishing attacks to steal sensitive data and maintain persistent access to compromised systems.
Venom Spider Expands Malware Operation with Advanced Backdoor and Loader Tools
Cybercrime group Venom Spider has enhanced their malware-as-a-service platform with two sophisticated new tools: the RevC2 backdoor and Venom Loader. The expansion demonstrates advanced capabilities including browser data theft and customized payloads, despite recent legal challenges to their operation.
Critical Zero-Day Vulnerability Exposes Mitel MiCollab Enterprise Platform
Security researchers uncover a serious zero-day flaw in Mitel's MiCollab collaboration suite that could expose sensitive organizational data. Over 16,000 exposed instances are at risk until patches arrive in December 2024.