APT Groups Exploit Gaming Platforms and Debug APIs in Multi Vector Cyber Campaigns

North Korea's ScarCruft group uses a gaming platform to deploy BirdCall malware, while critical RCE flaws in Apache HTTP/2, MetInfo CMS, and Weaver E-cology are actively exploited alongside a DAEMON Tools supply chain attack.

The Latest

Breaking News and Alerts

Bluekit Phishing Platform Bundles Domain Automation, 2FA Circumvention, and Session Hijack Tools

Varonis researchers found that Bluekit's centralized dashboard captures session tokens and cookies after victims complete 2FA, rendering that security measure ineffective.

Spotlight

Cybersecurity Profiles and Stories

AI Driven Zero Day Discovery Now Automates Attacks at Machine Speed

Attackers now use AI models to discover and exploit zero day vulnerabilities in minutes, with documented campaigns like GAMECHANGE showing LLMs orchestrating espionage in real time.

MOVEit Automation Patches Critical Backend Flaws Allowing Full Server Takeover

Two critical MOVEit Automation vulnerabilities discovered by Airbus SecLab researchers allow unauthenticated attackers to bypass authentication and escalate privileges to full administrative control.

Rogue DHCP Server Attack Can Fully Compromise FreeBSD Systems

The flaw allows attackers on the same local network to inject commands into the dhclient configuration file through unescaped double quotes in BOOTP responses.

Mass Email Floods Precede Fake Teams IT Support in New Wave of Breaches

Security researchers warn that email bombing, which triggers panic, is the entry point for fake IT support calls that achieve a 72 percent success rate.

Features

Research and Thought Leadership