China-Linked Threat Group Targets Japanese Orgs' Servers
Winnti once used a variety of malware but is now focused on SQL vulnerabilities and obfuscation, updated encryption, and new evasion methods to gain access.
Microsoft: New Variant of macOS Threat XCSSET Spotted in the Wild
Microsoft is warning the modular and potentially wormable Apple-focused infostealer boasts new capabilities for obfuscation, persistence, and infection, and could lead to a supply chain attack.
Chase to decline social media-directed Zelle payments
Chase Bank customers sending Zelle payments may be sought to provide details, including payment purpose and means of contact with recipients, said the bank in an updated user policy.
Funding round secures $100M for AI cybersecurity startup Dream
Such newly raised funds would be channeled toward creating more advanced AI models for defending critical infrastructure and bolstering its current models, while opening new offices in the U.S. and South America, according to Dream, which was co...
Severe supply chain flaw impacting newly acquired firm nets over $50K reward
Evaluation of the firm's online resources led to the identification of a DockerHub organization containing a Docker image that not only contained the company's backend systems source code but also a .git folder with a GitHub Actions authorization...
Authentication credential compromise likely with Xerox VersaLink printer flaws
Threat actors with configuration page access to VersaLink printers with proper Lightweight Directory Access Protocol settings could enable IP address alterations and clear-text LDAP service credential compromise, according to Rapid7 researchers.
Privacy concerns prompt South Korean suspension of DeepSeek
"This temporary suspension of the DeepSeek app restricts new app downloads from the app market, and we ask existing users to use it cautiously, such as not entering personal information in the DeepSeek input window (prompt) until the final results...