News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Lotus Malware Targets Venezuelan Energy Sector
Malware

Lotus Malware Targets Venezuelan Energy Sector

A new type of malware known as Lotus has been identified as a data-wiping tool used in attacks against energy and utility companies in Venezuela. This malware, which had not been documented previously, was deployed to disrupt operations within these critical infrastructure sectors last year. The attacks highlight ongoing cybersecurity threats targeting essential services, emphasizing the need for robust protection measures against similar incidents. Organizations globally, including in India, should remain vigilant to such evolving cyber threats that can impact their data security.

via BleepingComputerRead source
SystemBC Malware Exposes Over 1,570 Victims of Ransomware Operation
Ransomware

SystemBC Malware Exposes Over 1,570 Victims of Ransomware Operation

Research by Check Point has revealed that the SystemBC command-and-control server is associated with over 1,570 victims of The Gentlemen ransomware operation. The Gentlemen operates as a ransomware-as-a-service (RaaS) model, which allows attackers to deploy ransomware by utilizing various tools, including the known proxy malware SystemBC. This malware is particularly notable for establishing SOCKS5 network tunnels, which facilitate further malicious activities. The discovery raises concerns about the scale and impact of ransomware operations, demonstrating the ongoing threat to individuals and organizations. Cybersecurity awareness is essential in combating such risks. Source: Check Point.

via The Hacker NewsRead source
22 Vulnerabilities Found in Lantronix and Silex Converters
Data Breaches

22 Vulnerabilities Found in Lantronix and Silex Converters

Researchers from Forescout Research Vedere Labs have discovered 22 vulnerabilities in serial-to-IP converters made by Lantronix and Silex. These flaws could potentially allow cybercriminals to take control of devices and interfere with data transmissions. Nearly 20,000 Serial-to-Ethernet converters are at risk due to these vulnerabilities, which have been collectively named BRIDGE:BREAK. Users of these devices should be aware of the risks associated with these vulnerabilities and consider implementing security measures to protect against possible exploits. Keeping firmware updated is advisable for enhanced security. Source: [publication name].

via The Hacker NewsRead source
Exploitation of Bomgar RMM Flaw Highlights Supply Chain Vulnerabilities
Ransomware

Exploitation of Bomgar RMM Flaw Highlights Supply Chain Vulnerabilities

A significant security vulnerability identified as CVE-2026-1731 in the Bomgar remote monitoring and management (RMM) tool poses a serious risk. This flaw can allow cybercriminals to execute remote code, potentially enabling them to deploy ransomware and compromise supply chains. Organizations using this tool need to be aware of these risks and ensure they have proper security measures in place. Continuous monitoring and prompt updates can help mitigate the dangers associated with such vulnerabilities.

via Dark ReadingRead source
Google Addresses Important Vulnerability in AI Tool
Malware

Google Addresses Important Vulnerability in AI Tool

Google has resolved a significant security vulnerability in its AI-based Antigravity tool, which is used for filesystem operations. This flaw was related to prompt injection, allowing attackers to bypass security measures and execute arbitrary code, potentially leading to a sandbox escape. The company has implemented fixes to enhance the product's security and protect users from potential threats. It is essential for users of such technologies to stay updated and apply necessary security measures to safeguard their systems. Regular updates are critical for maintaining cybersecurity in advanced tools. Source: [publication name].

via Dark ReadingRead source
British Cybercriminal Pleads Guilty to Fraud and Identity Theft
Phishing

British Cybercriminal Pleads Guilty to Fraud and Identity Theft

A 24-year-old British man, Tyler Robert Buchanan, has admitted guilt in a court for his involvement with the cybercrime group 'Scattered Spider.' Charged with wire fraud conspiracy and aggravated identity theft, he acknowledged participating in text-message phishing attacks during the summer of 2022. These attacks enabled the group to infiltrate at least twelve prominent technology companies, resulting in the theft of tens of millions of dollars in cryptocurrency from investors. This case highlights ongoing issues with cybercrime and the tactics used to exploit individuals and organizations. Source: [publication name].

via Krebs on SecurityRead source
Ransomware Negotiator Admits Role in BlackCat Attacks
Ransomware

Ransomware Negotiator Admits Role in BlackCat Attacks

A ransomware negotiator from Florida, Angelo Martino, has admitted to his involvement in ransomware attacks targeting U.S. companies in 2023. He began working with the BlackCat ransomware group in April 2023, helping them negotiate higher ransom payments. Martino, who is 41 years old, communicated with multiple companies as part of his role in these cybercrimes. His plea highlights ongoing challenges in combating ransomware and underscores the importance of cybersecurity measures for businesses worldwide. This case illustrates the growing sophistication of cybercriminal networks and the involvement of various individuals in facilitating these attacks. Source: [publication name].

via The Hacker NewsRead source
Effective Fraud Prevention During Customer Interactions
Identity Theft

Effective Fraud Prevention During Customer Interactions

A recent discussion highlighted that preventing fraud does not need to compromise user experience. IPQS emphasizes the importance of integrating various signals, such as identity, device, and network information, to effectively combat fraud while maintaining ease of access for consumers. By leveraging these techniques, businesses can better secure transactions without imposing additional barriers on genuine users. This approach aims to enhance overall customer satisfaction while effectively minimizing fraudulent activities. As the digital landscape evolves, improving safety in online transactions becomes increasingly critical for both businesses and customers. Source: [publication name].

via BleepingComputerRead source
Improving MTTR: Key Strategies for Effective Security Operations Centers
Cyber Law (India)

Improving MTTR: Key Strategies for Effective Security Operations Centers

In the realm of cybersecurity, Mean Time to Recovery (MTTR) is a vital metric for measuring how quickly a security team responds to threats. For organizational leaders, each moment a threat exists poses risks of data theft, service interruptions, and harm to the company's reputation. Interestingly, slow MTTR often isn't due to a shortage of analysts but rather structural issues within the team, particularly regarding the effectiveness of threat intelligence. Establishing a robust threat intelligence framework is crucial for expediting response times and ensuring better protection against cyber threats. Organizations should focus on optimizing their security operations to enhance responsiveness and minimize potential damages. Source: [publication name].

via The Hacker NewsRead source
CISA Warns of New Vulnerability in SD-WAN Systems Being Exploited
Malware

CISA Warns of New Vulnerability in SD-WAN Systems Being Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has identified a new vulnerability in the Catalyst SD-WAN Manager that is currently being exploited in cyberattacks. As a result, U.S. federal agencies have been given a tight deadline of four days to implement security measures to safeguard their systems. Organizations using similar technologies should remain vigilant and ensure they apply necessary updates to prevent potential intrusions. Awareness and quick action are key to protecting sensitive data from these emerging threats. Source: [publication name].

via BleepingComputerRead source
KelpDAO Faces $290 Million Crypto Theft Linked to North Korean Hackers
Crypto Scams

KelpDAO Faces $290 Million Crypto Theft Linked to North Korean Hackers

KelpDAO, a decentralized finance platform, has reportedly fallen victim to a major theft amounting to $290 million. The incident, which took place recently, is believed to be the work of Lazarus Group, a hacking collective tied to the North Korean government. This heist marks a significant event in the cryptocurrency space, highlighting ongoing security concerns in decentralized finance. As the investigation unfolds, it draws attention to the increasing sophistication and frequency of cyberattacks targeting crypto projects. Users are advised to remain vigilant and cautious with their assets in light of such incidents.

via BleepingComputerRead source
Data Breach at Vercel Triggered by AI Tool Access
Data Breaches

Data Breach at Vercel Triggered by AI Tool Access

A recent incident at Vercel involved a data breach linked to the misuse of AI tools by an employee. The breach occurred due to stolen OAuth tokens, which have become increasingly common in cyberattacks. These tokens allow unauthorized access and can lead to further security vulnerabilities. Experts highlight that stolen tokens represent a significant risk as they can be exploited for lateral movement within systems. Firms are urged to enhance their security measures to safeguard sensitive information against such attacks. This incident underscores the importance of addressing potential vulnerabilities associated with emerging technologies. Source: [publication name].

via Dark ReadingRead source