North Korean WaterPlum Hackers Infiltrate 30,000 Devices Worldwide
The North Korean group WaterPlum compromised over 30,000 devices worldwide, stealing more than $10.7 million in cryptocurrency between December 2025 and July 2026.
Tag
10 results in the archive.
The North Korean group WaterPlum compromised over 30,000 devices worldwide, stealing more than $10.7 million in cryptocurrency between December 2025 and July 2026.
US, UK, and Dutch agencies report Iran's intelligence uses Windows malware controlled via Telegram to spy on dissidents and journalists globally, targeting sensitive communications and recordings.
CISA has listed CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway, as actively exploited and requires urgent remediation by federal agencies.
Microsoft Threat Intelligence reports attacks on AI workloads targeting gateways such as LiteLLM, focusing on credential harvesting, persistence, and cryptomining risks in AI infrastructure.
CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
SilkParasite, a newly uncovered cyber espionage campaign, targets Central Asian government bodies using seven remote access tools, five of which are previously undocumented, highlighting evolving advanced threats in the region.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched just three days ago is now actively exploited, posing a critical security risk.
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics, revealing increased sophistication in leveraging cloud-based AI for malicious activities.
Microsoft Threat Intelligence uncovered ShinyHunters abusing OAuth in SaaS applications through vishing, supply chain attacks, and guest access misconfigurations, exposing new SaaS security risks.
Progress Software advises ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat, disabling account access as a precaution.