Proving there are no depths they won’t plum, cybercriminals have begun exploiting the news of Pope Francis’s passing in a range of malicious campaigns. This tactic has been popular for some time. Bad actors are the first to jump on the bandwagon during major world events—from global disasters to the deaths of famous people. From disinformation and scams, to malware, there is no tragedy they won’t take advantage of. According to Check Point Research, “They typically begin with disinformation campaigns on social media platforms like Instagram, TikTok, or Facebook, uploading fake images generated by AI.” These campaigns aim to grab…
Kirsten Doyle
A critical security vulnerability has been discovered in the Commvault Command Center, that could enable malicious actors to remotely to execute arbitrary code without authentication,” Commvault said in an advisory. “This vulnerability could lead to a complete compromise of the Command Center environment. Fortunately, other installations within the same system are not affected by this vulnerability,” the advisory added. The vulnerability, tracked as CVE-2025-34028, carries a CVSS score of 10.0 – the highest possible. A researcher from watchTowr Labs, Sonny Macdonald, is credited with discovering and reporting the flaw on 7 April. He said it could be exploited to achieve…
At this year’s RSA Conference, the theme “Many Voices. One Community” is a reminder that cybersecurity isn’t just about technology—it’s about people. In a field driven by constant innovation and rapid response, the strength of our defenses often depends on the breadth of perspectives behind them. We asked our panel of cybersecurity experts two key questions: Is the community doing enough to elevate individual voices and welcome diverse perspectives? And how can we create more space for those who aren’t always heard? Their candid responses highlight both the progress we’ve made—and the opportunities still ahead. Identifying Gaps in Security Cybersecurity…
ReliaQuest has uncovered a serious vulnerability in SAP NetWeaver, a popular software platform used by many businesses around the world. In April 2025, the company investigated several customer incidents involving SAP NetWeaver, a technology integration platform. Bad actors were able to upload unauthorized files and run malicious programs. ReliaQuest found that attackers had placed “JSP webshells” into public directories, similar to what happens with a remote file inclusion (RFI) vulnerability. Notably, many of the affected systems were already up-to-date with the latest SAP service packs and patches. This, said ReliaQuest, posed the questions, if attackers were exploiting an old vulnerability…
In 2024 alone, the FBI’s Internet Crime Complaint Center (IC3) received a staggering 859,532 complaints, with reported losses surging to an all-time high of $16.6 billion—a 33% increase over 2023. Of those complaints, more than 256,000 involved actual financial losses, with an average loss of $19,372 per incident. These were some of the findings from the IC3’s 2024 Internet Crime Report—the agency’s 25th report that tracks cyber-enabled crime across the US. Its message is clear: online crime is more pervasive, more damaging, and more sophisticated than ever before. “The criminals Americans face today may look different than in years past,…
CISA has published five advisories alerting of critical vulnerabilities in Industrial Control Systems (ICS) manufactured by Siemens, Schneider Electric, and ABB. The advisories detail high-severity flaws that could enable malicious actors to access sensitive systems, disrupt industrial operations, or execute malicious code Firstly, CISA warns that multiple SQL injection vulnerabilities have been discovered in Siemens’ TeleControl Server Basic SQL, with the potential to grant attackers unauthorized database access and code execution capabilities. Affected internal methods include: Each vulnerability could allow bad actors to bypass authorization mechanisms and manipulate backend databases, threatening the integrity of industrial systems. Another advisory details a…
Marks & Spencer (M&S) has confirmed it is managing a cyber incident that has caused minor disruptions to its store operations in the last few days. Despite the security breach, the British retailer reassured customers that all stores remain open and that its website and mobile app are operating as normal. In a statement released today, M&S said: “As soon as we became aware of the incident, it was necessary to make some minor, temporary changes to our store operations to protect customers and the business and we are sorry for any inconvenience experienced. Importantly, our stores remain open and…
A ransomware group called Sarcoma has claimed responsibility for a cyberattack on Manchester Credit Union (MCU) in the UK. The credit union reported technical issues with its payment system earlier this month but described the incident as a “failed ransomware attack,” saying no customer data was compromised. Although MCU said no ransom demand was received, Sarcoma has listed the firm on its leak site and threatened to auction stolen data if payment isn’t made. The bad actors wiped some servers, causing two days of downtime for 21 employees, complicating forensic investigations. Sarcoma, active since October 2024, has been linked to…
At a time when cyber threats are escalating at unprecedented rates, a new warning has emerged for businesses and government entities: networks may be exposing organizations to more danger than they realize. Lawrence Pingree, Vice President at Dispersive and former security lead at Gartner, has published “Your Network Is Showing — Time to Go Stealth,” an in-depth look at how cyberattacks have evolved beyond the perimeter. Pingree points out that malicious actors are no longer simply trying to bypass defenses — they’re now executing coordinated campaigns that target the defenses themselves. Firewalls, VPNs, and control planes, once the cornerstone of…
Researchers at Trustwave have uncovered a surge in malicious online activity traced to IP addresses belonging to a Russian bulletproof hosting provider dubbed Proton66. Since 8 January this year, Trustwave’s SpiderLabs researchers have seen a steep increase in mass scanning, credential brute-forcing, and exploitation attempts targeting organizations around the world. The detailed findings, including technical indicators of compromise and deeper forensic analysis, can be found here (Part 1) and here (Part 2). Both look at Proton66’s role in hosting malicious infrastructure used for launching widespread cyberattacks. According to Trustwave, Proton66 is linked to another Russian autonomous system named PROSPERO. This…
