Personally identifiable information (PII), financial data, medical records, account credentials, and intellectual property all require strict access controls to prevent unauthorized exposure. Unfortunately, mobile applications commonly used in both personal and professional settings can compromise this data, even when users believe they are following best security practices. As mobile devices have become central to business operations, especially with widespread bring-your-own-device (BYOD) policies, they are increasingly serving as primary access points for digital services, they have also become a significant attack surface for data leaks and breaches. To investigate the risks associated with mobile applications, zLabs, the research team at Zimperium,…
Kirsten Doyle
Two senators have introduced a bipartisan bill to extend key cybersecurity protections that encourage businesses to share threat information with the federal government. The bill would renew provisions first signed into law under the Cybersecurity Information Sharing Act of 2015. Introduced by U.S. Senators Gary Peters (D-MI), Ranking Member of the Homeland Security and Governmental Affairs Committee, and Mike Rounds (R-SD), the bill incentivizes companies to voluntarily share cybersecurity threat indicators—like software vulnerabilities, malware, and malicious IP addresses—with the Department of Homeland Security (DHS). Protecting Americans’ Personal Data The goal is to better protect Americans’ personal data and strengthen collaboration…
The controversial internet forum 4chan appears to have been hacked, according to multiple online reports. Alleged leaks suggest that a hacker gained access to backend infrastructure and exposed personal details of the site’s moderators. The breach first came to light when a previously inactive section of 4chan suddenly reappeared, displaying a bold message: “U GOT HACKED,” as reported by by Wired. Cybersecurity experts, including Alon Gal, co-founder of Hudson Rock, have said the breach “looks legit,” citing widely shared screenshots that purportedly show internal systems. Adding weight to the claims, TechCrunch spoke with an unnamed 4chan moderator who stated there…
After operating quietly for a year, a Chinese state-sponsored hacking group known as UNC5174 has launched a new cyber campaign, according to the Sysdig Threat Research Team (TRT). Sysdig researchers uncovered the campaign in late January 2025 when they spotted a malicious bash script downloading several files to maintain access on targeted systems. One of these files was a variant of the group’s known malware, SNOWLIGHT, which has been previously used in attacks on F5 devices and was recently mentioned in France’s 2025 Cyber Threat Overview report. In a new twist, UNC5174 is now using an open-source tool called VShell—a…
A sophisticated campaign that pre-installs malware onto budget Android smartphones, targeting cryptocurrency users through a technique known as “clipping” has been discovered by Doctor Web’s virus lab. Its findings reveal that malefactors have embedded a trojanized version of WhatsApp directly into the system partition of newly manufactured devices, exposing users to stealthy financial theft from the moment they activate their phones. Starting in June 2024, Dr Web began receiving reports from users who installed its Security Space antivirus on new Android devices. Investigations confirmed that these phones — usually sold under names resembling popular brands like “S23 Ultra,” “Note 13…
Towards the end of March, OpenAI debuted image generation features for its ChatGPT-4o and ChatGPT-4o mini models. Less than a week later, the tool was made available for free to all users, and since then, users have reported that the feature can be used to create convincing fake documents—including receipts and passports. According to the 2025 Cato CTRL Threat Report, generative AI (GenAI) tools like ChatGPT are lowering the barrier to entry for malicious actors. The report highlights the growing threat of so-called “zero-knowledge threat actors”—people with no technical expertise who are now able to carry out advanced fraud using…
The Office of the Comptroller of the Currency (OCC) has alerted Congress to a “major information security incident” following unauthorized access to its email systems, including messages containing sensitive financial data. The breach was discovered on 11 February 2025, and confirmed the following day. According to the OCC, the incident involved unusual activity by a system administrator account accessing user mailboxes without authorization. Once detected, the OCC shut down the compromised accounts and activated its incident response protocols. The breach was reported to the Cybersecurity and Infrastructure Security Agency and publicly disclosed on 26 February. The investigation, involving internal teams…
APT29—also known as “Cozy Bear,” a notorious threat actor linked to Russia’s Foreign Intelligence Service (SVR)—has launched a new phishing campaign aimed at European diplomatic missions. This was revealed in a new report from Check Point Research. This latest campaign marks a continuation of the group’s long-running cyber espionage activities, with signs of both increased sophistication and strategic targeting. Phishing Lures Masquerade as Diplomatic Event Invitations The phishing attacks, which started in January this year, use cunning email lures pretending to be invitations to exclusive diplomatic events. One example included an invitation to a wine-tasting evening, purportedly sent by a…
In a bold and unconventional move, cybersecurity intelligence firm Prodaft has debuted a new initiative called “Sell Your Source” (SYS) aimed at acquiring aged, verified accounts from underground hacking forums. The goal is to gain covert access to adversarial networks and uncover malicious operations from within. Through this initiative, Prodaft is offering to buy accounts created before December 2022—as long as they haven’t been used for cybercrime or unethical activity. These accounts, once vetted and verified, will serve as human intelligence (HUMINT) assets for the firm’s threat intelligence efforts. “We want to ensure our coverage does not hit any limitations,”…
Fortinet discovered a new technique used by threat actors to maintain access to FortiGate devices, even after known vulnerabilities were patched. The company has since taken action to notify affected customers and provide mitigation guidance. What Happened? Fortinet’s internal security team found that malicious actors were exploiting known vulnerabilities—specifically FG-IR-22-398, FG-IR-23-097, and FG-IR-24-015—to gain access to devices. While targeting unpatched systems is not new, Fortinet observed a novel post-exploitation method that allowed bad actors to maintain read-only access to FortiGate systems even once the initial vulnerabilities were addressed. The attackers created a symbolic link—a kind of shortcut—that connected the user…
