Over the last few weeks, an emerging and rapidly growing ransomware-as-a-service (RaaS) operation dubbed VanHelsingRaaS has been attracting attention in the cybercrime world. Check Point Research has discovered two variants of this scourge, targeting Windows, but in its advert, VanHelsingRaas says it offers tools “targeting Linux, BSD, ARM, and ESXi systems”. Mirroring legitimate tools, the program offers an intuitive control panel that makes operating ransomware attacks child’s play. The two variants Check Point Research obtained were compiled only five days apart, with the latest version featuring significant updates—a sign of how quickly this ransomware is evolving. Debuted on 7 March,…
Kirsten Doyle
Once widespread for facilitating deeper customization and removing OS limitations on mobile devices, rooting and jailbreaking, are becoming primarily the domain of power users, as manufacturers have made giant leaps to limit this practice via two different approaches. Firstly, by adding additional customization options to prevent users from feeling restricted, and secondly, by introducing more stringent security protocols into stock Android and iOS versions. However, despite a drop in the number of rooted and jailbroken devices in general, they still represent a very dire security threat, not to the user alone, but to entities who allow staff members to access…
Elastic Security Labs has observed a financially motivated campaign delivering Medusa ransomware via a HEARTCRYPT-packed loader. This loader is deployed alongside a driver, signed with a revoked certificate from a Chinese vendor, which Elastic has named ABYSSWORKER. Once installed on the victim’s machine, the driver is used to disable various EDR solutions. This EDR-disrupting driver was previously reported by ConnectWise in a separate campaign, where it utilized a different certificate and IO control codes, and some of its functionalities were analyzed at that time. According to Elastic Security Labs, “Cybercriminals are increasingly bringing their own drivers — either exploiting a…
The danger to cryptography posed by next-generation large-scale, fault-tolerant quantum computers is widely understood. Although current encryption methods, which are used to secure everything from banking to communications, are based on mathematical algorithms that the everyday PC is unable to crack, a new era of incredibly fast quantum computers is just a few years away, poised to revolutionize problem-solving, communication, and computation. Modern cryptography relies on algorithms specifically designed to be as difficult to break as possible. For instance, today’s public key algorithms—such as RSA, Diffie-Hellman, and Elliptic Curve—are used to help communicating parties establish cryptographic keys or to generate…
California Cryobank (CCB), one of the world’s largest reproductive tissue banks, has begun informing consumers about a data breach impacting an unspecified number of individuals. The biotechnology company reported detecting unauthorized activity on certain computers on 21 April last year, and subsequently isolated them from its IT network. Protecting Data Confidentiality In a statement, the company said it is committed to protecting the confidentiality and security of the information it maintains. “CCB recently completed our investigation of an incident that involved unauthorized activity on certain computers in our information technology (“IT”) environment. Upon identifying the activity, it said it isolated…
A highly advanced zero-day vulnerability has been covertly exploited for years by multiple state-sponsored hacking groups, underscoring its severe security risks. This flaw leverages Windows shortcut (.lnk) files, enabling attackers to stealthily execute malicious commands without detection. However, Microsoft tagged it as “not meeting the bar servicing” in late September and said it wouldn’t release security updates to address it. While Microsoft has yet to assign a CVE-ID to this vulnerability, Trend Micro is tracking it internally as ZDI-CAN-25373 and said it enables bad actors to execute arbitrary code on affected Windows systems. Trend Micro’s experts have linked the…
Western Alliance Bank has announced a data breach affecting 21,899 people, that was caused by an October 2024 cyberattack on a third-party file transfer software. The breach exposed sensitive personal and financial information, including names, Social Security numbers, driver’s license details, and financial account numbers. The bank said the malicious actors exploited a zero-day vulnerability in the third-party software to breach a limited number of Western Alliance systems and exfiltrate files stored on the compromised devices. Western Alliance found that customer data was exfiltrated from its network only after discovering that the attackers leaked some files stolen from its systems. The breach happened on 12…
A newly discovered remote code execution (RCE) vulnerability, CVE-2025-24813, is actively being exploited, putting Apache Tomcat servers at risk—malicious actors need but a single PUT API request to gain full control over vulnerable systems. The exploit was initially published by a Chinese forum user, iSee857, with a proof-of-concept (PoC) code now readily available online. How a Simple PUT Request Leads to Full RCE The attack takes advantage of Tomcat’s default session persistence mechanism and its support for partial PUT requests. Wallarm says it follows a straightforward two-step process: Step 1: Uploading a Malicious Serialized Session According to Wallarm: “The attacker…
Security researchers at Guardz have warned of new malicious campaigns that abuse Microsoft 365 for phishing , or target the service’s users to take over their accounts. As part of one campaign, malicious actors are leveraging legitimate Microsoft domains and tenant misconfigurations in BEC attacks likely aimed at stealing credentials and performing account takeover (ATO). According to the researchers, this attack exploits genuine Microsoft services to fashion a trusted delivery mechanism for phishing content, making it tricky for technical controls and security practitioners to detect. Operating Within Microsoft’s Ecosystem Unlike conventional phishing, which depends on fake domains crafted to appear…
A major security flaw has been found in RSA encryption keys used across the internet. Researchers discovered that about one in 172 online certificates are at risk due to a mathematical weakness. The issue mainly affects Internet of Things (IoT) devices but could impact any system using improperly generated RSA keys, arising from poor random number generation during key creation, particularly in devices with limited entropy sources. If RSA keys lack enough randomness, they could share prime factors with other keys, making them easy to break using a factorization attack. Factorization Attacks This type of attack takes advantage of a…
