Google has issued an urgent security alert addressing two critical Android vulnerabilities, CVE-2024-43093 and CVE-2024-50302, which are actively being exploited in coordinated attacks targeting devices running Android versions 12 through 15. The vulnerabilities, patched in the March 2025 Android Security Bulletin (security patch level 2025-03-05), could allow malicious actors to bypass lock screens, escalate privileges, and execute remote code. Details of the Vulnerabilities CVE-2024-43093: System Component Privilege Escalation: This vulnerability, with a CVSS score of 7.8, allows malicious applications to bypass Android’s sandboxing through improper validation of inter-process communication (IPC) messages. Attackers can exploit weak permission checks in the System…
Kirsten Doyle
A major Microsoft outage on 1 March left tens of thousands unable to access key services like Outlook, Teams, and Office 365 for over three hours. Microsoft has not fully explained the cause but blamed a “problematic code change.” Timeline of the Outage Downdetector data shows issues began around 3:30 p.m. ET, with over 37,000 complaints for Outlook, 24,000 for Office 365, and 150 for Teams. Most reports came from U.S. cities like New York, Chicago, and Los Angeles, though users worldwide also experienced disruptions. Frustrated users took to social media, with some initially fearing a hack. Microsoft acknowledged the…
The Splunk Threat Research Team has uncovered a widespread cyber campaign targeting Internet Service Provider (ISP) infrastructure providers on the West Coast of the United States and in China. Over 4,000 ISP-related IPs were explicitly targeted in this campaign. The attack, believed to have originated from Eastern Europe, uses brute-force tactics to exploit weak credentials. It deploys crypto-mining payloads and info-stealing binaries across compromised networks. Multiple Attack Techniques The observed cyber operation employs multiple attack techniques, including: According to Splunk researchers, the perpetrators are stealthy, operating with minimal intrusion, using scripting languages such as Python and PowerShell—tools that allow them…
A new cyber espionage campaign has been uncovered targeting a select group of entities in the United Arab Emirates (UAE), focusing on aviation, satellite communications, and critical transportation infrastructure. The attack, identified by Proofpoint researchers, used advanced obfuscation techniques and a newly discovered backdoor dubbed Sosano, developed using the Go programming language. The campaign, attributed to an emerging threat cluster labeled UNK_CraftyCamel, used a compromised Indian electronics company to distribute malware-laden emails. These emails, highly tailored to each target, originated from what appeared to be a trusted business relationship, making them particularly effective. Sophisticated Infection Chain The attack, first observed…
Defense Secretary Pete Hegseth has ordered U.S. Cyber Command to halt all planning against Russia, including offensive digital operations, The Record reports. The directive, issued towards the end of last week to Cyber Command chief General Timothy Haugh, heralds a major shift in U.S. cyber strategy toward Moscow. The order, which was subsequently relayed to the outgoing director of operations, Marine Corps Major General Ryan Heritage, does not extend to the National Security Agency (NSA) or its signals intelligence activities targeting Russia, sources said. However, the full extent of Hegseth’s directive remains unclear. Policy Shift and Diplomatic Implications Hegseth’s decision…
Notorious ransomware gang Qilin has claimed responsibility for the 3 February attack on Lee Enterprises, an American media company. On its data leak site, Qilin claimed to have stolen 350 GB of data, including “investor records, financial arrangements that raise questions, payments to journalists and publishers, funding for tailored news stories, and approaches to obtaining insider information.” The attack disrupted many of the entity’s more than 70 newspapers and other publications, affecting operations, including distribution of products, billing, collections, and vendor payments. In addition, the distribution of print publications across its portfolio of products experienced delays, and online operations were…
Microsoft has amended recent civil litigation to name key developers of malicious tools designed to bypass AI safeguards, including those in Azure OpenAI Service. The legal action targets four individuals—Arian Yadegarnia (Iran), Alan Krysiak (UK), Ricky Yuen (Hong Kong), and Phát Phùng Tấn (Vietnam)—who are part of a global cybercrime group, Storm-2139. These actors exploited stolen credentials to access AI services, modify their capabilities, and resell access to malicious actors, enabling the creation of harmful content such as non-consensual intimate images. Generating Illicit Content Storm-2139 operates through three tiers: creators develop illicit tools, providers distribute them, and users generate violating…
The Cleveland Municipal Court, including Cleveland Housing Court, will remain closed today, one week after it was hit by a cyber event. On its Facebook page on 24 February, it said it is currently investigating a cyber incident. Although it has not confirmed its nature and scope, it said it is taking this incident seriously. The court was closed all last week, and according to Mike Negray, Deputy Court Administrator at Cleveland Municipal Court, it will remain closed on Monday except for jail cases. “As a precautionary measure, the Court has shut down the affected systems while we focus on…
Check Point Research (CPR) has uncovered a sophisticated cyber campaign leveraging a vulnerable Windows driver to disable security protections, evade detection, and deploy malicious payloads. They identified a large-scale, ongoing attack campaign that abuses a legacy version of the Truesight.sys driver to disable endpoint detection and response (EDR) and antivirus (AV) solutions. The attack, which has been active since at least June last year, has already produced more than 2,500 modified variants of the vulnerable driver, enabling attackers to bypass modern security mechanisms. Exploiting a Security Loophole CPR’s investigation revealed that the threat actors exploited the legacy version 2.0.2 of…
Windows CE, a decades-old operating system originally designed for embedded systems, remains a crucial component of industrial control systems (ICS) and supervisory control and data acquisition (SCADA) environments. However, despite its widespread use in human-machine interfaces (HMI), kiosks, and even vehicle infotainment systems, its legacy nature presents significant cybersecurity risks. Recent research from Claroty has looked into Windows CE vulnerabilities, uncovering security gaps that could expose industrial and medical infrastructure to cyber threats. In fact, when they examined an HMI panel using Windows CE, they found several potential dangers and vulnerabilities that could be exploited by bad actors. Outdated, Unsupported …
