The Cleveland Municipal Court, including Cleveland Housing Court, will remain closed today, one week after it was hit by a cyber event. On its Facebook page on 24 February, it said it is currently investigating a cyber incident. Although it has not confirmed its nature and scope, it said it is taking this incident seriously. The court was closed all last week, and according to Mike Negray, Deputy Court Administrator at Cleveland Municipal Court, it will remain closed on Monday except for jail cases. “As a precautionary measure, the Court has shut down the affected systems while we focus on…
Kirsten Doyle
Check Point Research (CPR) has uncovered a sophisticated cyber campaign leveraging a vulnerable Windows driver to disable security protections, evade detection, and deploy malicious payloads. They identified a large-scale, ongoing attack campaign that abuses a legacy version of the Truesight.sys driver to disable endpoint detection and response (EDR) and antivirus (AV) solutions. The attack, which has been active since at least June last year, has already produced more than 2,500 modified variants of the vulnerable driver, enabling attackers to bypass modern security mechanisms. Exploiting a Security Loophole CPR’s investigation revealed that the threat actors exploited the legacy version 2.0.2 of…
Windows CE, a decades-old operating system originally designed for embedded systems, remains a crucial component of industrial control systems (ICS) and supervisory control and data acquisition (SCADA) environments. However, despite its widespread use in human-machine interfaces (HMI), kiosks, and even vehicle infotainment systems, its legacy nature presents significant cybersecurity risks. Recent research from Claroty has looked into Windows CE vulnerabilities, uncovering security gaps that could expose industrial and medical infrastructure to cyber threats. In fact, when they examined an HMI panel using Windows CE, they found several potential dangers and vulnerabilities that could be exploited by bad actors. Outdated, Unsupported …
Researchers at Palo Alto Networks have identified a new Linux malware strain dubbed Auto-Color, which uses cunning, advanced stealth techniques to slip through the security nets and maintain persistence on compromised systems. The malware, first detected in early November last year, mainly targets universities and government offices across North America and Asia. Auto-Color hides its presence by using benign-sounding file names, such as door or egg, and uses an advanced method for hiding command and control (C2) connections—similar to the tactics used by the Symbiote malware family. It also uses proprietary encryption algorithms to obfuscate communication and configuration details. Once…
At a time when artificial intelligence (AI) is reshaping cybersecurity, conventional approaches to passwords and endpoint management are increasingly vulnerable. AI-powered threats are rapidly evolving, leveraging automation and deep learning to crack passwords, slip past authentication measures, and exploit weaknesses in endpoints at an unrivaled scale. Entities that once relied on static credentials and perimeter-based security now face a landscape where adaptive, AI-driven attacks demand equally intelligent defenses. As endpoint ecosystems expand—with remote work, cloud services, and IoT devices—attack surfaces grow, making it critical for businesses to rethink how they manage access and secure endpoints in real-time. To understand how…
Cybersecurity researchers at SentinelLABS have uncovered a new campaign linked to the long-running Ghostwriter operation, targeting Belarusian opposition activists and Ukrainian military and government entities. The campaign, which entered its active phase in late 2024, is ongoing, with recent malware samples and command-and-control (C2) activity indicating continued threats. A Persistent Espionage Operation Ghostwriter, an advanced persistent threat (APT) campaign with ties to Belarusian intelligence, has been active since at least 2016. Previously tracked by cybersecurity firms under the names UNC1151 (Mandiant) and UAC-0057 (CERT-UA), the campaign blends information manipulation with cyber intrusions. Over the years, it has targeted European countries…
The Trump administration is set to significantly weaken the CHIPS Act by terminating hundreds of employees at the National Institute of Standards and Technology (NIST), the agency responsible for administering the semiconductor incentive program. President Biden signed the bipartisan CHIPS and Science Act two years ago, investing $53 billion to boost US semiconductor supply chains, create jobs, and enhance national security. According to multiple sources, including Axios and Bloomberg, nearly 500 NIST employees, many of whom were recently hired to support the CHIPS Act, are expected to be dismissed under the pretext of “probationary” firings. Mass Firings Threaten CHIPS Act…
A botnet made up of more than 130,000 compromised devices is conducting large-scale password-spraying attacks against M365 accounts, exploiting non-interactive sign-ins with Basic Authentication. This method lets malicious actors bypass modern login protections, evade multi-factor authentication (MFA) enforcement, and remain undetected by security teams. Leveraging Purloined Credentials Malefactors are leveraging stolen credentials from infostealer logs to systematically target M365 accounts on a global scale. These attacks are recorded in Non-Interactive Sign-In logs, an area frequently overlooked by security teams. They exploit this gap to launch high-volume password spraying attempts without triggering security alerts. Non-interactive sign-ins are often used for service-to-service…
The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI) and the Multi-State Information Sharing and Analysis Center (MS-ISAC), has issued a joint Cybersecurity Advisory on Ghost (Cring) ransomware. The advisory, titled #StopRansomware: Ghost (Cring) Ransomware, provides network defenders with key indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods identified through FBI investigations. Ghost ransomware actors target firms with outdated software and firmware in their internet-facing services. The advisory warns that these bad actors exploit known vulnerabilities where patches have not been applied to gain unauthorized access. The identified Common…
Cisco Talos has been actively tracking reports of extensive intrusion attempts targeting multiple major U.S. telecommunications companies. First identified in late 2024 and subsequently confirmed by the US government, this activity is attributed to a highly advanced threat actor known as Salt Typhoon. According to public reports, Salt Typhoon successfully infiltrated core networking infrastructure in multiple instances, leveraging these systems to collect sensitive information. While one case suggested exploitation of a known Cisco vulnerability (CVE-2018-0171), Cisco Talos’ investigations indicate that most incidents stemmed from the use of legitimate victim login credentials rather than newly discovered vulnerabilities. The findings reveal that…
