DeadLock ransomware uses blockchain to shrug off takedowns
Ransomware groups have spent years moving their leak sites around the internet, hopping from domain to domain as takedowns land. DeadLock tries to remove the weak point entirely. It spreads its command structure across a blockchain, so there is no single server for police to seize and no domain name to sinkhole. How it stays […]
Critical LoadMaster Command Injection Is Under Active Attack, Patch Now
If you run Progress LoadMaster (or the Kemp-branded versions of it), this is a patch-this-week story, not a note-for-later story. CISA has confirmed that a critical command injection vulnerability in the load balancer is being actively exploited in the wild, and the agency has added it to the Known Exploited Vulnerabilities catalog. That KEV listing […]
Metabase SQL injection zero-day is being exploited for data theft
A critical Metabase vulnerability is being actively exploited in the wild to steal customer data, and at least two well-known companies have already confirmed they were hit. Framework Computer and the accounting platform Tally both disclosed breaches tied to the flaw, which is an unauthenticated SQL injection in Metabase versions 1.58 and newer. If you […]
TONTOU CPU Attack Bypasses Spectre v2 Fixes and Leaks Kernel Secrets
Eight years after Spectre upended assumptions about CPU security, a new attack from MIT CSAIL shows the mitigations we built to contain it still have holes. TONTOU, short for time-of-neutralization to time-of-use, bypasses Spectre v2 defenses on AMD and Intel CPUs and has been demonstrated leaking Linux password hashes straight out of kernel memory. It […]
Kremlin Hackers Exploit Max-Severity Exchange Flaw to Backdoor Unpatched Networks
Russian state hackers are actively exploiting a maximum-severity flaw in Microsoft Exchange Server to backdoor unpatched networks, according to Proofpoint researchers. The attacks are notable less for the vulnerability itself and more for what happens when it is triggered: opening an email is enough to get you compromised, and the resulting backdoor survives both credential […]
Hermes AI Agent Weaponized in Thai Finance Ministry Cyberattack
Attackers used the Hermes AI agent to automate post-exploitation activities against Thailand’s Ministry of Finance, marking one of the first documented cases of an AI agent being weaponized in a real-world state-targeted cyberattack. Security researchers at Hunt.io discovered the artifacts on a compromised C2 server. The operator installed Hermes Agent (by Nous Research), switched off […]