Microsoft Warns of Tax-Themed Email Attacks Using PDFs and QR Codes to Deliver Malware
“These campaigns notably use redirection methods such as URL shorteners and QR codes contained in malicious attachments and abuse legitimate services like file-hosting services and business profile pages to avoid detection,” Microsoft said in a report shared with The
Chinese APT Pounces on Misdiagnosed RCE in Ivanti VPN AppliancesĀ
Ivanti misdiagnoses a remote code execution vulnerability and Mandiant reports that Chinese hackers are launching in-the-wild exploits.
The post Chinese APT Pounces on Misdiagnosed RCE in Ivanti VPN AppliancesĀ appeared first on SecurityWeek.
Halo ITSM Vulnerability Exposed Organizations to Remote Hacking
An unauthenticated SQL injection vulnerability in Halo ITSM could have been exploited to read, modify, or insert data.
The post Halo ITSM Vulnerability Exposed Organizations to Remote Hacking appeared first on SecurityWeek.
Texas State Bar warns of data breach after INC ransomware claims attack
Oracle privately confirms Cloud breach to customers
Recent GitHub supply chain attack traced to leaked SpotBugs token
Hunters International Ransomware Gang Rebranding, Shifting Focus
The notorious cybercrime group Hunters International is dropping ransomware to focus on data theft and extortion.
The post Hunters International Ransomware Gang Rebranding, Shifting Focus appeared first on SecurityWeek.
Lazarus Group Targets Job Seekers With ClickFix Tactic to Deploy GolangGhost Malware
The new activity, assessed to be a continuation of the campaign, has been codenamed ClickFake Interview by
Cybersecurity M&A Roundup: 23 Deals Announced in March 2025
Less than two dozen cybersecurity merger and acquisition (M&A) deals were announced in March 2025.
The post Cybersecurity M&A Roundup: 23 Deals Announced in March 2025 appeared first on SecurityWeek.
