U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no sign that it ever locked a single
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
“The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer accounts,
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and other devices built on
New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
Bad Epoll sits in the same small stretch of kernel code where Anthropic’s most powerful AI model, Mythos, recently found a different bug.
The AI caught one flaw and missed
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one
NetNut proxy network disrupted, 2 million infected devices cut off
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic the legitimate “rollup-plugin-polyfill-node” project, down to the description, repository metadata, and
In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
Noteworthy stories that might have slipped under the radar: Anonymous-linked Canadian hacker jailed, researcher drops zero-days in open source projects, Venezuelans sentenced in the US over ATM jackpotting.
The post In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting appeared first on SecurityWeek.
