Rust arrayref crate compromised to deliver infostealer malware: Hackers successfully compromised the maintainer account for the widely used arrayref Rust crate, introducing malicious code that executes on developers' machines during the compilation process. (Source: BleepingComputer)
Critical vulnerability in Elementor Pro allows RCE on WordPress sites: A major flaw in the popular Elementor Pro plugin enables attackers to upload executable files, potentially leading to remote code execution (RCE) on vulnerable WordPress servers. (Source: BleepingComputer)
Citrix warns of active exploitation of NetScaler vulnerabilities: Administrators are urged to patch Citrx NetScaler Gateway and ADC appliances immediately following the discovery of two critical vulnerabilities being targeted by attackers. (Source: BleepingComputer)
CISA issues warning on exploits targeting MLflow vulnerability: The Cybersecurity and Infrastructure Security Agency (CISA) has alerted federal agencies that threat actors are actively exploiting a critical flaw in the MLflow open-source AI engineering platform. (Source: BleepingComputer)
'Manic' Android malware uses nearby devices for data exfiltration: A new malware strain called 'Manic' targeting European users has been found using a fallback mechanism to exfiltrate stolen data via proximity to other infected devices. (Source: BleeplarBleepingComputer)
Active exploitation of critical Zimbra RCE vulnerability reported: Security researchers, including CERT Polska, have identified active attacks leveraging a remote code execution flaw in the Zimbra Collaboration Suite (ZCS). (Source: BleepingComputer)
Rogue ransomware affiliate 'Ransom Busters' targets victims with fake recovery services: A criminal entity is posing as a legitimate ransomware recovery firm to trick victims into paying for decryption keys and data deletion services. (Source: BleepingComputer)
Sakura Internet breach exposes data of up to 1.36 million accounts: Japanese cloud provider Sakura Internet reported that hackers accessed its sales management system, compromising customer contract and membership details for millions of users. (Source: BleepingComputer)
CareCloud breach impacts over 3.7 million patients: A data breach at US healthcare IT firm CareCloud has been confirmed to have exposed the personal information of more than 3.7 million individuals. (Source: BleepingComputer)
'CameraSwarm' campaign compromises 14,500 Dahua web cameras: A massive 35-day campaign dubbed 'CameraSwarm' successfully compromised over 14,500 Dahua IP cameras, primarily located in Ukraine and Russia. (Source: BleepingComputer)
US agencies warn of AI-powered attacks on Siemens PLCs: Cybersecurity officials have warned that threat actors are utilizing AI-generated scripts to exploit Siemens S7 Series programmable logic controllers within US critical infrastructure. (Source: BleepingComputer)
U.S. indicts Iranian hackers for $3.4 billion IP theft: The U.S. Department of Justice has charged 17 members of the Mabna Institute, an Iranian hacking-for-hire group, for their involvement in a long-running campaign to steal intellectual property from American organizations. (Source: BleepingComputer)