• North Korean Hackers Target Developers with Malicious npm Packages

    North Korean Hackers Target Developers with Malicious npm Packages

    Threat actors with ties to North Korea have been observed publishing a set of malicious packages to the npm registry, indicating “coordinated and relentless” efforts to target developers with malware and steal cryptocurrency assets. The latest wave, which was observed between August 12 and 27, 2024, involved packages named temp-etherscan-api, ethersscan-api, telegram-con, helmet-validate, and

    Read More

  • Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32

    Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32

    A non-profit supporting Vietnamese human rights has been the target of a multi-year campaign designed to deliver a variety of malware on compromised hosts. Cybersecurity company Huntress attributed the activity to a threat cluster known as APT32, a Vietnamese-aligned hacking crew that’s also known as APT-C-00, Canvas Cyclone (formerly Bismuth), Cobalt Kitty, and OceanLotus. The…

    Read More

  • Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack

    Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack

    Cybersecurity researchers have flagged multiple in-the-wild exploit campaigns that leveraged now-patched flaws in Apple Safari and Google Chrome browsers to infect mobile users with information-stealing malware. “These campaigns delivered n-day exploits for which patches were available, but would still be effective against unpatched devices,” Google Threat Analysis Group (TAG) researcher Clement

    Read More

  • U.S. Agencies Warn of Iranian Hacking Group’s Ongoing Ransomware Attacks

    U.S. Agencies Warn of Iranian Hacking Group’s Ongoing Ransomware Attacks

    U.S. cybersecurity and intelligence agencies have called out an Iranian hacking group for breaching multiple organizations across the country and coordinating with affiliates to deliver ransomware. The activity has been linked to a threat actor dubbed Pioneer Kitten, which is also known as Fox Kitten, Lemon Sandstorm (formerly Rubidium), Parisite, and UNC757, which it described…

    Read More

  • How AitM Phishing Attacks Bypass MFA and EDR—and How to Fight Back

    How AitM Phishing Attacks Bypass MFA and EDR—and How to Fight Back

    Attackers are increasingly using new phishing toolkits (open-source, commercial, and criminal) to execute adversary-in-the-middle (AitM) attacks. AitM enables attackers to not just harvest credentials but steal live sessions, allowing them to bypass traditional phishing prevention controls such as MFA, EDR, and email content filtering. In this article, we’re going to look at what AitM phishing

    Read More

  • Unpatched AVTECH IP Camera Flaw Exploited by Hackers for Botnet Attacks

    Unpatched AVTECH IP Camera Flaw Exploited by Hackers for Botnet Attacks

    A years-old high-severity flaw impacting AVTECH IP cameras has been weaponized by malicious actors as a zero-day to rope them into a botnet. CVE-2024-7029 (CVSS score: 8.7), the vulnerability in question, is a “command injection vulnerability found in the brightness function of AVTECH closed-circuit television (CCTV) cameras that allows for remote code execution (RCE),” Akamai…

    Read More

  • Animal control on the ballot on Skamania County

    Animal control on the ballot on Skamania County

    SKAMANIA CO. — A 0.03% increase in sales tax could get Skamania County’s dogs, horses and other assorted creatures a dedicated animal control officer to answer their emergencies. The public safety tax to fund animal control in Skamania County, proposed…

    Read More

  • News briefs: Aug. 28, 2024

    News briefs: Aug. 28, 2024

    Notice of recount in Klickitat County; Advocacy Lunch Sept. 11

    Read More

  • Fortra Issues Patch for High-Risk FileCatalyst Workflow Security Vulnerability

    Fortra Issues Patch for High-Risk FileCatalyst Workflow Security Vulnerability

    Fortra has addressed a critical security flaw impacting FileCatalyst Workflow that could be abused by a remote attacker to gain administrative access. The vulnerability, tracked as CVE-2024-6633, carries a CVSS score of 9.8, and stems from the use of a static password to connect to a HSQL database. “The default credentials for the setup HSQL…

    Read More

  • APT-C-60 Group Exploit WPS Office Flaw to Deploy SpyGlace Backdoor

    APT-C-60 Group Exploit WPS Office Flaw to Deploy SpyGlace Backdoor

    A South Korea-aligned cyber espionage has been linked to the zero-day exploitation of a now-patched critical remote code execution flaw in Kingsoft WPS Office to deploy a bespoke backdoor dubbed SpyGlace. The activity has been attributed to a threat actor dubbed APT-C-60, according to cybersecurity firms ESET and DBAPPSecurity. The attacks have been found to…

    Read More