• UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors

    UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors

    Companies in the legal services, software-as-a-service (SaaS) providers, Business Process Outsourcers (BPOs), and technology sectors in the U.S. have been targeted by a suspected China-nexus cyber espionage group to deliver a known backdoor referred to as BRICKSTORM. The activity, attributed to UNC5221 and closely related, suspected China-nexus threat clusters, is designed to facilitate

    Read More

  • How One Bad Password Ended a 158-Year-Old Business

    How One Bad Password Ended a 158-Year-Old Business

    Most businesses don’t make it past their fifth birthday – studies show that roughly 50% of small businesses fail within the first five years. So when KNP Logistics Group (formerly Knights of Old) celebrated more than a century and a half of operations, it had mastered the art of survival. For 158 years, KNP adapted and endured,…

    Read More

  • Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials

    Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials

    Cloud security company Wiz has revealed that it uncovered in-the-wild exploitation of a security flaw in a Linux utility called Pandoc as part of attacks designed to infiltrate Amazon Web Services (AWS) Instance Metadata Service (IMDS). The vulnerability in question is CVE-2025-51591 (CVSS score: 6.5), which refers to a case of Server-Side Request Forgery (SSRF)…

    Read More

  • State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability

    State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability

    Libraesva has released a security update to address a vulnerability in its Email Security Gateway (ESG) solution that it said has been exploited by state-sponsored threat actors. The vulnerability, tracked as CVE-2025-59689, carries a CVSS score of 6.1, indicating medium severity. “Libraesva ESG is affected by a command injection flaw that can be triggered by…

    Read More

  • Jail costs, funding measures considered

    Jail costs, funding measures considered

    BINGEN — The Bingen City Council, on the heels of a successful sales tax ballot measure, grappled with a second fundraising opportunity at its Sept. 16 meeting.

    Read More

  • Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security

    Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security

    Cybersecurity researchers have disclosed details of two security vulnerabilities impacting Supermicro Baseboard Management Controller (BMC) firmware that could potentially allow attackers to bypass crucial verification steps and update the system with a specially crafted image. The medium-severity vulnerabilities, both of which stem from improper verification of a cryptographic signature, are

    Read More

  • Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries

    Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries

    Law enforcement authorities in Europe have arrested five suspects in connection with an “elaborate” online investment fraud scheme that stole more than €100 million ($118 million) from over 100 victims in France, Germany, Italy, and Spain. According to Eurojust, the coordinated action saw searches in five places across Spain and Portugal, as well as in…

    Read More

  • U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN

    U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN

    The U.S. Secret Service on Tuesday said it took down a network of electronic devices located across the New York tri-state area that were used to threaten U.S. government officials and posed an imminent threat to national security. “This protective intelligence investigation led to the discovery of more than 300 co-located SIM servers and 100,000…

    Read More

  • SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw

    SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw

    SolarWinds has released hot fixes to address a critical security flaw impacting its Web Help Desk software that, if successfully exploited, could allow attackers to execute arbitrary commands on susceptible systems. The vulnerability, tracked as CVE-2025-26399 (CVSS score: 9.8), has been described as an instance of deserialization of untrusted data that could result in code…

    Read More

  • Lean Teams, Higher Stakes: Why CISOs Must Rethink Incident Remediation

    Lean Teams, Higher Stakes: Why CISOs Must Rethink Incident Remediation

    Big companies are getting smaller, and their CEOs want everyone to know it. Wells Fargo has cut its workforce by 23% over five years, Bank of America has shed 88,000 employees since 2010, and Verizon’s CEO recently boasted that headcount is “going down all the time.” What was once a sign of corporate distress has…

    Read More