Hackers exploiting SharePoint zero-day seen targeting government agencies

Hackers exploiting SharePoint zero-day seen targeting government agencies

The hackers behind the initial wave of attacks exploiting a zero-day in Microsoft SharePoint servers have so far primarily targeted government organizations, according to researchers and news reports. Over the weekend, U.S. cybersecurity agency CISA published an alert, warning that hackers were exploiting a previously unknown bug — known as a “zero-day” — in Microsoft’s…

Read More
Hacker reconnaissance work continues on TeleMessage app vulnerability — Report

Hacker reconnaissance work continues on TeleMessage app vulnerability — Report

As of Wednesday, at least eleven IP addresses have actively tried to exploit the vulnerability, with thousands more addresses possibly doing reconnaissance work. Hackers are continuing to seek out opportunities to exploit the infamous CVE-2025-48927 vulnerability involved in TeleMessage, according to a new report from threat intelligence company GreyNoise. GreyNoise’s tag, which monitors attempts to…

Read More
US Army soldier pleads guilty to hacking telcos and extortion

US Army soldier pleads guilty to hacking telcos and extortion

Former U.S. Army soldier Cameron John Wagenius pleaded guilty to hacking telecommunication companies and attempting to extort them by threatening to release stolen files, the Department of Justice announced on Tuesday. According to the DOJ, Wagenius, who went online with the nickname “kiberphant0m,” conspired to defraud 10 victim companies by stealing their login credentials, using…

Read More
Researchers foil M DeFi backdoor in thousands of smart contracts

Researchers foil $10M DeFi backdoor in thousands of smart contracts

The Venn Network team suspects the attack was linked to the North Korean Lazarus Group, citing its complexity and widespread deployment. Crypto security researchers uncovered and neutralized a critical threat affecting thousands of smart contracts, potentially preventing more than $10 million in crypto from being stolen.  On Thursday, pseudonymous Venn Network researcher Deeberiroz shared in…

Read More
CoinMarketCap has 'identified and removed' malicious wallet scam

CoinMarketCap has 'identified and removed' malicious wallet scam

According to a post on CoinMarketCap’s X account, the malicious code has been removed, though the team insists the investigation into the incident is still ongoing. CoinMarketCap, a price-tracking website for cryptocurrencies, has reportedly removed a malicious popup notification on its website prompting users to verify their cryptocurrency wallets, according to a post on its…

Read More