InfoSec News 20250128
Top News
-
China's DeepSeek just dropped a free challenger to OpenAI's o1 – here's how to use it on your PC
"El Reg digs its claws into Middle Kingdom's latest chain of thought model"
TLP1 : Green
"El Reg digs its claws into Middle Kingdom's latest chain of thought model"
TLP1 : Green
"Sygnia’s latest report reveals the evolving tactics of ransomware groups targeting VMware ESXi appliances. By exploiting these critical virtualized infrastructure components, attackers aim to disrupt operations and maintain stealthy persistence within compromised networks."
"Google on Wednesday shed light on a financially motivated threat actor named TRIPLESTRENGTH for its opportunistic targeting of cloud environments for cryptojacking and on-premise ransomware attacks."
TLP1 : Green
"Cyble Research and Intelligence Labs (CRIL) has uncovered an ongoing cyber campaign targeting German organizations using sophisticated tactics like DLL sideloading, proxying, and the deployment of the Sliver implant, an open-source red-teaming framework adapted for malicious purposes."
"The behavior of ChatGPT’s web crawler can be exploited through a discovered vulnerability: under specific query conditions, OpenAI’s bot may inadvertently execute DDoS attacks on arbitrary websites."
TLP1 : Green
"Popular file archiver, 7-Zip, contained a flaw that could have allowed attackers to slip malware past Windows’ security defenses."
TLP1 : Green
"TikTok shut down in the U.S. late Saturday night following the Supreme Court's decision to uphold the law that banned the company over national security concerns."
TLP1 : Green
"Cybersecurity researchers have found that the Microsoft Active Directory Group Policy that's designed to disable NT LAN Manager (NTLM) v1 can be trivially bypassed by a misconfiguration."
TLP1 : Green
New research has pulled back the curtain on a "deficiency" in Google's "Sign in with Google" authentication flow that exploits a quirk in domain ownership to gain access to sensitive data.
TLP1 : Green
"Threat actors are targeting people searching for pirated or cracked software with fake downloaders that include infostealing malware such as Lumma and Vidar."