Cybersecurity

Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom 

Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom 

In episode 403 of “Smashing Security” we dive into the mystery of $65 million vanishing from Coinbase users faster than J-Lo slipped into Graham’s DMs, Geoff gives a poor grade for PowerSchool’s security, and Carole takes a curious look at QR codes.

All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist’s Geoff White.

Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign 

Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign 

The North Korea-linked Lazarus Group has been linked to an active campaign that leverages fake LinkedIn job offers in the cryptocurrency and travel sectors to deliver malware capable of infecting Windows, macOS, and Linux operating systems.
According to cybersecurity company Bitdefender, the scam begins with a message sent on a professional social media network, enticing them with the promise of

Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts 

Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts 

Cybercriminals are increasingly leveraging legitimate HTTP client tools to facilitate account takeover (ATO) attacks on Microsoft 365 environments.
Enterprise security company Proofpoint said it observed campaigns using HTTP clients Axios and Node Fetch to send HTTP requests and receive HTTP responses from web servers with the goal of conducting ATO attacks.
“Originally sourced from public

Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks 

Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks 

A previously undocumented threat actor known as Silent Lynx has been linked to cyber attacks targeting various entities in Kyrgyzstan and Turkmenistan.
“This threat group has previously targeted entities around Eastern Europe and Central Asian government think tanks involved in economic decision making and banking sector,” Seqrite Labs researcher Subhajeet Singha said in a technical report

New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack 

New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack 

Veeam has released patches to address a critical security flaw impacting its Backup software that could allow an attacker to execute arbitrary code on susceptible systems.
The vulnerability, tracked as CVE-2025-23114, carries a CVSS score of 9.0 out of 10.0.
“A vulnerability within the Veeam Updater component that allows an attacker to utilize a Man-in-the-Middle attack to execute arbitrary code

Navigating the Future: Key IT Vulnerability Management Trends  

Navigating the Future: Key IT Vulnerability Management Trends  

As the cybersecurity landscape continues to evolve, proactive vulnerability management has become a critical priority for managed service providers (MSPs) and IT teams. Recent trends indicate that organizations increasingly prioritize more frequent IT security vulnerability assessments to identify and address potential security flaws.
Staying informed on these trends can help MSPs and IT teams

AsyncRAT Campaign Uses Python Payloads and TryCloudflare Tunnels for Stealth Attacks 

AsyncRAT Campaign Uses Python Payloads and TryCloudflare Tunnels for Stealth Attacks 

A malware campaign has been observed delivering a remote access trojan (RAT) named AsyncRAT by making use of Python payloads and TryCloudflare tunnels.
“AsyncRAT is a remote access trojan (RAT) that exploits the async/await pattern for efficient, asynchronous communication,” Forcepoint X-Labs researcher Jyotika Singh said in an analysis.
“It allows attackers to control infected systems

CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25 

CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The list of vulnerabilities is as follows –

CVE-2024-45195 (CVSS score: 7.5/9.8) – A forced browsing vulnerability in Apache OFBiz that allows a remote attacker to obtain unauthorized

The AI Fix #36: A DeepSeek special 

The AI Fix #36: A DeepSeek special 

In episode 36 of The AI Fix, Graham and Mark take a long look at DeepSeek, an upstart AI out of China that was trained on a shoestring, shook up Wall Street, kneecapped Nvidia, and challenged America’s AI hegemony.

Graham also discovers a remarkably f***ing effective way to remove AI snippets, a personal mobility robot gets a bit over-excited, some aliens regret installing an FTP server, and Mark explains what o3-mini owes to Spinal Tap.

All this and much more is discussed in the latest edition of “The AI Fix” podcast by Graham Cluley and Mark Stockley.

NEW CUSTOMERS CALL TODAY: 720.221.6804  |  EXISTING CUSTOMERS REQUIRING SUPPORT: 303.617.6442

X