Newly identified APT group, NightEagle, observed exploiting zero-day vulnerabilty in Microsoft Exchange to target Chinese military and tech sectors.

Newly identified APT group, NightEagle, observed exploiting zero-day vulnerabilty in Microsoft Exchange to target Chinese military and tech sectors.

A newly identified advanced persistent threat (APT) group, dubbed NightEagle (also known as APT-Q-95), has been observed exploiting a previously undocumented zero-day vulnerability in Microsoft Exchange servers. The group’s campaign, active since at least 2023, has primarily targeted China’s military, defense, and high-technology sectors, including organizations involved in semiconductor manufacturing, quantum technology, and artificial intelligence research.
Unlocking Roku’s Secret Menus: Hidden Features and How to Access Them

Unlocking Roku’s Secret Menus: Hidden Features and How to Access Them

Security be damned. Did you know your Roku streaming device is packed with hidden menus and secret screens? These advanced features are tucked away behind special remote-control codes, giving you access to powerful diagnostic tools, developer options, and customization settings not found in the standard Roku interface. Here’s everything you need to know about Roku’s secret menus—and how to unlock them.
FBI says recent breach of US telecommunications infrastructure by China’s Salt Typhoon is largely contained with affected networks.

FBI says recent breach of US telecommunications infrastructure by China’s Salt Typhoon is largely contained with affected networks.

The FBI’s top cyber official announced this week that the Chinese state-backed hacking group known as Salt Typhoon, responsible for a significant breach of U.S. telecommunications infrastructure, is now “largely contained” within affected networks. While the immediate threat has been mitigated, federal authorities caution that the risk posed by the group remains unresolved.
Researchers reveal the existence of extensive brand-spoofing campaigns that leverage thousands of fraudulent websites impersonating known brands.

Researchers reveal the existence of extensive brand-spoofing campaigns that leverage thousands of fraudulent websites impersonating known brands.

Recent investigations by cybersecurity firm Silent Push and VPN provider NordVPN have revealed the existence of extensive brand-spoofing campaigns that leverage thousands of fraudulent websites to impersonate some of the world’s most recognized brands. These operations are designed to deceive consumers, steal sensitive information, and facilitate financial fraud on a global scale.
Initial Access Brokers are deploying patches to exploited vulnerabilities to effectively lock out rival cybercriminals.

Initial Access Brokers are deploying patches to exploited vulnerabilities to effectively lock out rival cybercriminals.

A recent cyber campaign has brought to light a sophisticated new tactic employed by initial access brokers, believed to be linked to China. These threat actors are leveraging zero-day vulnerabilities in Ivanti Connect Secure systems to infiltrate target networks. Uniquely, after gaining access, the attackers are applying their own patches to the exploited vulnerabilities, effectively locking out both defenders and rival cybercriminals.
The Big Beautiful Bill: How the New Legislation Will Impact U.S. Cybersecurity.

The Big Beautiful Bill: How the New Legislation Will Impact U.S. Cybersecurity.

Washington, D.C. – The recently approved "Big Beautiful Bill" is making waves across the cybersecurity landscape, promising sweeping changes for federal agencies, the Department of Defense, and civilian infrastructure. While the bill delivers major funding boosts for federal IT modernization and defense cybersecurity, it also slashes budgets for key civilian programs, raising concerns among experts about the nation’s ability to respond to evolving cyber threats.
Hackers are increasingly leveraging PDF attachments in email-based phishing campaigns to impersonate trusted brands like Microsoft and DocuSign.

Hackers are increasingly leveraging PDF attachments in email-based phishing campaigns to impersonate trusted brands like Microsoft and DocuSign.

Hackers are increasingly leveraging PDF attachments in email-based phishing campaigns to impersonate trusted brands like Microsoft and DocuSign, as well as others such as NortonLifeLock, PayPal, and Geek Squad. The primary technique being used is known as callback phishing or Telephone-Oriented Attack Delivery (TOAD), where victims are persuaded to call phone numbers controlled by the attackers.
Chinese-linked Houken targets France in Ivanti zero-day exploit campaign.

Chinese-linked Houken targets France in Ivanti zero-day exploit campaign.

A Chinese-linked hacking group, dubbed “Houken,” has been identified as the orchestrator of a sophisticated cyberattack campaign targeting French organizations by exploiting multiple zero-day vulnerabilities in Ivanti Cloud Service Appliance (CSA) devices. The campaign was first detected by France’s national cybersecurity agency, ANSSI, in September 2024, though evidence suggests it may have started as early as 2023.