CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

Description: Citing pressure from payment processors and new legislation, a critical resource for producing nonconsensual content bans AI models depicting the likeness of real people.
Source: 404 Media
May 27th, 2025 (24 days ago)
Source: TheRegister
May 27th, 2025 (24 days ago)
Description: The government, which previously criticized the app for so-called "subversive" activity on the platform, alleged Telegram had not cooperated with authorities in addressing criminal activity.
Source: The Record
May 27th, 2025 (24 days ago)
Description: Brackett & Ellis provides legal advice for private businesses of all sizes, governmental entities and non-profit organizations. We are going to upload about 40 GB of corporate data. Lots of cli ent information, financial data and payment details, contracts, e mployee personal documents, etc.
Source: Ransomware.live
May 27th, 2025 (24 days ago)
Description: A/C Supply, Inc. is a leading wholesale distributor of HVAC-R products in southern Louisiana and Mississippi. With twelve branches in Louisiana and Mississippi, A/C Supply employs highly qualified staff with the integrity and dedication you expect from a third-generation family business. At the same time, they take their cybersecurity and their customers seriously.
Source: Ransomware.live
May 27th, 2025 (24 days ago)
Description: ​​​​​ Educo El Salvador, the Salvadoran branch of Educo, an international non-governmental organization (NGO) dedicated to...
Source: Ransomware.live
May 27th, 2025 (24 days ago)
Description: MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage. [...]
Source: BleepingComputer
May 27th, 2025 (24 days ago)
Description: Flock's automatic license plate reader (ALPR) cameras are in more than 5,000 communities around the U.S. Local police are doing lookups in the nationwide system for ICE.
Source: 404 Media
May 27th, 2025 (24 days ago)

CVE-2025-5271

Description: Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139.

EPSS Score: 0.05%

Source: CVE
May 27th, 2025 (24 days ago)
Description: Written by: Diana Ion, Rommel Joven, Yash Gupta Since November 2024, Mandiant Threat Defense has been investigating an UNC6032 campaign that weaponizes the interest around AI tools, in particular those tools which can be used to generate videos based on user prompts. UNC6032 utilizes fake “AI video generator” websites to distribute malware leading to the deployment of payloads such as Python-based infostealers and several backdoors. Victims are typically directed to these fake websites via malicious social media ads that masquerade as legitimate AI video generator tools like Luma AI, Canva Dream Lab, and Kling AI, among others. Mandiant Threat Defense has identified thousands of UNC6032-linked ads that have collectively reached millions of users across various social media platforms like Facebook and LinkedIn. We suspect similar campaigns are active on other platforms as well, as cybercriminals consistently evolve tactics to evade detection and target multiple platforms to increase their chances of success.  Mandiant Threat Defense has observed UNC6032 compromises culminating in the exfiltration of login credentials, cookies, credit card data, and Facebook information through the Telegram API. This campaign has been active since at least mid-2024 and has impacted victims across different geographies and industries. Google Threat Intelligence Group (GTIG) assesses UNC6032 to have a Vietnam nexus.  Mandiant Threat Defense acknowledges Meta's collaborative and proactive thre...
Source: Google Threat Intelligence
May 27th, 2025 (24 days ago)