Cybersecurity & Privacy
Federally Qualified Health Center Reports Ransomware Breach The Central Jersey Medical Center, a federally qualified health center, has reported a ransomware attack that occurred on August 25th, potentially compromising sensitive patient information including names, dates of birth, social security numbers, and health records. The center is working with cybersecurity experts to investigate and enhance its security measures, though it has not disclosed if data was exfiltrated or the number of individuals affected.
China-linked hackers exploited Lanscope flaw
China-linked hackers exploited Lanscope flaw as a zero-day in attacks www.bleepingcomputer.com/news/secu… China-linked cyber-espionage actors tracked as ‘Bronze Butler’ (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware. The discovery of this activity comes from Sophos researchers, who observed the threat actors exploiting the vulnerability in mid-2025 before it was patched to steal confidential information. The flaw exploited in these attacks is CVE-2025-61932, a critical request origin verification flaw impacting Motex Lanscope Endpoint Manager versions 9.
CISA warns ransomware gangs exploit CVE-2024-1086
CISA warns ransomware gangs exploit CVE-2024-1086, a Linux kernel flaw in netfilter: nf_tables, introduced in 2014 and patched in Jan 2024. securityaffairs.com/184076/se… CISA warned that ransomware gangs are exploiting CVE-2024-1086, a high-severity Linux kernel flaw introduced in 2014 and patched in January 2024. CISA didn’t provide details about the ransomware attacks exploiting the flaw or name the groups responsible for targeting it. The vulnerability CVE-2024-1086 is a Linux kernel use-after-free issue that resides in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.
Australia warns of BadCandy infections
Australia warns of BadCandy infections on unpatched Cisco devices www.bleepingcomputer.com/news/secu… The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell. The vulnerability exploited in these attacks is CVE-2023-20198, a max-severity flaw that allows remote unauthenticated threat actors to create a local admin user via the web user interface and take over the devices. Cisco fixed the flaw in October 2023, which was then marked as an actively exploited issue.
Cloud Abuse at Scale
Cloud Abuse at Scale www.fortinet.com/blog/thre… Identity compromise remains one of the most pressing threats to cloud infrastructure today. When attackers gain access to valid credentials, they can often bypass the traditional security controls designed to protect those environments. In AWS, this type of compromise frequently manifests through abuse of the Simple Email Service (SES), one of the most common tactics observed in real-world intrusions. SES offers adversaries a convenient and scalable way to conduct illicit email operations once they’ve obtained valid AWS access keys.
When AI Agents Go Rogue
When AI Agents Go Rogue: Agent Session Smuggling Attack in A2A Systems unit42.paloaltonetworks.com/agent-ses… We discovered a new attack technique, which we call agent session smuggling. This technique allows a malicious AI agent to exploit an established cross-agent communication session to send covert instructions to a victim agent. Here, we discuss the issues that can arise in a communication session using the Agent2Agent (A2A) protocol, which is a popular option for managing the connections between agents. The A2A protocol’s stateful behavior lets agents remember recent interactions and maintain coherent conversations.
Is NordVPN a trustworthy VPN? Independent audits and real-world use
NordVPN is one of the most widely recognized virtual private network (VPN) services. Its no-logs claims have been independently verified five times, most recently by Deloitte Audit Lithuania in late 2024. The service operates on RAM-only servers and uses high-capacity ports across its network. NordVPN is part of Nord Security, valued at roughly US$3 billion as of September 2023. For people looking for a privacy-focused VPN with modern infrastructure, NordVPN warrants serious consideration.
A concise roundup of notable incidents and high-risk exposures (at 08h22 ET on 2025-10-31). threatintel.cc/2025/10/3… #Cyber #ThreatIntel #Incidents #Malware #DataLeak #Breach #Hack
Is Surfshark a Trustworthy VPN? Independent Audits and Key Features
Surfshark is a VPN provider whose no-logs policy has been independently verified by Deloitte. Its infrastructure uses RAM-only servers and supports 10 Gbps ports, with recently announced deployment of 100 Gbps servers in Amsterdam. The company is part of the Nord Security group, valued at US $3 billion as of September 2023. For users seeking an audited no-logs VPN with modern architecture, Surfshark merits serious consideration.
Cloud Discovery With AzureHound This article details AzureHound, a data collection tool used by threat actors for cloud discovery in Azure environments, mapping its usage to MITRE ATT&CK techniques. It explains how AzureHound enumerates identities, permissions, and resources to identify attack paths and provides guidance for defenders on detecting and mitigating its misuse.