CVE-2024-9643 Exploited by Botnets
Attackers are exploiting CVE-2024-9643, an authentication bypass flaw in Four-Faith industrial routers, to compromise devices and fold them into botnets for further campaigns.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Attackers are exploiting CVE-2024-9643, an authentication bypass flaw in Four-Faith industrial routers, to compromise devices and fold them into botnets for further campaigns.
A 23-year-old Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDos botnet, a large-scale distributed denial-of-service platform that infected over a million devices worldwide.
Two former US executives pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide, with Americans losing at least $2.1 billion to such scams in 2025.
Chargebacks only capture a narrow slice of fraud losses, hiding bigger issues that affect revenue, customer experience, and long-term profitability.
The Supreme Court is considering a case that could reshape how law enforcement uses technology to identify suspects, with implications for digital privacy and the Fourth Amendment.
Meta has agreed to settle a lawsuit with a Kentucky school district over alleged addictive design practices that harmed students' mental health.
The FBI warns of Kali365, a phishing-as-a-service platform that tricks people into giving access to their Microsoft 365 accounts, with hundreds of attacks reported in April.
The FBI warns of Kali365, a growing phishing-as-a-service platform that retrieves Microsoft 365 access tokens, bypassing multi-factor authentication and abusing OAuth device code authorizations.
Lawmakers are demanding answers from CISA after a contractor leaked agency secrets on a public GitHub account, raising concerns about the agency's internal policies and procedures.