Category: Threat Intel Reports


  • An X user claimed a 7-Zip zero-day vulnerability, but 7-Zip’s creator says is a fake

    An X user using the handle @NSA_Employee39 disclosed a zero-day vulnerability in the open-source file archive software 7-Zip.—————————————————————————————————————————–A verified X…


  • Buckle up for an odd couple of 2025 government and technology predictions

    Buckle up for an odd couple of 2025 government and technology predictions=========================================================================![](https://cdn.nextgov.com/media/img/cd/2024/12/30/123024newyearNG/860×394.jpg?1735587970) ![](https://cdn.nextgov.com/media/img/cd/2024/12/30/123024newyearNG/860×394.jpg?1735587970)amgun/Getty Images | Get the latest federal technology…


  • China-linked actors hacked US Treasury Department

    China-linked threat actors breached the U.S. Treasury Department by hacking a remote support platform used by the agency.————————————————————————————————————————-China-linked threat actors…


  • Chinese-sponsored hackers accessed Treasury documents in ‘major incident’

    Chinese-sponsored hackers accessed Treasury documents in ‘major incident’=========================================================================![](https://cdn.nextgov.com/media/img/cd/2024/12/30/123024TreasuryNG/860×394.jpg?1735599416) ![](https://cdn.nextgov.com/media/img/cd/2024/12/30/123024TreasuryNG/860×394.jpg?1735599416)carterdayne/Getty Images | Get the latest federal technology news delivered to your…


  • Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation

    ![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjohomRDDjZyJfnjTusOWprpUGv8Yf_k2fgvGvfZqhXhusmUz1WWrkZB6yKdDXD1AOxuLmvoK4MJ88QpRBm0L_zRxNchQGVI0Ib3D3piR43BICNq823bHdXod7ADdFLWRfVlp8lChQjgZwNehps4hJf0atYyxanDBDDLLHQgfqLlXhtxbAQ-HyWs-KefebO/s728-rw-e365/main.png)Cybersecurity researchers have uncovered three security weaknesses in Microsoft’s Azure Data Factory [Apache Airflow](https://airflow.apache.org/) integration that, if successfully exploited, could…


  • US Treasury Department Hacked – Attackers Gained Access to Workstations

    A Chinese state-sponsored hacker has successfully breached the US Treasury Department’s systems, gaining access to employee workstations and unclassified documents,…


  • Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents

    ![U.S. Treasury Systems](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnW4uIKY7rtNoiGYo8nyYHd5Q4GOBJE2Wl-_rkjIV_2niquf9XG2YrD4kttbb6OreSiIdxwiE4vBkrzzBm20bS190-_oo09qmwp2jeTEXnlDUEkw6ue-paA2vVRIH9oQsPo6L7jCfHEAPMgvHQVrhhtp2ROEJRBgypM1uBCb7IA6obfG5TMReQs9QOadE5/s728-rw-e365/chinesehackers.png ‘U.S. Treasury Systems’)The United States Treasury Department said it suffered a ‘major cybersecurity incident’ that allowed suspected…


  • Cisco Data Breach – Authenticity of 4.45GB Data Leak Confirmed

    Cisco has confirmed the authenticity of a 4.45GB data leak posted online by the hacker known as IntelBroker.The leaked files,…


  • No Holiday Season for Attackers, (Tue, Dec 31st)

    [No Holiday Season for Attackers](/forums/diary/No+Holiday+Season+for+Attackers/31552/)=======================================================================================* * [](http://www.facebook.com/sharer.php?u=https%3A%2F%2Fisc.sans.edu%2Fforums%2Fdiary%2F31552 ‘Share on Facebook’)* [](http://twitter.com/share?text=No%20Holiday%20Season%20for%20Attackers&url=https%3A%2F%2Fisc.sans.edu%2Fforums%2Fdiary%2F31552&via=SANS_ISC ‘Share on Twitter’) **Published** : 2024-12-31. **Last Updated** :…


  • Harley-Davidson Data Breach – Threat Actor Allegedly Leaked Customer Details

    Harley-Davidson, the iconic American motorcycle manufacturer, has reportedly fallen victim to a significant data breach orchestrated by a cybercriminal group…