cybercrime/malcode – Lifeboat News: The Blog https://lifeboat.com/blog Safeguarding Humanity Mon, 12 May 2025 02:07:13 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.1 413,032 Americans Affected As Major Data Breach Leaks Customer Names, Social Security Numbers, Financial Records and More https://lifeboat.com/blog/2025/05/413032-americans-affected-as-major-data-breach-leaks-customer-names-social-security-numbers-financial-records-and-more https://lifeboat.com/blog/2025/05/413032-americans-affected-as-major-data-breach-leaks-customer-names-social-security-numbers-financial-records-and-more#respond Mon, 12 May 2025 02:07:13 +0000 https://lifeboat.com/blog/2025/05/413032-americans-affected-as-major-data-breach-leaks-customer-names-social-security-numbers-financial-records-and-more

Hundreds of thousands of Americans are now at risk of identity theft and fraud after a major data breach at a human resources firm.

In a new filing with the Office of the Maine Attorney General, Maryland-based Kelly Benefits says it has discovered a significant cybersecurity incident impacting 413,032 people.

The company says an internal investigation revealed that an unknown entity gained unauthorized access to its database and stole sensitive customer information, including names, dates of birth, Social Security numbers, tax ID numbers, medical and health insurance records and financial account datasets.

]]>
https://lifeboat.com/blog/2025/05/413032-americans-affected-as-major-data-breach-leaks-customer-names-social-security-numbers-financial-records-and-more/feed 0
Chinese Hackers Exploit SAP RCE Flaw CVE-2025–31324, Deploy Golang-Based SuperShell https://lifeboat.com/blog/2025/05/chinese-hackers-exploit-sap-rce-flaw-cve-2025-31324-deploy-golang-based-supershell https://lifeboat.com/blog/2025/05/chinese-hackers-exploit-sap-rce-flaw-cve-2025-31324-deploy-golang-based-supershell#respond Fri, 09 May 2025 11:11:48 +0000 https://lifeboat.com/blog/2025/05/chinese-hackers-exploit-sap-rce-flaw-cve-2025-31324-deploy-golang-based-supershell

China-based hackers exploited SAP flaw CVE-2025–31324 since April 29, impacting global industries via web shells.

]]>
https://lifeboat.com/blog/2025/05/chinese-hackers-exploit-sap-rce-flaw-cve-2025-31324-deploy-golang-based-supershell/feed 0
38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases https://lifeboat.com/blog/2025/05/38000-freedrain-subdomains-found-exploiting-seo-to-steal-crypto-wallet-seed-phrases https://lifeboat.com/blog/2025/05/38000-freedrain-subdomains-found-exploiting-seo-to-steal-crypto-wallet-seed-phrases#respond Fri, 09 May 2025 11:11:35 +0000 https://lifeboat.com/blog/2025/05/38000-freedrain-subdomains-found-exploiting-seo-to-steal-crypto-wallet-seed-phrases

FreeDrain exploited SEO and free hosting to run 38,000+ phishing pages stealing crypto wallets since 2022.

]]>
https://lifeboat.com/blog/2025/05/38000-freedrain-subdomains-found-exploiting-seo-to-steal-crypto-wallet-seed-phrases/feed 0
Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks https://lifeboat.com/blog/2025/05/europol-shuts-down-six-ddos-for-hire-services-used-in-global-attacks https://lifeboat.com/blog/2025/05/europol-shuts-down-six-ddos-for-hire-services-used-in-global-attacks#respond Fri, 09 May 2025 11:11:21 +0000 https://lifeboat.com/blog/2025/05/europol-shuts-down-six-ddos-for-hire-services-used-in-global-attacks

Europol dismantled six DDoS-for-hire services, arrested four, seized nine domains—disrupting attacks since 2022.

]]>
https://lifeboat.com/blog/2025/05/europol-shuts-down-six-ddos-for-hire-services-used-in-global-attacks/feed 0
Google links new LostKeys data theft malware to Russian cyberspies https://lifeboat.com/blog/2025/05/google-links-new-lostkeys-data-theft-malware-to-russian-cyberspies https://lifeboat.com/blog/2025/05/google-links-new-lostkeys-data-theft-malware-to-russian-cyberspies#respond Fri, 09 May 2025 11:11:08 +0000 https://lifeboat.com/blog/2025/05/google-links-new-lostkeys-data-theft-malware-to-russian-cyberspies

Since the start of the year, the Russian state-backed ColdRiver hacking group has been using new LostKeys malware to steal files in espionage attacks targeting Western governments, journalists, think tanks, and non-governmental organizations.

In December, the United Kingdom and Five Eyes allies linked ColdRiver to Russia’s Federal Security Service (FSB), the country’s counterintelligence and internal security service.

Google Threat Intelligence Group (GTIG) first observed LostKeys being “deployed in highly selective cases” in January as part of ClickFix social engineering attacks, where the threat actors trick targets into running malicious PowerShell scripts.

]]>
https://lifeboat.com/blog/2025/05/google-links-new-lostkeys-data-theft-malware-to-russian-cyberspies/feed 0
Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet https://lifeboat.com/blog/2025/05/hackers-exploit-samsung-magicinfo-geovision-iot-flaws-to-deploy-mirai-botnet https://lifeboat.com/blog/2025/05/hackers-exploit-samsung-magicinfo-geovision-iot-flaws-to-deploy-mirai-botnet#respond Wed, 07 May 2025 10:22:22 +0000 https://lifeboat.com/blog/2025/05/hackers-exploit-samsung-magicinfo-geovision-iot-flaws-to-deploy-mirai-botnet

Two critical CVEs exploited in GeoVision IoT and Samsung MagicINFO allow Mirai botnet deployment via RCE.

]]>
https://lifeboat.com/blog/2025/05/hackers-exploit-samsung-magicinfo-geovision-iot-flaws-to-deploy-mirai-botnet/feed 0
New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims https://lifeboat.com/blog/2025/05/new-investment-scams-use-facebook-ads-rdga-domains-and-ip-checks-to-filter-victims https://lifeboat.com/blog/2025/05/new-investment-scams-use-facebook-ads-rdga-domains-and-ip-checks-to-filter-victims#respond Wed, 07 May 2025 10:22:08 +0000 https://lifeboat.com/blog/2025/05/new-investment-scams-use-facebook-ads-rdga-domains-and-ip-checks-to-filter-victims

Cybersecurity researchers have lifted the lid on two threat actors that orchestrate investment scams through spoofed celebrity endorsements and conceal their activity through traffic distribution systems (TDSes).

The activity clusters have been codenamed Reckless Rabbit and Ruthless Rabbit by DNS threat intelligence firm Infoblox.

The attacks have been observed to lure victims with bogus platforms, including cryptocurrency exchanges, which are then advertised on social media platforms. An important aspect of these scams is the use of web forms to collect user data.

]]>
https://lifeboat.com/blog/2025/05/new-investment-scams-use-facebook-ads-rdga-domains-and-ip-checks-to-filter-victims/feed 0
Human Verification https://lifeboat.com/blog/2025/05/human-verification https://lifeboat.com/blog/2025/05/human-verification#respond Sun, 04 May 2025 10:04:33 +0000 https://lifeboat.com/blog/2025/05/human-verification Four children have gained life-changing improvements in sight following treatment with a pioneering new genetic medicine through Moorfields Eye Hospital and UCL Institute of Ophthalmology.

The work was funded by the NIHR Research Professorship, Meira GTx and Moorfields Eye Charity.

The 4 children were born with a severe impairment to their sight due to a rare genetic deficiency that affects the ‘AIPL1’ gene. The defect causes the retinal cells to malfunction and die. Children affected are only able to distinguish between light and darkness. They are legally certified as blind from birth.

The new treatment is designed to enable the retinal cells to work better and to survive longer. The procedure, developed by UCL scientists, consists of injecting healthy copies of the gene into the retina through keyhole surgery. These copies are contained inside a harmless virus, so they can penetrate the retinal cells and replace the defective gene.

The condition is very rare, and the first children identified were from overseas. To mitigate any potential safety issues, the first 4 children received this novel therapy in only one eye.

The eye gene therapy was delivered via keyhole surgery at Great Ormond Street Hospital. The children were assessed in the NIHR Moorfields Clinical Research Facility, and the NIHR Moorfields Biomedical Research Centre provided infrastructure support for the research.


Complete the security check before continuing. This step verifies that you are not a bot, which helps to protect your account and prevent spam.

]]>
https://lifeboat.com/blog/2025/05/human-verification/feed 0
MintsLoader Drops GhostWeaver via Phishing, ClickFix https://lifeboat.com/blog/2025/05/mintsloader-drops-ghostweaver-via-phishing-clickfix https://lifeboat.com/blog/2025/05/mintsloader-drops-ghostweaver-via-phishing-clickfix#respond Sat, 03 May 2025 10:05:53 +0000 https://lifeboat.com/blog/2025/05/mintsloader-drops-ghostweaver-via-phishing-clickfix

Stealth malware MintsLoader delivers GhostWeaver RAT + Evades sandboxes using DGA + Powers data theft via encrypted C2

]]>
https://lifeboat.com/blog/2025/05/mintsloader-drops-ghostweaver-via-phishing-clickfix/feed 0
Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support https://lifeboat.com/blog/2025/05/microsoft-sets-passkeys-default-for-new-accounts-15-billion-users-gain-passwordless-support https://lifeboat.com/blog/2025/05/microsoft-sets-passkeys-default-for-new-accounts-15-billion-users-gain-passwordless-support#comments Sat, 03 May 2025 10:05:40 +0000 https://lifeboat.com/blog/2025/05/microsoft-sets-passkeys-default-for-new-accounts-15-billion-users-gain-passwordless-support

Microsoft now defaults new accounts to passkeys instead of passwords + Safer logins + Reduced phishing risk.

]]>
https://lifeboat.com/blog/2025/05/microsoft-sets-passkeys-default-for-new-accounts-15-billion-users-gain-passwordless-support/feed 1