GOLD BLADE Remote DLL Sideloading Attack Deploys RedLoader
Attacks surged in July 2025 after the threat group updated its process to combine malicious LNK files and a recycled WebDAV technique
Substance abuse treatment provider BayMark Health Services says patient personal information was compromised in a data breach. The post Major Addiction Treatment Firm BayMark Confirms Ransomware Attack Caused Data Breach appeared first on SecurityWeek.
The headline, and the text that follows, is a machine translation of an article by Brice Le Borgne that appeared in Liberation on November 1, 2025: “The museum’s security systems did not fail,” insisted Culture Minister Rachida Dati shortly after the spectacular burglary at the Louvre Museum on October 19. Ten days later, the tone had changed. On……
Threat actors behind the Interlock ransomware group have unleashed a new PHP variant of its bespoke remote access trojan (RAT) as part of a widespread campaign using a variant of ClickFix called FileFix. “Since May 2025, activity related to the Interlock RAT has been observed in connection with the LandUpdate808 (aka KongTuke) web-inject threat clusters,”…
Another day, another school district hit. KDRV in Oregon reports: Central Point School District 6 is addressing a cybersecurity incident that impacted its digital systems. According to the district, unauthorized access was detected on Wednesday, leading to immediate activation of cybersecurity protocols. The affected systems were isolated to prevent further issues. Cybersecurity experts and law…
Mark Keierleber has an interesting and concerning update on the BoardDocs breach previously reported by DataBreaches on June 1: BoardDocs, a software tool used by thousands of school boards to track meeting minutes and store confidential information, has suffered a data breach affecting districts nationally, The 74 has learned. Records at the center of the…
Cybersecurity researchers have disclosed details of a new malware called MDifyLoader that has been observed in conjunction with cyber attacks exploiting security flaws in Ivanti Connect Secure (ICS) appliances. According to a report published by JPCERT/CC today, the threat actors behind the exploitation of CVE-2025-0282 and CVE-2025-22457 in intrusions observed between December 2024 and July