ANSH Infosec

Police arrests suspects tied to AI-generated CSAM distribution ring

Law enforcement agencies from 19 countries have arrested 25 suspects linked to a criminal ring that was distributing child sexual abuse material (CSAM) generated using artificial intelligence (AI). Operation Cumberland, coordinated by Danish law enforcement and supported by Europol, resulted in the seizure of 173 electronic devices and the identification of 273 suspected members tied […]

Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks

Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows. The vulnerable drivers were exploited in ‘Bring Your Own Vulnerable Driver’ (BYOVD) attacks where threat actors drop the kernel driver on a targeted system to elevate privileges. “An attacker with local access to a […]

Nearly 12,000 API keys and passwords found in AI training dataset

Close to 12,000 valid secrets that include API keys and passwords have been found in the Common Crawl dataset used for training multiple artificial intelligence models. The Common Crawl non-profit organization maintains a massive open-source repository of petabytes of web data collected since 2008 and is free for anyone to use. Because of the large dataset, many […]

3.2 Million Users Exposed by Malicious Browser Extensions

A newly uncovered cybersecurity threat has revealed that at least 3.2 million users have been affected by malicious browser extensions masquerading as legitimate utilities. A cluster of 16 extensions—ranging from screen capture tools to ad blockers and emoji keyboards—was identified as injecting malicious code into users’ browsers. According to GitLab Threat Intelligence, these extensions facilitate […]

New PayPal Scam Tricks Users with Convincing Ads and Pages

A new scam targeting PayPal customers has been identified, using convincing Google search ads and specially-crafted PayPal pay links to deceive users. This scheme is particularly dangerous on mobile devices due to their limited screen size and the lower likelihood of having security software installed. The scammers create ads that impersonate PayPal, often using hacked […]