Smart Contract Scams | Ethereum Drainers Pose as Trading Bots to Steal Crypto
SentinelLABS has identified widespread and ongoing cryptocurrency scams in which actors advertise a crypto trading bot that conceals a smart contract designed to steal the victim’s funds. The scams are marketed through YouTube videos which explain the purported nature of the crypto trading bot and explain how to deploy a smart contract on the Remix Solidity Compiler platform, a web-based integrated development environment (IDE) for Web3 projects. The video descriptions share a link to an external site that hosts the weaponized smart contract code.
Cisco Says User Data Stolen in CRM Hack
The incident came to light on July 24, when Cisco learned that one of its representatives had been targeted in a vishing attack. The threat actor had managed to access and steal a “subset of basic profile information” from an instance of a third-party CRM system used by Cisco. The networking giant immediately took steps to terminate the hacker’s access to the CRM system. An investigation determined that the attacker obtained information provided by individuals who registered an account on Cisco.com.
SonicWall investigates possible zero-day amid Akira ransomware surge
SonicWall is investigating a potential new zero-day after a surge in Akira ransomware attacks targeting Gen 7 firewalls with SSLVPN enabled. The company is working to determine if the incidents stem from an existing flaw or a newly discovered vulnerability. “Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled.” reads the statement published by the vendor. This includes threat activity highlighted by third-party cybersecurity research teams.
AI Slashes Workloads for vCISOs by 68% as SMBs Demand More – New Report Reveals
As the volume and sophistication of cyber threats and risks grow, cybersecurity has become mission-critical for businesses of all sizes. To address this shift, SMBs have been urgently turning to vCISO services to keep up with escalating threats and compliance demands. A recent report by Cynomi has found that a full 79% of MSPs and MSSPs see high demand for vCISO services among SMBs. How are service providers scaling to meet this demand? Which business upside can they expect to see? And where does AI fit in? The answers can be found in “The 2025 State of the vCISO Report”. This newly-released report offers a deep dive into the vCISO market evolution and the broader shift toward advanced cybersecurity services. The bottom line? What used to be a niche offering is now a foundational service, and AI is transforming how it’s delivered. Below, we bring some of the main findings of the report.
Millions of Dell laptops at risk of attack due to security chip flaw
Millions of Dell laptops were vulnerable to attack that would have let potential hackers steal sensitive data and monitor activities thanks to a chip flaw. As reported by Reuters, Dell has released a fix to address a vulnerability which impacts a chip in many of its laptops that stores biometric data, passwords, security codes and more. The flaw was first discovered by researches at Cisco Talos. Dell apparently validated this analysis in a June security advisory in which it explained that the flaw affects more than 100 models of the company’s laptops.
NIST releases final digital identity guidelines after years of drafts
The National Institute of Standards and Technology released new digital identity guidelines on Friday, updating standards dating back to 2017 to respond to a changing landscape. These guidelines outline the process and technical requirements for digital identity proofing, authentication and federation. Many non-governmental organizations also look to these standards. It took NIST four years, two drafts and 6,000 public comments to update them. “This is one step in a continued evolution of how we can help organizations deploy more effective, more efficient, more secure identity technology,” Ryan Galluzzo, the digital identity lead for NIST’s applied cybersecurity division, told Nextgov/FCW Monday.