Category: Cyber Attack News

  • Authorities Seized 800 Servers of Hosting Company Used to Launch Cyberattacks

    Authorities Seized 800 Servers of Hosting Company Used to Launch Cyberattacks Dutch authorities have seized more than 800 servers and arrested two individuals as part of a major investigation into a hosting infrastructure allegedly used to support cyberattacks, disinformation campaigns, and sanctions evasion linked to Russia. The Fiscal Information and Investigation Service (FIOD) confirmed that…

  • Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks

    Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks A multi-stage intrusion attack where a threat actor exploited an internet-facing F5 BIG-IP edge appliance as the entry point for a widespread, identity-focused attack that ultimately accessed Active Directory. According to Microsoft’s Defender Security Research, the attack reflects a growing…

  • GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device

    GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in a series of official statements on May 20, 2026. The Microsoft-owned code hosting platform said it identified…

  • Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability

    Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day exploit chain against an Indonesian defense-sector portal and ultimately pivoting to exfiltrate over 4GB of sensitive Chinese railway documents. The campaign’s…

  • Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts

    Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the matching Docker images on the GitHub…

  • Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide

    Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide A major investigation has revealed that sophisticated threat actors are exploiting fundamental vulnerabilities in global mobile networks to track users worldwide. By abusing legacy 3G SS7 and 4G Diameter signaling protocols, hackers are successfully bypassing telecom firewalls to conduct silent, cross-border espionage. The extensive…

  • Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff

    Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff A newly identified threat group, UNC6692, has been caught running a sophisticated multistage intrusion campaign that uses Microsoft Teams impersonation, a custom modular malware suite, and cloud infrastructure abuse to deeply penetrate enterprise networks, all without exploiting a single software vulnerability. Google Threat…

  • Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code

    Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code A significant supply chain attack targeting the official checkmarx/kics Docker Hub repository, where threat actors pushed trojanized images capable of harvesting and exfiltrating sensitive developer credentials and infrastructure secrets. Docker’s internal monitoring flagged suspicious activity around KICS image tags on April 22, 2026, and promptly…

  • Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns

    Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers observed in 2024,…

  • Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online

    Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online Rockstar Games has confirmed a data breach after the notorious hacking group ShinyHunters exploited a third-party integration to access the company’s internal Snowflake data warehouse, ultimately leaking over 78.6 million records on April 14, 2026. The breach did not stem from a direct attack…

  • FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users

    FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users The U.S. Justice Department and the FBI have successfully dismantled a massive cyberespionage network in a court-authorized takedown dubbed “Operation Masquerade.” Announced on April 7, 2026, the technical operation neutralized thousands of compromised small office/home office (SOHO) routers that were hijacked by Russian military intelligence…

  • Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload

    Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload Cybercriminals are launching a sophisticated new wave of attacks using fake Microsoft Teams domains. According to recent threat intelligence shared by SEAL Org, hackers are actively tricking corporate users into downloading malicious payloads by mimicking the widely used communication platform. As Microsoft Teams remains…

  • Hackers Probe Citrix NetScaler Instances Ahead of Likely CVE-2026-3055 Exploitation

    Hackers Probe Citrix NetScaler Instances Ahead of Likely CVE-2026-3055 Exploitation Cybersecurity researchers are sounding the alarm over imminent in-the-wild exploitation of a recently disclosed critical vulnerability in Citrix NetScaler ADC and Gateway appliances. Threat intelligence firm watchTowr and Defused Cyber have detected active reconnaissance campaigns specifically targeting CVE-2026-3055, a high-severity memory overread flaw that could…

  • FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian Hackers

    FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian Hackers Iran-linked hackers have claimed responsibility for breaching FBI Director Kash Patel’s personal Gmail inbox, leaking photographs, documents, and email correspondence online. The hacker group Handala Hack Team announced the breach on their website, declaring that Patel “will now find his name among the list…

  • Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack

    Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack A sophisticated supply chain attack targeting Aqua Security’s widely used open-source vulnerability scanner, Trivy. A threat actor leveraged compromised credentials to distribute malicious releases, turning a trusted security tool into a mechanism for large-scale credential theft across CI/CD pipelines. The incident remains an ongoing and evolving…

  • Hackers Compromise Trivy Scanner to Inject malicious Scripts and Steal Login Credentials

    Hackers Compromise Trivy Scanner to Inject malicious Scripts and Steal Login Credentials A sophisticated supply chain attack targeting the official Trivy GitHub Action (aquasecurity/trivy-action) has compromised continuous integration and continuous deployment (CI/CD) pipelines globally. Disclosed in late March 2026, this incident marks the second distinct compromise affecting the Trivy ecosystem within a single month. Threat…

  • New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data

    New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data A sophisticated full-chain iOS exploit kit dubbed DarkSword, actively deployed by multiple commercial surveillance vendors and state-sponsored threat actors since at least November 2025 to steal sensitive personal data from iPhone users across four countries. DarkSword is a full-chain iOS exploit that…

  • Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites

    Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites A critical warning has been issued about an active threat campaign targeting misconfigured Experience Cloud sites. The notorious threat actor group ShinyHunters has claimed responsibility for a massive data theft operation exploiting overly permissive guest user configurations, reportedly impacting hundreds of high-profile organizations. According to Salesforce’s…

  • Meta Launches New Anti-Scam Tools on WhatsApp, Facebook and Messenger

    Meta Launches New Anti-Scam Tools on WhatsApp, Facebook and Messenger Meta has launched a suite of advanced anti-scam tools across WhatsApp, Facebook, and Messenger to combat the growing industrialization of online fraud. These new defenses combine artificial intelligence, behavioral alerts, and global law enforcement partnerships to protect users proactively. To protect users from evolving social…

  • Hackers Leveraged CyberStrikeAI Tool to Breach Fortinet FortiGate Devices

    Hackers Leveraged CyberStrikeAI Tool to Breach Fortinet FortiGate Devices A new artificial intelligence (AI) offensive security tool called CyberStrikeAI, which is being actively leveraged by threat actors to target edge devices, particularly Fortinet FortiGate appliances. This open-source platform, developed by a China-based individual with potential ties to state-sponsored operations, represents a significant escalation in the…

  • Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices

    Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices A financially motivated threat actor exploited various commercial generative AI services to compromise over 600 FortiGate devices across more than 55 countries between January 11 and February 18, 2026. The campaign marks a defining demonstration of how AI is lowering the technical entry barrier to…

  • Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data

    Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data A malicious Chrome extension that claims to help Meta Business users quietly steals Facebook Business Manager 2FA codes and analytics data, putting high‑value ad accounts at risk of takeover. The extension, “CL Suite by @CLMasters” (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in the Chrome Web…

  • Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers

    Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers Security researchers have identified the first documented instance of a malicious Microsoft Outlook add-in being used against users in real-world scenarios. A compromised meeting scheduler named AgreeTo was used to steal over 4,000 Microsoft account credentials, credit card numbers, and answers to banking security questions.…

  • Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom

    Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom A new and dangerous class of cyberattack called “Promptware” has been discovered, capable of turning your personal AI assistant into a sleeper agent that spies on you. Security researchers from Ben-Gurion University, Tel Aviv University, and Harvard have demonstrated a terrifying…

  • BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages

    BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages BridgePay Network Solutions, a major U.S. payment gateway provider, confirmed a ransomware attack caused a widespread outage, disrupting card processing for merchants nationwide. The outage began early on February 6, 2026, around 3:29 a.m. EST with degraded performance in systems like the Gateway.Itstgate.com virtual terminal, reporting,…

  • Hackers Linked to State Actors Target Signal Messages of Military Officials and Journalists

    Hackers Linked to State Actors Target Signal Messages of Military Officials and Journalists Germany’s top security agencies issued an urgent warning yesterday regarding a sophisticated cyber espionage campaign targeting high-ranking officials and journalists across Europe. The Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) revealed that…

  • Threat Actors Hacking NGINX Servers to Redirect Web Traffic to Malicious Servers

    Threat Actors Hacking NGINX Servers to Redirect Web Traffic to Malicious Servers A sophisticated campaign in which threat actors are stealthily compromising NGINX servers to redirect web traffic to malicious destinations. The attackers, previously linked to “React2Shell” exploits, are now targeting NGINX configurations, specifically those using the Baota (BT) management panel, widely used in Asia.…

  • OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

    OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem. OpenClaw, previously known as Clawdbot and briefly as Moltbot, is a…

  • Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used

    Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used A sophisticated espionage campaign attributed to the Chinese Advanced Persistent Threat (APT) group Lotus Blossom (also known as Billbug). The threat actors compromised the infrastructure hosting the popular text editor Notepad++ to deliver a custom, previously undocumented backdoor named “Chrysalis”. This campaign, discovered by…

  • State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers

    State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The breach allowed attackers to intercept and selectively redirect update traffic to malicious servers,…

  • China Hacked Email Systems Used by US Congressional Staff, New Report

    China Hacked Email Systems Used by US Congressional Staff, New Report A sophisticated Chinese hacking group has breached email systems accessed by staffers on critical U.S. House committees, exposing sensitive communications amid escalating cyber tensions between Washington and Beijing. The Financial Times revealed on Wednesday that the intruders, tracked as Salt Typhoon, targeted aides supporting…

  • Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability

    Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability The chaos surrounding Ubisoft escalated significantly today as the first group of hackers, previously known for silent exploits, initiated a highly visible and disruptive takeover of Rainbow Six Siege servers. Players worldwide are reporting a massive influx of in-game currency, unwarranted bans, and taunting messages…

  • TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses

    TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses Many Trust Wallet users saw their wallets drained of over $7 million after a security breach in the Chrome browser extension version 2.68.0, released on December 24, 2025. Blockchain investigator ZachXBT first flagged the incident on X, noting a surge in unauthorized outflows from affected…

  • Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised

    Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised Romania’s National Administration “Apele Române” (Romanian Waters) disclosed a severe ransomware attack on December 20, 2025. That compromised approximately 1,000 IT systems across the agency and 10 of its 11 regional water basin administrations. The incident affected critical infrastructure responsible for managing the country’s…

  • DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks

    DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks A new and ominous player has emerged in the rapidly expanding landscape of “Shadow AI.” Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the darknet that is empowering threat actors to automate cyberattacks, generate illicit content,…

  • Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays

    Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays A slight delay in keystrokes from a supposed U.S.-based IT worker alerted Amazon to a North Korean infiltrator accessing a corporate laptop. The commands should have zipped from the worker’s machine to Amazon’s Seattle headquarters in under 100 milliseconds. Instead, they trickled in…

  • Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands

    Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands An active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, targeting Secure Email Gateway (formerly Email Security Appliance, ESA) and Secure Email and Web Manager (formerly Content Security Management Appliance, SMA). The attack, spotted since late November 2025 and publicly disclosed on…

  • Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware

    Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware A deceptive Android application lurking in the Google Play Store, disguised as a document reader and file manager, but delivering the Anatsa banking trojan to users. Cybersecurity firm Zscaler ThreatLabz found an app named “Document Reader – File Manager” by developer ISTOQMAH.…

  • Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits

    Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits Jack, a Solana enthusiast using the Phantom wallet, fell victim to a sophisticated crypto drainer scam that wiped out $9,000 from his wallet almost instantly. He informed Cybersecurity News that the incident began with an attractive Instagram advertisement touting quick profits that…

  • LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak

    LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak LockBit 5.0 key infrastructure exposed, revealing the IP address 205.185.116.233, and the domain karma0.xyz is hosting the ransomware group’s latest leak site. According to researcher Rakesh Krishnan, hosted under AS53667 (PONYNET, operated by FranTech Solutions), a network frequently abused for illicit activities, the server…

  • Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload

    Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload A new, highly sophisticated malware campaign has been identified targeting remote workers and organizations through a fake Google Meet landing page. Hosted on the deceptive domain gogl-meet[.]com, this attack leverages the “ClickFix” social engineering technique to bypass traditional browser security controls and…

  • London Councils’ IT Systems Impacted by CyberAttack, Including Phone Lines

    London Councils’ IT Systems Impacted by CyberAttack, Including Phone Lines Three West London councils are struggling with significant disruption to IT systems and phone lines after a cyberattack on a shared services provider, which officials are publicly describing only as an “IT incident”. The Royal Borough of Kensington and Chelsea (RBKC), Westminster City Council (WCC),…

  • Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack

    Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack Canon has officially confirmed that it was targeted during the widespread hacking campaign exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, orchestrated by the notorious Clop ransomware gang, has impacted dozens of major organizations worldwide. The group listed Canon…

  • Weaponized Putty and Teams Ads Deliver Malware Allowing Hackers to Access Devices and Networks

    Weaponized Putty and Teams Ads Deliver Malware Allowing Hackers to Access Devices and Networks An ongoing malicious advertising campaign is weaponizing legitimate software downloads to deploy OysterLoader malware, previously identified as Broomstick and CleanUpLoader. This sophisticated initial access tool enables cybercriminals to establish footholds in corporate networks, ultimately serving as a delivery mechanism for the…

  • Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft

    Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft Volkswagen Group has issued a statement addressing claims by the ransomware group 8Base, which alleges it has stolen and leaked sensitive data from the automaker. The German carmaker maintains that its core IT infrastructure remains unaffected; however, the company’s vague response leaves questions…

  • Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File

    Microsoft Disrupted Vanilla Tempest Attack by Revoking Certificates Used to Sign Fake Teams File Microsoft announced that it had revoked more than 200 digital certificates exploited by the notorious Vanilla Tempest hacking group. This action effectively disrupted an ongoing campaign where attackers impersonated Microsoft Teams installations to infiltrate corporate networks and deploy ransomware. The operation,…

  • GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware

    GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware A critical deserialization flaw in GoAnywhere MFT’s License Servlet, tracked as CVE-2025-10035, has already been weaponized by the Storm-1175 group to execute the Medusa ransomware. The vulnerability affects GoAnywhere MFT versions up to 7.8.3. It resides in the License Servlet Admin Console, where…

  • Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild

    Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild Oracle has issued an emergency security alert for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite after the notorious Cl0p ransomware group began extorting customers who failed to patch their systems.  The vulnerability, carrying a maximum CVSS score of 9.8, affects the…

  • Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails

    Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails Oracle Corporation has officially acknowledged that cybercriminals are targeting customers of its E-Business Suite (EBS) platform through sophisticated extortion campaigns.  The company’s Chief Security Officer, Rob Duhart, confirmed that hackers have been exploiting previously identified vulnerabilities that were addressed in Oracle’s July 2025 Critical…

  • VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution

    VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged local attacker to gain root-level code execution on affected systems. On September 29, 2025,…

  • Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code

    Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code A malicious npm package masquerading as the official Postmark MCP Server has been exfiltrating user emails to an external server.  This fake “postmark-mcp” module, available on npm from versions 1.0.0 through 1.0.15, built trust over 15 incremental releases before…

  • Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware

    Hackers use Weaponized Microsoft Teams Installer to Compromise Systems With Oyster Malware A sophisticated malvertising campaign is using fake Microsoft Teams installers to compromise corporate systems, leveraging poisoned search engine results and abused code-signing certificates to deliver the Oyster backdoor malware. The attack was neutralized by Microsoft Defender’s Attack Surface Reduction (ASR) rules, which blocked…

  • New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic

    New Domain-fronting Attack Uses Google Meet, YouTube, Chrome and GCP to Tunnel Traffic Organizations commonly allow traffic to core services like Google Meet, YouTube, Chrome update servers, and Google Cloud Platform (GCP) to ensure uninterrupted operations.  A newly demonstrated domain fronting technique weaponizes this trust to establish covert command-and-control (C2) channels, enabling attackers to tunnel…

  • European Airport Disruptions Caused by Sophisticated Ransomware Attack

    European Airport Disruptions Caused by Sophisticated Ransomware Attack Over the weekend, a sophisticated ransomware attack compromised Collins Aerospace’s Muse check-in and boarding systems, forcing key hubs including Heathrow, Brussels, and Berlin to return to manual processes. Airlines reported hundreds of delayed and cancelled flights as security teams raced to contain the breach, restore encrypted data,…

  • BlackLock Ransomware Attacking Windows, Linux, and VMware ESXi Environments

    BlackLock Ransomware Attacking Windows, Linux, and VMware ESXi Environments A sophisticated new ransomware operation dubbed BlackLock has emerged as a significant threat to organizations worldwide, demonstrating advanced cross-platform capabilities and targeting diverse computing environments.  Originally operating under the name “El Dorado” since March 2024, the group rebranded to BlackLock in September 2024, establishing itself as…

  • First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Ransomware Code

    First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Ransomware Code AI-powered malware, known as ‘MalTerminal’, uses OpenAI’s GPT-4 model to dynamically generate malicious code, including ransomware and reverse shells, marking a significant shift in how threats are developed and deployed. This discovery follows the recent analysis of PromptLock, another AI-driven malware, indicating a clear…

  • Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed

    Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed A major cyberattack on a popular aviation software provider has caused significant disruptions at key European airports, including London’s Heathrow, Brussels, and Berlin, resulting in hundreds of flight delays and cancellations on Saturday. The attack disabled electronic check-in and baggage drop systems, forcing airport…

  • UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach

    UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach UK law enforcement has arrested two individuals linked to the notorious Scattered Spider cybercriminal group, including 19-year-old Thalha Jubair from London, who faces charges in connection with over 120 network intrusions that resulted in more than $115 million in ransom payments.  The arrests…

  • Lessons Learned From Massive npm Supply Chain Attack Using “Shai-Hulud” Self-Replicating Malware

    Lessons Learned From Massive npm Supply Chain Attack Using “Shai-Hulud” Self-Replicating Malware The JavaScript ecosystem experienced one of its most sophisticated and damaging supply chain attacks in September 2025, when a novel self-replicating worm dubbed “Shai-Hulud” compromised over 477 npm packages, marking the first successful automated propagation campaign in the npm registry’s history. This attack represents…

  • How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks

    How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks A threat actor who gained initial access through a SonicWall VPN device was able to escalate their attack by finding Huntress recovery codes saved in a plaintext file on a user’s desktop. This allowed the attacker to log into the client’s…

  • Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads

    Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads In the largest supply chain attack, hackers compromised 18 popular npm packages, which together account for over two billion downloads per week. The attack, which began on September 8th, involved injecting malicious code designed to steal cryptocurrency from users. The compromised packages include…

  • Top 10 Attack Surface Management Software Solutions In 2025

    Top 10 Attack Surface Management Software Solutions In 2025 Attack Surface Management (ASM) is a proactive security discipline focused on continuously discovering, analyzing, and reducing an organization’s external-facing digital footprint. In 2025, with the proliferation of cloud services, remote work, and supply chain dependencies, an organization’s attack surface has grown exponentially. Top ASM solutions have…

  • WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

    WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, was combined with a separate vulnerability in Apple’s operating systems to compromise devices and access…

  • Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach

    Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach Google has issued a broad security alert to its 2.5 billion Gmail users, advising them to enhance their account security in the wake of a data breach involving one of the company’s third-party Salesforce systems. The incident, which occurred in June 2025, has…

  • TransUnion Hack Exposes 4M+ Customers Personal Information

    TransUnion Hack Exposes 4M+ Customers Personal Information TransUnion, one of the nation’s three major credit reporting agencies, has disclosed a significant data breach that exposed the personal information of more than four million U.S. customers. The company is now alerting affected individuals about the cyber incident, which involved unauthorized access to data stored on a…

  • Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances

    Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances A sophisticated data exfiltration campaign targeting corporate Salesforce instances has exposed sensitive information from multiple organizations through compromised OAuth tokens associated with the Salesloft Drift third-party application.  The threat actor, designated as UNC6395, systematically harvested credentials and sensitive data between August 8-18,…

  • Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs

    Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs A massive coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with threat actors deploying over 30,000 unique IP addresses to probe for vulnerabilities in Microsoft RD Web Access and RDP Web Client authentication portals.  The campaign represents one of the…

  • PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware

    PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware A sophisticated malware campaign has been identified, utilizing PipeMagic, a highly modular backdoor deployed by the financially motivated threat actor Storm-2460.  This advanced malware masquerades as a legitimate open-source ChatGPT Desktop Application while exploiting the zero-day vulnerability CVE-2025-29824 in Windows Common Log File…

  • DarkBit Hackers Attacking VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files

    DarkBit Hackers Attacking VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files A newly discovered ransomware campaign has targeted enterprise VMware ESXi environments with military precision, deploying custom-built encryption tools that specifically hunt for virtual machine disk files across VMFS datastores.  Security researchers have successfully reverse-engineered the attack methodology and developed breakthrough decryption techniques,…

  • WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware

    WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware A critical zero-day vulnerability has been identified in WinRAR that cybercriminals are actively exploiting through sophisticated phishing campaigns to distribute RomCom malware.  The flaw, designated as CVE-2025-8088, represents a significant security threat with a CVSS v3.1 score of 8.4, enabling attackers to execute arbitrary code on…

  • Google Confirms Data Breach – Notifying Users Affected By the Cyberattack

    Google Confirms Data Breach – Notifying Users Affected By the Cyberattack Tech giant Google has officially acknowledged a significant data breach affecting its corporate Salesforce database, with the company completing email notifications to affected users as of August 8, 2025. Google revealed on August 5 that one of its corporate Salesforce instances was compromised in…

  • Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds

    Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.  The incident, investigated by NCC Group’s Digital Forensics and Incident Response (DFIR) team, demonstrates how cybercriminals are weaponizing trusted business applications to…

  • Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections

    Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections A sophisticated attack technique was uncovered where cybercriminals exploit free trials of Endpoint Detection and Response (EDR) software to disable existing security protections on compromised systems.  This method, dubbed BYOEDR (Bring Your Own EDR), represents a concerning evolution in defense evasion tactics that leverage…

  • Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

    Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.  In April 2025, cybersecurity firm Darktrace successfully detected…