1/30/2025

Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations

Time Bandit ChatGPT Jailbreak Bypasses Safeguards on Sensitive Topics

Google Blocked 2.36 Million Risky Android Apps From Play Store in 2024

Krebs: Infrastructure Laundering: Blending in with the Cloud

U.S. FDA Identifies Cybersecurity Risks in Certain Patient Monitors

Authorities Seize Domains of Popular Hacking Forums in Major Cybercrime Crackdown

Gabbard Grilled Over Snowden Comments During Senate Confirmation Hearing
Ransomware Attack Disrupts Blood Donation Services in U.S.

AngelSense Exposed Location Data and Personal Information of Tracked Users

Cybersecurity Event at Benefits Management Group (IL) Results in Data Breach

Solana Pump.Fun Tool DogWifTool cCompromised to Drain Wallets

Syncjacking Attack Enables Full Browser and Device Takeover

New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks

States With Laws Requiring Data Brokers to Register Are Ramping up Enforcement

1/29/2025

Poland Accuses Russia of Recruiting Polish Citizens Online for Election Meddling

Lazarus Group Uses React-Based Admin Panel to Control Global Cyber Attacks

UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents

Google Will Now Automatically Revoke Permissions From Harmful Android Apps

Exposed DeepSeek Database Revealed Chat Prompts and Internal Data

DeepSeek Leveraged U.S. Chips, ‘Stolen’ Technology, Trump’s Commerce Secretary Pick Says

Chinese and Iranian Hackers Are Using U.S. AI Products to Bolster Cyberattacks

Italian Regulator Asks DeepSeek for Information About Data Collection

Nation-State Hackers Abuse Gemini AI Tool

The Trial at the Tip of the Terrorgram Iceberg

FBI Seizes Cracked.io, Nulled.to Hacking Forums in Operation Talent
Threat Actors Exploit Government Websites for Phishing

How Interlock Ransomware Infects Healthcare Organizations

South Africa’s Government-Run Weather Service Knocked Offline by Cyberattack

Frederick Health (MD) Network Forced to Shut down It Systems After Ransomware Attack

Albany Gastroenterology Associates (NY) Files Notice of Data Breach Following Unauthorized Access to Computer Network

Laravel Admin Package Voyager Vulnerable to One-Click Rce Flaw

Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability

Broadcom Warns of High-Severity SQL Injection Flaw in VMware Avi Load Balancer

Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution

New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits

Sectigo Buys Entrust’s Public Certificate Business

1/28/2025

Krebs: A Tumultuous Week for Federal Cybersecurity Efforts

DeepSeek’s Popular AI App Is Explicitly Sending U.S. Data to China

Apple Researchers Reveal the Secret Sauce Behind DeepSeek AI

Scammers Are Creating Fake News Videos to Blackmail Victims

AI Haters Build Tarpits to Trap and Trick AI Scrapers That Ignore robots.txt

Microsoft Tests Edge Scareware Blocker to Block Tech Support Scams

Google Play Will Now Verify VPNs That Prioritize Privacy and Safety

British Vishing-as-a-Service Trio Sentenced

Prosecutors Say They Can’t Obtain Murder Conviction After Judge Throws Out Evidence From Facial Recognition Match

58% of Ransomware Victims Forced to Shut Down Operations

How Long Does It Take Hackers to Crack Modern Hashing Algorithms?
UK Engineering Firm Smiths Group Hit by Cyber Attack

Texas Utility Firm CenterPoint Energy Investigating Potential Leak of Customer Data Tied to 2023 MOVEit Breach

API Supply Chain Attacks Put Millions of Airline Users at Risk

PowerSchool Starts Sending Breach Notifications, but There Are Still Questions Left to Answer

ENGlobal Cyber-Attack Exposes Sensitive Data

PureCrypter Deploys Agent Tesla and New TorNet Backdoor in Ongoing Cyberattacks

Lynx Ransomware Group Unveiled with Sophisticated Affiliate Program

Hellcat: Baguette Bandits Strike Again With Ransomware and a Side of Mockery

Hackers Exploiting Flaws in SimpleHelp RMM to Breach Networks

New Apple CPU Side-Channel Attacks Steal Data From Browsers

Signal Will Let You Sync Old Messages When Linking New Devices

1/27/2025

Silicon Valley Is Raving About a Made-in-China DeepSeek AI Model

China’s DeepSeek AI App Sends U.S. Tech Stocks Reeling

DeepSeek’s Top-Ranked AI App Is Restricting Sign-Ups Due to ‘Malicious Attacks’

Hackers Hijack Emergency Sirens in Kindergartens Across Israel

Ukraine Denies Involvement in Cyberattack Against Slovakia

Sweden Seizes Cargo Ship After Another Undersea Cable Hit in Suspected Sabotage

EU Sanctions Russian GRU Hackers for Cyberattacks Against Estonia

MGM Agrees to Pay $45 Million to Settle Data-Breach Lawsuit

Brazil Bans Iris Scan Company Co-Founded by Sam Altman From Paying Citizens for Biometric Data

Democrat Members of U.S. Surveillance Watchdog Fired After Refusing to Resign
Matagorda County (TX) Issues Disaster Declaration Following Cyberattack

Universal Lenders (IL) Sends Data Breach Letters to 19,575 Individuals

Hidden Text Salting Disrupts Brand Name Detection Systems

New Phishing Campaign Targets Mobile Devices with Malicious PDFs

MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks

Clone2Leak: GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs

Apple Fixes This Year’s First Actively Exploited Zero-Day Bug

CISOs Boost Crisis Simulation Budgets Amid High-Profile Cyber-Attacks

Bitwarden Makes It Harder to Hack Password Vaults Without MFA

Microsoft Teams Phishing Attack Alerts Coming to Everyone Next Month

1/24-26/2025

Cyber Diplomacy Funding Halted as U.S. Issues Broad Freeze on Foreign Aid

Kristi Noem Confirmed by U.S. Senate as Trump’s Homeland Secretary

UK to Examine Undersea Cable Vulnerability as Russian Spy Ship Spotted in British Waters

UnitedHealth Estimates Change Healthcare Hack Impacted About 190 Million People

Russian Scammers Target Crypto Influencers with Infostealers

Hacker Infects 18,000 “Script Kiddies” With Fake Malware Builder

Can’t Download TikTok? How About a Used iPhone for $3,000

U.S. Privacy Snags a Win as Judge Limits Warrantless FBI Searches

Hackers Get $886,250 For 49 Zero-Days at Pwn2Own Automotive 2025
TalkTalk Investigates Breach After Data for Sale on Hacking Forum

At Least $69 Million Stolen From Crypto Platform Phemex in Suspected Cyberattack

Game Developer Big Cheese Studio Targeted in Cyber Attack, PAP Reports

Ransomware Gang Uses SSH Tunnels for Stealthy VMware ESXi Access

Hackers Use Windows RID Hijacking to Create Hidden Admin Account

Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List

Microsoft: Outdated Exchange Servers Fail to Auto-Mitigate Security Bugs

Zyxel Warns of Bad Signature Update Causing Firewall Boot Loops

1/23/2025

Hackers Imitate Kremlin-Linked Group to Target Russian Entities

FBI: North Korean IT Workers Steal Source Code to Extort Employers

DOJ Indicts Two Americans for Running Laptop Farm Used in North Korea IT Worker Scam

Google Is Giving IT More Control Over Your Chrome Extensions

New GhostGPT AI Chatbot Facilitates Malware Creation and Phishing

Hundreds of Fake Reddit Sites Push Lumma Stealer Malware

Bookmakers Ramp Up Efforts to Combat Arbitrage Betting Fraud

PayPal Fined by New York for Cybersecurity Failures

Texas Probes Four More Car Companies Over How They Collect and Sell Consumer Data

LinkedIn Sued for Allegedly Training AI Models With Private Messages Without Consent

Tesla EV Charger Hacked Twice on Second Day of Pwn2Own Tokyo

CISA: Hackers Still Exploiting Older Ivanti Bugs to Breach Networks

CISOs Dramatically Increase Boardroom Influence but Still Lack Soft Skills

New Android Identity Check Locks Settings Outside Trusted Locations
FortiGate Config Leaks: Victims’ Email Addresses Published Online

RansomHub Lays Claim on American Standard, Grohe Breaches

PFS Investments Inc. (GA) Files Notice of Recent Data Breach Leaking Confidential Information

Experts Find Shared Codebase Linking Morpheus and HellCat Ransomware Payloads

QakBot-Linked BC Malware Adds Enhanced Remote Access and Data Gathering Features

Subaru Security Flaws Exposed Its System for Tracking Millions of Cars

Critical Zero-Days Impact Premium WordPress Real Estate Plugins

QNAP Fixes Six Rsync Vulnerabilities in NAS Backup, Recovery App

Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits

SonicWall Urges Immediate Patch for Critical CVE-2025-23006 Flaw Amid Likely Exploitation

Cisco Fixes Critical 9.9-Rated, Make-Me-Admin Bug in Meeting Management

The Security Risk of Rampant Shadow AI

1/22/2025

Iran and Russia Deepen Cyber Ties With New Agreement

Trump Terminates DHS Advisory Committee Memberships, Disrupting Cybersecurity Review

Trump Admin Tells All Democrats on Intelligence Oversight Board to Resign

Krebs: MasterCard DNS Error Went Unnoticed for Years

What PowerSchool Isn’t Saying About Its ‘Massive’ Student Data Breach

PowerSchool Hacker Claims They Stole Data of 62 Million Students

Cloudflare CDN Flaw Leaks User Location Data, Even Through Secure Chat Apps

Major Cybersecurity Vendors’ Credentials Found on Dark Web

BreachForums Admin to Be Resentenced After Appeals Court Slams Supervised Release

Israeli Private Eye Wanted in U.S. Over Alleged Hacking for Exxon Lobbyist, Lawyer Says

Trump Frees Silk Road Creator Ross Ulbricht After 11 Years in Prison
Conduent Confirms Cybersecurity Incident Behind Recent Outage

Octagon (CT) Sends Round of Data Breach Letters Following Recent Cybersecurity Incident

PlushDaemon APT Targeted South Korean VPN Software

Telegram CAPTCHA Tricks You Into Running Malicious Powershell Scripts

Tycoon 2FA Phishing Kit Upgraded to Bypass Security Measures

IPany VPN Breached in Supply-Chain Attack to Push Custom Malware

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet

Cisco Warns of Denial of Service Flaw With PoC Exploit Code

Microsoft Issues Out-Of-Band Fix for Windows Server 2022 NUMA Glitch

Hackers Exploit 16 Zero-Days on First Day of Pwn2Own Automotive 2025

Why CISOs Must Think Clearly Amid Regulatory Chaos

1/21/2025

Russian Ransomware Groups Deploy Email Bombing and Teams Vishing

CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits

Fake Homebrew Google Ads Target Mac Users With Malware

Quad Foreign Ministers Meet in Washington in Signal of Trump’s China Focus

TSA Chief Behind Cyber Directives for Aviation, Pipelines and Rail Ousted by Trump Team

U.S. Department of Homeland Security Firing All Advisory Committee Members, Letter Says

UK’s New Digital IDs Raise Security and Privacy Fears

Disciplinary and Special Ed Records of Toronto Students May Have Leaked in PowerSchool Breach

Cloudflare Mitigated a Record-Breaking 5.6 Tbps DDoS Attack
Russian Telecom Giant Rostelecom Investigates Suspected Cyberattack on Contractor

Govtech Giant Conduent Won’t Rule Out Cyberattack as Outage Drags On

IntraSystems Data Breach Hits Home Care Patients at Allegheny Health Network

PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers

13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks

New Mirai Malware Variant Targets AVTECH Cameras, Huawei Routers

Oracle To Address 320 Vulnerabilities in January Patch Update

7-Zip Fixes Bug That Bypasses Windows MoTW Security Warnings, Patch Now

Patch Procrastination Leaves 50,000 Fortinet Firewalls Vulnerable to Zero-Day

1/17-20/2025

Ukraine’s State Registers Restored Following Cyber-Attack

Indian APT Group DONOT Misuses App for Intelligence Gathering

U.S. Treasury Department Imposes Sanctions on Chinese Company Over Salt Typhoon Hack

FCC Orders Telecoms to Secure Their Networks After Salt Tyhpoon Hacks

Trump Revokes Biden Executive Order on Addressing AI Risks

Homeland Security Nominee Kristi Noem Bashes CISA, Says Agency Must Be ‘Smaller, More Nimble’

Tough New EU Cyber Rules Require Banks to Ramp up Security — But Many Aren’t Ready

TikTok Goes Dark in the U.S. as Federal Ban Takes Effect January 19, 2025

How to Get around the U.S. TikTok Ban

TikTok Restores Service for U.S. Users Based on Trump’s Promised Executive Order

Canadian IT Company OpenText Corporation Added to Moscow’s List of ‘Undesirable’ Organizations

Former CIA Analyst Pleads Guilty to Sharing Top Secret Files

Philippines Arrests Chinese National Suspected of Spying on Critical Infrastructure
Costa Rica Refinery Cyberattack Was First Deployment for New U.S. Response Program, Ambassador Says

Data on Half a Million Hotel Guests Exposed After Otelier Breach

HPE Launches Investigation After Hacker Claims Data Breach

Medusa Ransomware Group Claims Attack on UK’s Gateshead Council

LifeBridge Health (MD) Posts Notice of 2024 Data Breach Affecting Patient SSNs and Medical Info

Edw. C. Levy Co. (MI) Announces Data Breach Following Ransomware Attack

Hackers Deploy Malicious npm Packages to Steal Solana Wallet Keys via Gmail SMTP

Python-Based Bots Exploiting PHP Servers Fuel Gambling Platform Proliferation

Malicious PyPi Package Steals Discord Auth Tokens From Devs

Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation

Strategic Approaches to Threat Detection, Investigation & Response

FTC Orders GM to Stop Collecting and Selling Driver’s Data

FTC Cracks Down on Genshin Impact Gacha Loot Box Practices

1/16/2025

Biden’s Cyber Ambassador Urges Trump Not to Cede Ground to Russia and China in Global Tech Fight

Krebs: Chinese Innovations Spawn Wave of Toll Phishing Via SMS

Russian Star Blizzard Shifts Tactics to Exploit WhatsApp QR Codes for Credential Harvesting

Biden Issues 11th-Hour Cyber Executive Order

Trump’s Truth Social Users Targeted by Rampant Scams Online

GitHub’s Deepfake Porn Crackdown Still Isn’t Working

Middle Eastern Real Estate Fraud Grows with Online Listings

Enzo Biochem Settles Lawsuit Over 2023 Ransomware Attack for $7.5m

GDPR Complaints Filed Against TikTok, Temu for Sending User Data to China

U.S. Cracks Down on North Korean IT Worker Army With More Sanctions

Microsoft Expands Testing of Windows 11 Admin Protection Feature
Wolf Haldenstein Law Firm Says 3.5 Million Impacted by Data Breach

Carruth Compliance Consulting (OR) Sends Out Data Breach Letters Following December 2024 Cyberattack

Clop Ransomware Gang Names Dozens of Victims Hit by Cleo Mass-Hack, but Several Firms Dispute Breaches

Hackers Hide Malware in Images to Deploy VIP Keylogger and 0bj3ctivity Stealer

Python-Based Malware Powers RansomHub Ransomware to Exploit Network Flaws

Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint Manager

Researchers Find Exploit Allowing NTLMv1 Despite Active Directory Restrictions

W3 Total Cache Plugin Flaw Exposes 1 Million WordPress Sites to Attacks

New UEFI Secure Boot Vulnerability Could Allow Attackers to Load Malicious Bootkits

1/15/2025

Russian Espionage and Financial Theft Campaigns Have Ramped Up, Ukraine Cyber Agency Says

China’s Salt Typhoon Spies Spotted on U.S. Gov’t Networks Before Telcos, CISA Boss Says

North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains

Lazarus Group Targets Web3 Developers with Fake LinkedIn Profiles in Operation 99

UN Security Council Members Meet on Spyware for First Time

No New Funding in EU Plan to Tackle Ransomware Attacks Against Hospitals

Section 702 Surveillance Powers Remain ‘Indispensable,’ CIA Pick Ratcliffe Says

Federal Court Orders Massive Return of $9.3b in Bitcoin Stolen From Bitfinex in 2016 Hack

FTC Cracks Down on GoDaddy for Cybersecurity Failings

From Gmail to Word, Your Privacy Settings and AI Are Entering Into a New Relationship

DJI Loosens Flight Restrictions, Decides to Trust Operators to Follow FAA Rules

CISA Shares Guidance for Microsoft Expanded Logging Capabilities
Suspected Ukrainian Hackers Impersonating Russian Ministries to Spy on Industry

UnitedHealth Hid Its Change Healthcare Data Breach Notice for Months

Label Giant Avery Says Website Hacked to Steal Credit Cards

University of Oklahoma Isolates Systems After ‘Unusual Activity’ on IT Network

E-Benefit Solution Notifies Consumers of Recent Data Breach

EncompassCare (OH) Files Notice of Data Breach Affecting Consumers’ Social Security Numbers

Google Ads Users Targeted in Malvertising Scam Stealing Credentials and 2FA Codes

MikroTik Botnet Uses Misconfigured SPF DNS Records to Spread Malware

Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks

Google Cloud Researchers Uncover Flaws in Rsync File Synchronization Tool

SAP Fixes Critical Vulnerabilities in NetWeaver Application Servers

Microsoft: Happy 2025. Here’s 161 Security Updates (Krebs)

1/14/2025

North Korea Linked to Crypto Heists of Over $650 Million in 2024 Alone

U.S. Issues Final Rule Barring Chinese, Russian Connected Car Tech

Hegseth Says Debate Over Cyber Command, NSA Leadership Would Reach ‘Conclusion’

FBI Hacked Thousands of Computers to Make PlugX Malware Used by China Uninstall Itself

Biden Opens Federal Land for AI Data Centers, Sets Rules for Developers

The UK Wants to Do Its ‘Own Thing’ on AI Regulation, Suggesting a Divergence From U.S. And EU

UK Floats Ransomware Payout Ban for Public Sector

Wyze Cameras Will Use AI to Describe What They See

The ‘Largest Illicit Online Marketplace’ Ever Huione Guarantee Is Growing at an Alarming Rate, Report Says

Asset Manager Ashford Settles SEC Allegations It Failed to Disclose Extent of Hack
Russia’s Largest Platform for State Procurement Hit by Cyberattack From Pro-Ukraine Group

Connecticut City of West Haven Assessing Impact of Cyberattack

Tennessee-Based Mortgage Lender Confirms December Cyberattack

WP3.XYZ Malware Attacks Add Rogue Admins to 5,000+ WordPress Sites

Google OAuth Vulnerability Exposes Millions via Failed Startup Domains

Hackers Use FastHTTP in New High-Speed Microsoft 365 Password Attacks

Zero-Day Vulnerability Suspected in Attacks on Fortinet Firewalls with Exposed Interfaces

Microsoft January 2025 Patch Tuesday Fixes 8 Zero-Days, 159 Flaws

Snyk Appears to Deploy ‘Malicious’ Packages Targeting Cursor for Unknown Reason

New Startups Focus on Deepfakes, Data-in-Motion & Model Security

1/13/2025

Russian Malware Campaign Hits Kazakhstan and Central Asian Diplomatic Files

Turks and Caicos Recovering From Pre-Christmas Ransomware Attack

CISA Orders Agencies to Patch BeyondTrust Bug Exploited in Attacks

Poland Uncovers Russia-Linked Disinformation Campaign Targeting Upcoming Presidential Election

Rep. Don Bacon on Cyber Deterrence: ‘Speak Softly and Carry a Big-@$$ Stick’

Expired Domains Allowed Control Over 4,000 Backdoors on Compromised Systems

The Criminal Question in the Coming Wave of Pro-Crypto Legislation

Inside the Black Box of Predictive Travel Surveillance

Texas Sues Allstate, Alleging It Violated Data Privacy Rights of 45 Million Americans

WEF Warns of Growing Cyber Inequity Amid Escalating Complexities in Cyberspace
A Breach of Gravy Analytics’ Huge Trove of Location Data Threatens the Privacy of Millions

UK Domain Registry Nominet Confirms Breach via Ivanti Zero-Day

Cyberattack Forces Eindhoven University of Technology to Cancel Lectures

HCF Management (OH) Sends Data Breach Letters to Victims Following September 2024 Cyberattack

OneBlood Confirms Personal Data Stolen in July Ransomware Attack

Stolen Path of Exile 2 Admin Account Used to Hack Player Accounts

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners

Ransomware Abuses Amazon AWS Feature to Encrypt S3 Buckets

WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables

Microsoft: macOS Bug Lets Hackers Install Malicious Kernel Drivers

Microsoft 365 MFA Outage Fixed

1/10-12/2025

As China Hacking Threat Builds, Biden to Order Tougher Cybersecurity Standards

Silk Typhoon Treasury Hackers Also Breached Us Foreign Investments Review Office

Chinese Cyber-Spies Peek Over Shoulder of Officials Probing Real-Estate Deals Near American Military Bases

Phishing Texts Trick Apple iMessage Users Into Disabling Protection

Secret Phone Surveillance Tech Was Likely Deployed at 2024 DNC

Microsoft Sues Hacking Group Exploiting Azure AI for Harmful Content Creation

Pastor Who Saw Crypto Project in His “Dream” Indicted for Fraud

New York Sues to Recover $2 Million in Crypto Stolen in Remote Job Scams

DoJ Indicts Three Russians for Operating Crypto Mixers Used in Cybercrime Laundering

NSO Ruling Is a Victory for WhatsApp, but Could Have a Small Impact on Spyware Industry
Slovakia Hit by Historic Cyber-Attack on Land Registry

STIIIZY Data Breach Exposes Cannabis Buyers’ IDs and Purchases

Telefónica Confirms Internal Ticketing System Breach After Data Leak

The North Los Angeles County Regional Center Files Notice of Data Breach Following Apparent Ransomware Attack

Laramie County (WY) Library System Hit by Cyberattack

AI-Driven Ransomware FunkSec Targets 85 Victims Using Double Extortion Tactics

Fake PoC Exploit Targets Security Researchers with Infostealer

New Web3 Attack Exploits Transaction Simulations to Steal Crypto

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices

Docker Desktop Blocked on Macs Due to False Malware Alert

Scammers File First — Get Your IRS Identity Protection PIN Now

1/9/2025

Japan Faces Prolonged Cyber-Attacks Linked to China’s MirrorFace

Ivanti Zero-Day Attacks Infected Devices With Custom Chinese Malware

U.S. Treasury Hack Linked to Silk Typhoon Chinese State Hackers

How the U.S. TikTok Ban Would Actually Work

Google Messages Takes a Step Towards Secure Messaging Across Apps and Platforms (APK Teardown)

Apple Says Siri Isn’t Sending Your Conversations to Advertisers

EU Commission Liable for Breaching EU’s Own Data Protection Rules

New AI Challenges Will Test CISOs & Their Teams in 2025
Hackers Claim Massive Breach Gravy Analytics, the Parent Company of Location Data Giant Venntel, Threaten to Leak Data

Hackers Claim to Breach Russian State Agency Rosreestr Managing Property, Land Records

Largest U.S. Addiction Treatment Provider ​BayMark Health Services Notifies Patients of Data Breach

PowerSchool Says Hackers Stole Students’ Sensitive Data, Including Social Security Numbers, in Data Breach

Some Winston-Salem (NC) City Services Knocked Offline by Cyberattack

Fake CrowdStrike Job Offer Emails Target Devs With Crypto Miners

New Banshee Stealer Variant Bypasses Antivirus with Apple’s XProtect-Inspired Encryption

1/8/2025

Cyber Command Overhaul Gets Austin’s Approval, but Plan Faces Uncertain Future

Pall Mall Process to Tackle Commercial Hacking Proliferation Raises More Concerns Than Solutions

Russian ISP Confirms Ukrainian Hackers “Destroyed” Its Network

TikTok’s Fate Divides Trump and Fellow Republicans as Supreme Court Action Looms

Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections

Fake Government Officials Use Remote Access Tools for Card Fraud

Scammers Exploit Microsoft 365 to Target PayPal Users

Krebs: A Day in the Life of a Prolific Voice Phishing Crew
PowerSchool Hack Exposes Student, Teacher Data From K-12 Districts

Medical Billing Firm Medusind Discloses Breach Affecting 360,000 People

Pediatric Home Service (MN) Files Official Notice of Data Breach

Researchers Expose NonEuclid RAT Using UAC Bypass and AMSI Evasion Techniques

Hackers Exploit KerioControl Firewall Flaw to Steal Admin CSRF Tokens

Unpatched Critical Flaws Impact Fancy Product Designer WordPress Plugin

Ivanti Warns of New Connect Secure Flaw Used in Zero-Day Attacks

SonicWall Urges Admins to Patch Exploitable SSLVPN Bug Immediately

1/7/2025

‘We Have to Prioritize Cybersecurity’ Within Federal Budgets, Outgoing Cyber Czar Says

Cybercriminals Don’t Care About National Cyber Policy

Phishing Click Rates Triple in 2024

Finland Finds Russian ‘Spy’ Ship Anchor as Subsea Cable Company Demands Ship’s Seizure for Compensation

Former NSA Cyber Chief Joins Venture Firm DataTribe

U.S. Adds Web and Gaming Giant Tencent to List of Chinese Military Companies

U.S. Cyber Trust Mark Launches as the Energy Star of Smart Home Security

License Plate Readers Are Leaking Real-Time Video Feeds and Vehicle Data

Telegram Hands Over Data on Thousands of Users to U.S. Law Enforcement

UK Government to Ban Creation of Explicit Deepfakes

Washington State Sues T-Mobile Over 2021 Data Breach Security Failures

Meta Ends Fact-Checking on Facebook, Instagram in Free-Speech Pitch
Turbulence at UN Aviation Agency as Probe Into Potential Data Theft Begins

Pittsburgh Regional Transit Employees’, Applicants’ Personal Information Stolen During Ransomware Attack

Green Bay Packers’ Online Store Hacked to Steal Credit Cards

Casio Says Data of 8,500 People Exposed in October Ransomware Attack

Walker County Schools (GA) Alerting Parents, Educators of Student Information System Data Breach

Dragonfly Health (AZ) Files Notice of Data Breach with Federal Regulators

Hyperice (CA) Sends Data Breach Letters Following June 2024 Cyberattack

Teton Orthopaedics (WY) Sends Out Data Breach Letters Following Ransomware Attack

New Mirai Botnet Targets Industrial Routers With Zero-Day Exploits

CISA Warns of Critical Oracle, Mitel Flaws Exploited in Attacks

Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers

1/6/2025

U.S. Cyber Watchdog Says No Indication Breach at Treasury Hit Other Federal Agencies

Chinese Hackers Double Cyber-Attacks on Taiwan

Eagerbee Backdoor Deployed Against Middle Eastern Gov’t Orgs, ISPs

Russia Blames Telecom Network Accident for Widespread Internet Outage

India Proposes Digital Data Rules with Tough Penalties and Cybersecurity Requirements

IoT’s Regulatory Reckoning Is Overdue

Pig Butchering (Romance Baiting) Victim Sues Banks for Allowing Scammers to Open Accounts
Hackers Reportedly Compromise Argentina’s Airport Security Payroll System

School Districts in Maine, Tennessee Respond to Holiday Cyberattacks

Pacific Pulmonary Medical Group (CA) October 2024 Announces Data Breach

New Infostealer Campaign Uses Discord Videogame Lure

Cybercriminals Target Ethereum Developers with Fake Hardhat npm Packages

New PhishWP Plugin Enables Sophisticated Payment Page Scams

Vulnerable Moxa Devices Expose Industrial Networks to Attacks

MediaTek Rings in the New Year With a Parade of Chipset Vulns

1/3-5/2025

How Chinese Hackers Graduated From Clumsy Corporate Thieves to Military Weapons

U.S. Sanctions Chinese Cybersecurity Firm for Global Botnet Attacks

Cyber Investors Expect More Mergers in 2025

Cybersecurity Firm Tenable’s CEO Amit Yoran Dies After Battle With Cancer

Crypto Boss Extradited to Face $40bn Fraud Charges

Cryptocurrency Wallet Drainers Stole $494 Million in 2024

Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations

Windows 10 Users Urged to Upgrade to Avoid “Security Fiasco”

Russia Orders Yandex to Scrub Maps and Images of Strategic Oil Refinery
Atos Group Denies Space Bears’ Ransomware Attack Claims

Lexington Diagnostic Center (KY) Announces Recent Data Breach Involving Sensitive Patient Information

Tycon Medical Systems (VA) Sends Data Breach Letters Following Cybersecurity Incident

New FireScam Android Data-Theft Malware Poses as Telegram Premium App

PLAYFULGHOST Delivered via Phishing and SEO Poisoning in Trojanized VPN Apps

Bad Tenable Plugin Updates Take down Nessus Agents Worldwide

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution

1/2/2025

Treasury’s Sanctions Office Hacked by Chinese Government, Officials Say

‘Office of Foreign Assets Control’

‘No Definitive Link’ Found Between New Orleans Attack and Las Vegas Cybertruck Explosion, FBI Says

Global Campaign Targets PlugX Malware with Innovative Portal

Tighter Regulations Proposed for Foreign IT in Drones Used in U.S.

Apple Offers to Settle ‘Snooping Siri’ Lawsuit for an Utterly Incredible $95M

Crypto Hacks, Scam Losses Reach $29M in December, Lowest in 2024
Japan’s Largest Mobile Carrier Says Cyberattack Disrupted Some Services

Hackers Leak Rhode Island Citizens’ Data on Dark Web

Crown Mortgage Company (IL) Sends Data Breach Letters Following Recent Cybersecurity Incident

Over 3 Million Mail Servers Without Encryption Exposed to Sniffing Attacks

Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

12/31/2024-1/1/2025

What to Know about String of U.S. Hacks Blamed on China

U.S. Sanctions Russian & Iranian Groups Over AI-Generated Election Disinformation

Finland Identifies Seven Suspects Among Crew of Alleged Russian ‘Spy’ Tanker

Krebs: U.S. Army Soldier Arrested in AT&T, Verizon Extortions

Hey, Maybe It’s Time to Delete Some Old Chat Histories

Over 3.1 Million Fake “Stars” on GitHub Projects Used to Boost Rankings
Indiana University Health Announces Data Breach Following Compromised Email Account

New “DoubleClickjacking” Exploit Bypasses Clickjacking Protections on Major Websites

Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation

New Details Reveal How Hackers Hijacked 35 Google Chrome Extensions

The Biggest Cybersecurity and Cyberattack Stories of 2024

These Were the Badly Handled Data Breaches of 2024