3/31/2025

Krebs: How Each Pillar of the 1st Amendment is Under Attack

Cybersecurity Professor Xiaofeng Wang Mysteriously Disappears as FBI Raids His Homes

Canadian Hacker Arrested for Allegedly Stealing Data From Texas Republican Party

British Intel Intern Pleads Guilty to Smuggling Top Secret Data Out of Protected Facility

China Cracks Down on Personal Information Collection. No, Seriously

An AI Image Generator’s Exposed Database Reveals What People Really Used It For

Microsoft Uses AI to Find Flaws in GRUB2, U-Boot, Barebox Bootloaders

AI-Powered Cybersecurity Firm ReliaQuest Raises More Than $500 Million

U.S. Seizes $8.2m From Romance Baiting Scammers

EU Commission to Invest €1.3bn in Cybersecurity and AI

French Regulator Fines Apple $162 Million for Anticompetitive Use of Privacy Tool

FTC Says 23andMe Purchaser Must Uphold Existing Privacy Policy for Data Handling

CIOs and CISOs Need a Common Strategy Around AI Copilots
Moscow Subway App and Website Disrupted in Possible Retaliation for Ukraine Railway Hack

Russia-Linked Gamaredon Uses Troop-Related Lures to Deploy Remcos RAT in Ukraine

Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWisp

ClickFake Interview Campaign by Lazarus Targets Crypto Job Seekers

API Testing Firm APIsec Exposed Customer Data During Security Lapse

Oracle Under Fire for Its Handling of Separate Security Incidents

Check Point Confirms Breach, but Says It Was ‘Old’ Data and Crook Made ‘False’ Claims

United Domestic Workers of America (CA) Sends Out Data Breach Letters Following Apparent Cyberattack

Georgia Urology Notifies Patients of Data Breach Following Compromised Employee Email Accounts

Phishing Platform ‘Lucid’ Behind Wave of iOS, Android SMS Attacks

Evilginx Tool (Still) Bypasses MFA

Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site Images

Bridging the Gap Between the CISO & the Board of Directors

3/28-30/2025

Trump CISA Cuts Threaten U.S. Election Integrity, Experts Warn

Solar Power System Vulnerabilities Could Result in Blackouts

Nine in Ten Healthcare Organizations Use the Most Vulnerable IoT Devices

OpenAI Now Pays Researchers $100,000 for Critical Vulnerabilities

Hijacked Microsoft Web Domain Injects Spam Into SharePoint Servers

Madison Square Garden’s Surveillance System Banned This Fan Over His T-Shirt Design

Personal Info on Federal Judges Is Widely Accessible Online, Leading to Safety Risks
Oracle Health Breach Compromises Patient Data at U.S. Hospitals

Retail Giant Sam’s Club Investigates Clop Ransomware Breach Claims

Pacific Residential Mortgage (OR) Confirms Data Breach Following Recent Ransomware Attack

Phishing-As-A-Service Operation Uses DNS-Over-HTTPS for Evasion

New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials

RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features

New Ubuntu Linux Security Bypasses Require Manual Mitigations

3/27/2025

Chinese FamousSparrow Hackers Deploy Upgraded Malware in Attacks

APT36 Spoofs India Post Website to Infect Windows and Android Users with Malware

Two Serbian Journalists Reportedly Targeted With Pegasus Spyware

Krebs: When Getting Phished Puts You in Mortal Danger

Troy Hunt: A Sneaky Phish Just Grabbed my Mailchimp Mailing List

No MFA? Expect Hefty Fines, UK’s ICO Warns

UK Fines Software Provider £3.07 Million for 2022 Ransomware Breach

UK NCSC Urges Domain Registrars to Improve Security

Security Shop Pwns BlackLock Ransomware Gang, Passes Insider Info to Authorities

Vivaldi Integrates Proton VPN Into the Browser to Fight Web Tracking

WhatsApp’s Meta AI Is Now Rolling out in Europe, and It Can’t Be Turned Off

SignalGate Is Driving the Most U.S. Downloads of Signal Ever

European Officials Increasingly Certain Baltic Sea Cable Breaks Are Accidental, Not Sabotage

Russia Arrests Three for Allegedly Creating Mamont Malware, Tied to Over 300 Cybercrimes
Russian Media, Academia Targeted in Espionage Campaign Using Google Chrome Zero-Day Exploit

Ukraine’s State Railway Restores Online Ticket Sales After Major Cyberattack

Vulnerable Children’s Details at Risk in Data Cardiff Breach

150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling Platforms

PJobRAT Malware Targets Users in Taiwan via Fake Apps

New Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims’ DNS Email Records

Infostealer Campaign Compromises 10 Npm Packages, Targets Devs

Hackers Repurpose RansomHub’s EDRKillShifter in Medusa, BianLian, and Play Attacks

CoffeeLoader Malware Loader Linked to SmokeLoader Operations

Dozens of Solar Inverter Flaws Could Be Exploited to Attack Power Grids

NetApp SnapCenter Flaw Could Let Users Gain Remote Admin Access on Plug-In Systems

Mozilla Warns Windows Users of Critical Firefox Sandbox Escape Flaw

CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices

3/26/2025

Austria Uncovers Alleged Russian Disinformation Campaign Spreading Lies About Ukraine

RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment

New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican Organizations

U.S. Intel Leaders Are Grilled Again About the Leaked Signal Chat as More Details Emerge

Here Are the Attack Plans That Trump’s Advisers Shared on Signal

SignalGate Isn’t About Signal

DOGE Staffer ‘Big Balls’ Provided Tech Support to Cybercrime Ring, Records Show

SEC’s Hester Peirce Discusses New Approach to Crypto and Cyber Rule Making

Secure Browser Startup Island Raises $250 Million
Oracle Customers Confirm Data Stolen in Alleged Cloud Breach Is Valid

StreamElements Discloses Third-Party Data Breach After Hacker Leaks Data

SecurityScorecard Observes Surge in Third-Party Breaches

UK Warns of Emerging Threat From ‘Sadistic’ Online ‘Com Networks’ of Teenage Boys

Malicious npm Packages Deliver Sophisticated Reverse Shells

Threat Actors Abuse Trust in Cloud Collaboration Platforms

Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks

Cybersecurity Gaps Leave Doors Wide Open

Claude is Testing ChatGPT-Like Deep Research Feature Compass

3/25/2025

Lengthy Disruption of Russian Internet Provider Claimed by Ukrainian Hacker Group

Ukraine Railways Say Sunday’s Cyber Attack Hit Its Online Freight Services

Cyber Command Official Is Trump’s Choice for Pentagon Policy Job

What Is Signal, the Messaging App Trump Team Used to Share War Plans?

NSA Warned of Vulnerabilities in Signal App a Month Before Houthi Strike Chat

Senate Democrats Dissatisfied With Intel Officials’ Responses About Signal Chat

Signal Is App of Choice for Trump Allies and Opponents Alike

How to Tell if Your Online Accounts Have Been Hacked

Cloudflare R2 Service Outage Caused by Password Rotation Error

Flurry to Pay $3.5 Million for Harvesting Sexual and Reproductive Health Data From Period App

5 Considerations for a Data Loss Prevention Rollout
Hacker Defaces NYU Website, Exposing Admissions Data on 1 Million Students

Nearly $13 Million Stolen From Abracadabra Finance in Crypto Heist

Malaysia PM Says Country Rejected $10 Million Ransom Demand After Airport Outages

New Android Malware Uses .NET MAUI to Evade Detection

Cybercriminals Use Atlantis AIO to Target 140+ Platforms

Researchers Uncover ~200 Unique C2 Domains Linked to Raspberry Robin Access Broker

Browser-In-The-Browser Attacks Target CS2 Players’ Steam Accounts

EncryptHub Linked to MMC Zero-Day Attacks on Windows Aystems

New Windows Zero-Day Leaks NTLM Hashes, Gets Unofficial Patch

Broadcom Warns of Authentication Bypass in VMware Windows Tools

CrushFTP Warns Users to Patch Unauthenticated Access Flaw Immediately

3/24/2025

Chinese Weaver Ant Hackers Spied on Telco Network for 4 Years

APT ‘Weaver Ant’

The Trump Administration Accidentally Texted Me Its War Plans

SANS Institute Warns of Novel Cloud-Native Ransomware Attacks

23andMe Files for Bankruptcy, Customers Advised to Delete DNA Data

How to Delete Your Data From 23andMe

Google’s $32 Billion Wiz Deal May Signal a Turning Point for Slow IPO, M&A Markets

Authorities Seize 1842 Devices in Africa’s Cybercrime Crackdown

Alleged Snowflake Hacker Agrees to Be Extradited to the U.S.
Ukraine Railway Systems Hit by Targeted Cyber-Attack

Ukraine Sees Russian Effort to Sow Chaos

South Africa’s Astral Foods Hit by Cybersecurity Incident

Hackers Steal Sensitive Data From Union County (PA) During Ransomware Attack

DrayTek Routers Worldwide Go into Reboot Loops Over Weekend

VanHelsingRaaS Expands Rapidly in Cybercrime Market

Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication

Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization Checks

Google Gemini’s Astra (Screen Sharing) Rolls Out on Android for Some Users

3/21-23/2025

Trump Denies Musk to Be Briefed on Top-Secret Plan for Potential War With China

Trump Administration Begins Shifting Cyberattack Response to States

China-Linked APT Aquatic Panda: 10-Month Campaign, 7 Global Targets, 5 Malware Families

U.S. Treasury Lifts Tornado Cash Sanctions Amid North Korea Money Laundering Probe

Krebs: Arrests in Tap-to-Pay Scheme Powered by Phishing

FBI Warnings Are True—Fake File Converters Do Push Malware

Cloudflare Now Blocks All Unencrypted Traffic to Its API Endpoints

Major Web Services Go Dark in Russia Amid Reported Cloudflare Block

Microsoft: Exchange Online Bug Mistakenly Quarantines User Emails

Why Cyber Quality Is the Key to Security
Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories’ CI/CD Secrets Exposed

Oracle Denies Breach After Hacker Claims Theft of 6 Million Data Records

YouTube Account of Costa Rica’s Presidency Back Online After Cyber Attack

Steam Pulls Game Demo Infecting Windows With Info-Stealing Malware

Fake Semrush Ads Used to Steal SEO Professionals’ Google Accounts

Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates

Albabat Ransomware Evolves to Target Linux and macOS

Microsoft Trusted Signing Service Abused to Code-Sign Malware

Cybercriminals Exploit CheckPoint Antivirus Driver in Malicious Campaign

Veeam RCE Bug Lets Domain Users Hack Backup Servers, Patch Now

3/20/2025

Taiwan Critical Infrastructure Targeted by Hackers With Possible Ties to Volt Typhoon

FishMonger APT Group Linked to I-SOON in Espionage Campaigns

North Korea Launches New Unit With a Focus on AI Hacking, per Report

Low-Cost Drone Add-Ons From China Let Anyone With a Credit Card Turn Toys Into Weapons of War

U.S. Offers $15M Reward for Team Accused of Smuggling Drone Tech to Iran

Krebs: DOGE to Fired CISA Staff: Email Us Your Personal Data

More Than 400 Social Security Numbers, Other Private Information Revealed in JFK Files

Wiz Deal Buoys Cyber Startup Outlook

The Post-Quantum Cryptography Apocalypse Will Be Televised in 10 Years, Says UK’s NCSC

Rooted Devices 250 Times More Vulnerable to Compromise

Google Sues Alleged Scammers Over 10,000 Fake Maps Listings

Ex-Michigan Assistant Charged With Hacking Computer Accounts

China’s Baidu Denies Data Breach After Executive’s Daughter Leaks Personal Info
Major Web Services Go Dark in Russia Amid Reported Cloudflare Block

Malware Campaign ‘DollyWay’ Breached 20,000 WordPress Sites

HellCat Hackers Go on a Worldwide Jira Hacking Spree

GitHub Action Supply Chain Attack Exposed Secrets in 218 Repos

ESHYFT (NJ) Allegedly Leaves Database Exposed, Leading to Potentially Large-Scale Data Breach

Parascript (CO) Announces Data Breach Following August 2024 Ransomware Attack

RansomHub Ransomware Uses New Betruger ‘Multi-Function’ Backdoor

VSCode Extensions Found Downloading Early-Stage Ransomware

CISA Adds NAKIVO Vulnerability to KEV Catalog Amid Active Exploitation

Critical Cisco Smart Licensing Utility Flaws Now Exploited in Attacks

Veeam and IBM Release Patches for High-Risk Flaws in Backup and AIX Systems

WordPress Security Plugin WP Ghost Vulnerable to Remote Code Execution Bug

Kali Linux 2025.1a Released With 1 New Tool, Annual Theme Refresh

3/19/2025

U.S. Suspends Some Efforts to Counter Russian Sabotage as Trump Moves Closer to Putin

Ex-U.S. Cyber Command Chief: Europe and 5 Eyes Can’t Fully Replicate U.S. Intel

Hong Kong Aims to Safeguard Key Facilities With New Cybersecurity Law

Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia

Europol Warns of “Shadow Alliance” Between States and Criminals

WhatsApp Patched Zero-Click Flaw Exploited in Paragon Spyware Attacks

Researchers Name Six Countries as Likely Customers of Paragon’s Spyware

Click Profit Blocked by the FTC Over Alleged E-commerce Scams

Turkey Restricts Social Media Following Arrest of President’s Main Rival
Ukrainian Military Targeted in New Signal Spear-Phishing Attacks

Ukraine’s IT Army Keeps up Attacks on Russia Despite Waning Media Hype

Attackers Swipe Data of 500K+ People From Pennsylvania Teachers Union

Names, Bank Info, and More Spills From Top Sperm Bank California Cryobank

Sneaky 2FA Joins Tycoon 2FA and EvilProxy in 2025 Phishing Surge

New Arcane Infostealer Infects YouTube, Discord Users via Game Cheats

ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread Info-Stealers

Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners

Critical mySCADA myPRO Flaws Could Let Attackers Take Over Industrial Control Systems

3/18/2025

China Identifies Taiwanese Hackers Allegedly Behind Cyberattacks and Espionage

China-Linked MirrorFace Deploys ANEL and AsyncRAT in New Cyber Espionage Operation

Third of UK Supply Chain Relies on “Chinese Military” Companies

BlackBasta Ransomware Ties to Russian Authorities Uncovered

Poisoned Windows Shortcuts Found to Be a Favorite of Chinese, Russian, N. Korean State Hackers

Security Researcher Proves GenAI Tools Can Develop Google Chrome Infostealers

New ‘Rules File Backdoor’ Attack Lets Hackers Inject Malicious Code via AI Code Editors

New Report Highlights Common Passwords in RDP Attacks

Google Strikes $32 Billion Deal for Cybersecurity Startup Wiz

CISA Fires, Rehires & Immediately Benches Security Crew on Full Pay

This New Tool Lets You See How Much of Your Data Is Exposed Online – And It’s Free
GitHub Action Hack Likely Led to Another in Cascading Supply Chain Attack

Municipalities in Four States Are Struggling With Cyberattacks Limiting Services

Western Alliance Bank Notifies 21,899 Customers of Data Breach

Blockchain Gaming Platform WEMIX Hacked to Steal $6.1 Million

HELLCAT: Jaguar Land Rover Breach Highlights Growing Cybersecurity Risks in Automotive Sector

Grede Holdings (MI) Sends Out Round of Data Breach Letters Following January 2025 Cybersecurity Incident

New Ad Fraud Campaign Exploits 331 Apps with 60M+ Downloads for Phishing and Intrusive Ads

New Critical AMI BMC Vulnerability Enables Remote Server Takeover and Bricking

Apple Has Revealed a Passwords App Vulnerability That Lasted for Months

Unpatched Windows Zero-Day Flaw Exploited by 11 State-Sponsored Threat Groups Since 2017

3/17/2025

Cloudflare Introduces E2E Post-Quantum Cryptography Protections

U.S. Legislators Demand Transparency in Apple’s UK Backdoor Court Fight

States Vie for Fired Federal Cyber Workers

Google in Fresh Talks to Buy Cybersecurity Startup Wiz for $30 Billion

How Economic Headwinds Influence the Ransomware Ecosystem

OKX Suspends DEX Aggregator after Lazarus Hackers Try to Launder Funds

Telegram CEO Pavel Durov Leaves France Temporarily as Criminal Probe Continues
‘Mora_001’ Ransomware Gang Exploiting Fortinet Bug Spotlighted by CISA in January

Cherokee County School District (SC) Remains Offline After Data Breach

Microsoft: New RAT Malware Used for Crypto Theft, Reconnaissance

Researchers Confirm BlackLock as Eldorado Rebrand

Cybercriminals Exploit CSS to Evade Spam Filters and Track Email Users’ Actions

GitHub Action Compromise Puts CI/CD Secrets at Risk in Over 23,000 Repositories

Apache Tomcat Vulnerability Actively Exploited Just 30 Hours After Public Disclosure

3/14-16/2025

North Korea’s ScarCruft Deploys KoSpy Malware, Spying on Android Users via Fake Utility Apps

Krebs: ClickFix: How to Infect Your PC in Three Easy Steps

Apple Will Soon Support Encrypted RCS Messaging With Android Users

Google Refuses to Deny It Received Encryption Order From UK Government

A New Era of Attacks on Encryption Is Starting to Heat Up

New Akira Ransomware Decryptor Cracks Encryptions Keys Using GPUs

Top 10 Takeaways from the New HIPAA Security Rule NPRM

Infosys Settles Lawsuits Against U.S. Unit Over Cyber Incident for $17.5 Million

LockBit Ransomware Developer Extradited to U.S.

FCC Stands up Council on National Security to Fight China in Ways That CISA Used To
Europe’s Telecoms Sector Under Increased Threat From Cyber Spies, Warns Denmark

Ransomware Attack Takes Down Health System Network in Micronesia

Fraudsters Impersonate Clop Ransomware to Extort Businesses

Coinbase Phishing Email Tricks Users With Fake Wallet Migration

Malicious PyPI Packages Stole Cloud Tokens—Over 14,100 Downloads Before Removal

Malicious Adobe, DocuSign OAuth Apps Target Microsoft 365 accounts

Fake “Security Alert” Issues on GitHub use OAuth App to Hijack Accounts

OBSCURE#BAT Malware Uses Fake CAPTCHA Pages to Deploy Rootkit r77 and Evade Detection

Black Basta Ransomware Gang Creates Tool to Automate VPN Brute-Force Attacks

Cisco IOS XR Vulnerability Lets Attackers Crash BGP on Routers

3/13/2025

Volt Typhoon Accessed U.S. OT Network for Nearly a Year

Juniper Patches Bug That Let Chinese Cyberspies Backdoor Routers

‘People Are Scared’: Inside CISA as It Reels From Trump’s Purge

CISA: We Didn’t Fire Red Teams, We Just Unhired a Bunch of Them

White House Instructs Agencies to Avoid Firing Cybersecurity Staff, Email Says

Albania Starts Turning off TikTok Amid Concern Over Youth Violence

UK ICO Fires GDPR “Warning Shot” Over Use of Children’s Data

Calls Grow for UK to Move Secret Apple Encryption Court Hearing to Public Session
‘ClickFix’ Phishing Scam Impersonates Booking.com to Target Hospitality

Why the Toll Road Text Scam Is Out of Control Across the U.S., and Apple, Android Can’t Do Anything to Stop It

New SuperBlack Ransomware Exploits Fortinet Auth Bypass Flaws

Bank of America Warns Customers of Data Breach After Document Handling Mishap

Professional Law Enforcement Association (MI) Files Notice of Data Breach with State Attorney General

GitHub Uncovers New ruby-saml Vulnerabilities Allowing Account Takeover Attacks

Microsoft Apologizes for Removing VSCode Extensions Used by Millions

3/12/2025

Chinese Hackers Implant Backdoor Malware on Juniper Routers

This Is the FBI, Open Up. China’s Volt Typhoon Is on Your Network

Schools Use AI to Monitor Kids, Hoping to Prevent Violence. Our Investigation Found Security Risks

Machine Identities Outnumber Humans Increasing Risk Seven-Fold

Australia Regulator Sues FIIG Securities for Cybersecurity Failures

Cyber Reporting Rules Savaged in House Hearing

Trump Administration Shakes Up CISA with Staff and Funding Cuts

Trump’s FTC Advances Broad Antitrust Probe of Microsoft, Bloomberg News Reports

The Violent Rise of ‘No Lives Matter’

Signal No Longer Cooperating With Ukraine on Russian Cyberthreats, Official Says
Spyware in Bogus Android Apps Is Attributed to North Korean Group

New North Korean Android Spyware Slips Onto Google Play

Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack

Tata Technologies’ Data Leaked by Hunters International Ransomware Gang

CISA: Medusa Ransomware Hit Over 300 Critical Infrastructure Orgs

HOLT Group (TX) Files Notice of Data Breach Leaking Consumer’s Financial Information

Facebook Discloses FreeType 2 Flaw Exploited in Attacks

Mozilla Warns Users to Update Firefox Before Certificate Expires

Krebs: Microsoft with 6 Zero-Days in March 2025 Patch Tuesday

Microsoft Patches Windows Kernel Zero-Day Exploited Since 2023

3/11/2025

North Korean Lazarus Hackers Infect Hundreds via npm Packages

SideWinder APT Targets Maritime, Nuclear, and IT Sectors Across Asia, Middle East, and Africa

Blind Eagle Hacks Colombian Institutions Using NTLM Flaw, RATs and GitHub-Based Attacks

Sean Plankey Picked by Trump to Be CISA Director

University of South Florida Gets $40 Million to Start Cyber and AI College

95% of Data Breaches Tied to Human Error in 2024

Steganography Explained: How XWorm Hides Inside Images

Krebs: Alleged Co-Founder of Garantex Arrested in India

Trump Administration Ends FTC’s Ransomware Data Breach Case Against MGM Resorts

Balancing Cybersecurity Accountability & Deregulation
PowerSchool Previously Hacked in August, Months Before Data Breach

‘Uber for Nurses’ Exposes 86K+ Medical Records, PII in Open S3 Bucket for Months

MassJacker Malware Uses 778,000 Wallets to Steal Cryptocurrency

Ballista Botnet Exploits Unpatched TP-Link Vulnerability, Infects Over 6,000 Devices

Critical PHP RCE Vulnerability Mass Exploited in New Attacks

CISA Urges All Organizations to Patch Exploited Critical Ivanti and VeraCore Vulnerabilities

Moxa Issues Fix for Critical Authentication Bypass Vulnerability in PT Switches

Microsoft March 2025 Patch Tuesday Fixes 7 Zero-Days, 57 Flaws

Apple Fixes Webkit Zero-Day Exploited in ‘Extremely Sophisticated’ Attacks

This Is the One Security Fix Added in iOS 18.3.2 and More

3/10/2025

Multiple Outages at X Caused by ‘Massive Cyberattack,’ Musk Claims

X Hit by ‘Massive Cyberattack’ Amid Dark Storm’s DDoS Claims

UK AI Research Under Threat From Nation-State Hackers

Surge in Malicious Software Packages Exploits System Flaws

Switzerland Mandates Cyber-Attack Reporting for Critical Infrastructure

Allstate Insurance Sued for Delivering Personal Info on a Platter, in Plaintext, to Anyone Who Went Looking For It

Trump Administration Ends FTC’s Ransomware Data Breach Case Against MGM Resorts

U.S. Gov’t Says Americans Lost Record $12.5 Billion to Fraud in 2024

FTC Will Send $25.5 Million to Victims of Tech Support Scams

North Korean Lazarus Hackers Cash out Hundreds of Millions From $1.5bn ByBit Hack
Desert Dexter Targets 900 Victims Using Facebook Ads and Telegram Malware Links

SilentCryptoMiner Infects 2,000 Russian Users via Fake VPN and DPI Bypass Tools

Sunflower Medical Group (KS) Says More Than 220,000 Impacted by Cyberattack

Central Texas Pediatric Orthopedics Announces Data Breach Affecting at Least 90,000 People

What PowerSchool Won’t Say About Its Data Breach Affecting Millions of Students

Scam Spoofs Binance Website and Uses Trump Coin as Lure for Malware

SIM Swapping Fraud Surges in the Middle East

Researchers Expose New Polymorphic Attack That Clones Browser Extensions to Steal Credentials

Google Paid $12 Million in Bug Bounties Last Year to Security Researchers

3/7-9/2025

Two U.S. Army Soldiers Charged With Selling Military Secrets to China

White House Cyber Director’s Office Set for More Power Under Trump, Experts Say

Cyber Companies Stress AI as Core Future Technology

Palantir Delivers First Two AI-Enabled Systems to U.S. Army

Ransomware Groups Favor Repeatable Access Over Mass Vulnerability Exploits

YouTubers Extorted via Copyright Strikes to Spread Malware

Employee of Unnamed Company Charged With Stealing Unreleased Movies, Sharing Them Online

U.S. Seizes $23 Million in Crypto Linked to LastPass Breaches

Krebs: Feds Link $150M Cyberheist to 2022 LastPass Hacks

Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist

U.S. Charges Garantex Admins With Money Laundering, Sanctions Violations

Developer Guilty of Using Kill Switch to Sabotage Employer’s Systems

Undocumented Commands Found in Bluetooth Chip Used by a Billion Devices
Microsoft: North Korean Hackers Join Qilin Ransomware Gang

Data Breach at Japanese Telecom Giant NTT Hits 18,000 Companies

Home Appliance Company Presto Says Cyberattack Causing Delivery Delays

Chicago Public Schools Data Breach: What to Know, How It Affects You

RansomHub Hackers Leak Sensitive Data From Elite Bronx Private School Riverdale Country School After Ransomware Attack

Mission (TX) Declares State of Emergency After Cyberattack on Government Systems

Amerman Ginder (PA) Files Official Notice of Data Breach

A Brand-New Botnet Is Delivering Record-Size DDoS Attacks

U.S. Cities Warn of Wave of Unpaid Parking Phishing Texts

FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations

This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions

Unpatched Edimax IP Camera Flaw Actively Exploited in Botnet Attacks

Bug Affecting PHP Scripts Demands ‘Immediate Action From Defenders Globally’

3/6/2025

Russia Claims Ukraine Hacked State Youth Organizations to Recruit Minors

Trump’s Spy Chief Tulsi Gabbard Urged to Declassify Details of Secret Surveillance Program

Pentagon Cuts Threaten Programs That Secure Loose Nukes and Weapons of Mass Destruction

Krebs: Who is the DOGE and X Technician Branden Spikes?

The U.S. Army Is Using ‘CamoGPT’ to Purge DEI From Training Materials

Enterprise AI Through a Data Security Lens: Balancing Productivity With Safety

Why Security Leaders Are Opting for Consulting Gigs

Cybersecurity Job Satisfaction Plummets, Women Hit Hardest

It’s ‘Never Been Easier’ to Become an Online Scammer as Cybercrime Markets Flourish, Security Experts Warn

U.S. Seizes Domain of Garantex Crypto Exchange Used by Ransomware Gangs

Cybercrime ‘Crew’ Stole $635,000 in Taylor Swift Concert Tickets

Malicious Chrome Extensions Can Spoof Password Managers in New Attack

Armis Buys Otorio for $120M to Beef up Cybersecurity in Physical Spaces
Attackers Target Japanese Firms with Cobalt Strike

Thousands of Public School Workers Impacted by Cyberattack on Retirement Plan Administrator

Scott County (IA) Notifies Residents of Data Breach

FlexCare Sends Out Data Breach Letters Following Email Compromise

The Badbox Botnet Is Back, Powered by up to a Million Backdoored Androids

Microsoft Says Malvertising Campaign Impacted 1 Million PCs

Medusa Ransomware Hits 40+ Victims in 2025, Demands $100K–$15M Ransom

Akira Ransomware Gang Encrypted Network From a Webcam to Bypass EDR

EncryptHub Deploys Ransomware and Stealer via Trojanized Apps, PPI Services, and Phishing

Ethereum Private Key Stealer on PyPi Downloaded Over 1,000 Times

Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access

Vulnerability in Chaty Pro Plugin Exposes 18,000 WordPress Sites

Over 37,000 VMware ESXi Servers Vulnerable to Ongoing Attacks

Elastic Releases Urgent Fix for Critical Kibana Vulnerability Enabling Remote Code Execution

3/5/2025

Silk Typhoon Shifts Tactics to Exploit Common IT Solutions

Chinese APT Lotus Panda Targets Governments With New Sagerunex Backdoor Variants

12 Chinese Hackers Charged With U.S. Treasury Breach — And Much, Much More

DOJ to Appeal Court Decision Ruling Broad Cell Phone Tower Searches Are Unconstitutional

1 Million Third-Party Android Devices Have a Secret Backdoor for Scammers

Would-be Extortionists Send “BianLian” Ransom Notes in the Mail

Mass Federal Layoffs Will Hurt Cybersecurity, Former Top U.S. Security Official Says

Rural Hospitals in U.S. Need to Invest at Least $70 Million in Cybersecurity, Microsoft Finds
Qilin Ransomware Gang Claims Attacks on Cancer Clinic, OB-GYN Facility

Toronto Zoo Shares Update on Last Year’s Ransomware Attack

Two Decades of Visitor Data

Loyola University Maryland Sends Data Breach Letters Following July 2024 Cyberattack

Seven Malicious Go Packages Found Deploying Malware on Linux and macOS Systems

Microsoft Teams Tactics, Malware Connect Black Basta, Cactus Ransomware

Dark Caracal Uses Poco RAT to Target Spanish-Speaking Enterprises in Latin America

Open-Source Tool ‘Rayhunter’ Helps Users Detect Stingray Attacks

People Are Using Super Mario to Benchmark AI Now

3/4/2025

Russia to Redeploy Resources Freed up by End of War in Ukraine, Warns Finnish Intelligence

Polish Space Agency Offline as It Recovers From Cyberattack

North Koreans Finish Initial Laundering Stage After More Than $1 Billion Stolen From Bybit

North Korean Fake IT Workers Leverage GitHub to Build Jobseeker Personas

Private 5G Networks Face Security Risks Amid AI Adoption

YouTube Warns Creators an AI-Generated Video of Its CEO Is Being Used for Phishing Scams

Google Messages Is Using AI to Detect Scam Texts

It’s Bad Enough We Have to Turn on Cams for Meetings, Now the Person Staring at You May Be an AI Deepfake

Apple Reportedly Challenges the UK’s Secretive Encryption Crackdown

Catalan Court Orders Former NSO Group Executives Be Indicted for Spyware Abuses

Treasury Sanctions Iranian National Behind Defunct Nemesis Darknet Marketplace

Iran Linked to More Than 20 Plots to Kill or Kidnap British Citizens and Residents
Polyglot: New Cyber-Espionage Campaign Targets UAE Aviation and Transport

Over 4,000 ISP IPs Targeted in Brute-Force Attacks to Deploy Info Stealers and Cryptominers

New Eleven11bot Botnet Infects 86,000 Devices for DDoS Attacks

Gregory & Appel Insurance (IN) Announces Data Breach Impacting Consumer Social Security Numbers

Hunters International Ransomware Claims Attack on Tata Technologies

Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates

Dark Caracal Group Might Have Refreshed Its Malware, Researchers Say

Cisco Warns of Webex for BroadWorks Flaw Exposing Credentials

VMware Warns Customers to Patch Actively Exploited Zero-Day Vulnerabilities

Google’s March 2025 Android Security Update Fixes Two Actively Exploited Vulnerabilities

GreyNoise Intelligence Releases New Research on Cybersecurity Vulns

Half of Online Gambling Firms Lose 10% of Revenue to Fraud

3/3/2025

CISA Denies Reports of Shift in Cybersecurity Posture Amid Russian Threats

Finland Releases Russian ‘Spy’ Ship but Continues to Detain Three Crew Members as Suspects

Russian Telecom Beeline Facing Outages After Cyberattack

Vodafone Trials Quantum-Safe Tech to Protect Smartphone Browsing

Microsoft Unveils Finalized EU Data Boundary as European Doubt Over U.S. Grows

Governments Can’t Seem to Stop Asking for Secret Backdoors

ICO Launches TikTok, Reddit & Imgur Investigation Over Use of Children’s Data

Cybersecurity Not the Hiring-’Em-Like-Hotcakes Role It Once Was
Rubrik Rotates Authentication Keys After Log Server Breach

Palau Health Ministry on the Mend After Qilin Ransomware Attack

Lee Enterprises Ransomware Attack Hits Freelance and Contractor Payments

Penn-Harris-Madison Schools (IN) Combat Ransomware Attack, Systems Shut down as Precaution

ClickFix Phishing Campaign Uses Havoc Framework to Control Infected Systems

Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail

Attackers Leverage Microsoft Teams and Quick Assist for Access

CISA Tags Windows, Cisco Vulnerabilities as Actively Exploited

2/28-3/2/2025

Cyberattack Detected at Polish Space Agency, Minister Says

German Government Denies Foreign Election Interference Was Successful

Hegseth Orders Cyber Command to Stand down on Russia Planning

Amnesty Finds Cellebrite’s Zero-Day Used to Unlock Serbian Activist’s Android Phone

Krebs: Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab

The Biggest Data Breaches of 2025 — So Far

Third-Party Attacks Drive Major Financial Losses in 2024

U.S. Recovers $31 Million Stolen in 2021 Uranium Finance Hack

Cybersecurity M&A Roundup: SolarWinds Acquired for $4.4bn

The UK Will neither Confirm nor Deny That It’s Killing Encryption

China Tells Its AI Leaders to Avoid U.S. Travel Over Security Concerns

Prolific Data Extortion Actor Arrested in Thailand

Police Arrests Suspects Tied to AI-Generated CSAM Distribution Ring

California Shuts Down Data Broker for Failing to Register
Zapier Says Someone Broke Into Its Code Repositories and May Have Accessed Customer Data

India’s Angel One Says Assessing Impact After Security Breach

Qilin Ransomware Claims Attack at Lee Enterprises, Leaks Stolen Data

12,000+ API Keys and Passwords Found in Public Datasets Used for LLM Training

Microsoft Exposes LLMjacking Cybercriminals Behind Azure AI Abuse Scheme

Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus

Fake CAPTCHA PDFs Spread Lumma Stealer via Webflow, GoDaddy, and Other Domains

Ransomware Gangs Exploit Paragon Partition Manager Bug in BYOVD Attacks

Old Vulnerabilities Among the Most Widely Exploited

Ransomware Criminals Love CISA’s KEV List – And That’s a Bug, Not a Feature

C++ Creator Calls for Help to Defend Programming Language From ‘Serious Attacks’

Mozilla Updates Firefox Terms Again After Backlash Over Broad Data License Language