7/31/2025

Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies

The Kremlin’s Most Devious Hacking Group Turla Is Using Russian ISPs to Plant Spyware

Espionage Costing Australia $8 Billion Each Year, Warns Intelligence Chief

Nvidia Says Its Chips Have No ‘Backdoors’ After China Flags H20 Security Concerns

Spikes in Malicious Activity Precede New Security Flaws in 80% of Cases

Columbia University Fends Off Hackers by Going Back to Basics

Israeli Cyber Startup Noma Security Raises $100 Million to Keep AI Agents From Going Rogue

As Ransomware Gangs Threaten Physical Harm, ‘I Am Afraid of What’s Next,’ Ex-negotiator Says
N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in Crypto

DoubleTrouble Android Malware Targets Banking Users Through Discord Channels

Microsoft Now Pays up to $40,000 for Some .Net Vulnerabilities

Microsoft to Disable Excel Workbook Links to Blocked File Types

Kali Linux Can Now Run in Apple Containers on macOS Systems

CISA Unveils Eviction Strategies Tool to Aid Incident Response

CISA Open-Sources Thorium Platform for Malware, Forensic Analysis

Biotech Contractor Illumina Settles for $9.8 Million With DOJ Over Alleged Cybersecurity Lapses

Cybercriminals ‘Spooked’ After Scattered Spider Arrests

7/30/2025

More Than 90 State, Local Governments Targeted Using Microsoft Sharepoint Vulnerability, Group Says

Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools

Cyberattack Shuts Down Hundreds of Russian Pharmacies, Disrupts Healthcare Services

Russia Blocks Popular U.S.-Made Internet Speed Test Tool Over National Security Concerns

Krebs: Scammers Unleash Flood of Slick Online Gaming Sites

Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps

Warning Over Email Scam Using Fake Telecom Bills

FunkSec Ransomware Decryptor Released Free to Public After Group Goes Dormant

Dropbox Is Shutting Down Its Password Manager

More Than 100 Flights Cancelled After UK Air Traffic Control Issue

The TSA Likes Facial Recognition at Airports. Passengers and Politicians, Not So Much
SafePay Ransomware Threatens to Leak 3.5tb of Ingram Micro Data

ShinyHunters Behind Salesforce Data Theft Attacks at Qantas, Allianz Life, and LVMH

Dollar Tree Denies Ransomware Claims, Says Stolen Data Is From Defunct Discount Chain

Hidden Backdoor Found in ATM Network via Raspberry Pi

Hackers Actively Exploit Critical RCE in WordPress Alone Theme

Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits

New Lenovo UEFI Firmware Updates Fix Secure Boot Bypass Flaws

Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome

Third of Exploited Vulnerabilities Weaponized Within a Day of Disclosure

Google to Publicly Report New Vulnerabilities Within One Week of Vendor Disclosure

Schools Are Next for Flock Safety’s Automatic License Place Reader Cameras

7/29/2025

Minnesota Activates National Guard After St. Paul Cyberattack

Poland Says More Than 30 Suspects Face Trial Over Pro-Russian Sabotage

Wyden Asks White House to Scrutinize UK Surveillance Laws

Senator Presses Musk on Starlink ‘Misuse’ by Southeast Asian Scammers

Google Workspace Is Rolling Out a Security Update to Stop Token Stealing Attacks

Charity Birthlink Fined After Destroying “Irreplaceable” Records

FBI Seizes $2.4m in Crypto from Chaos Ransomware Gang

Palo Alto Networks Nears Over $20 Billion Deal for Cybersecurity Firm CyberArk
Sex Toy Maker Lovense Caught Leaking Users’ Email Addresses and Exposing Accounts to Takeovers

French Telco Orange Hit by Cyber-Attack

Scattered Spider Is Targeting Victims’ Snowflake Data Storage for Quick Exfiltration

Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain

Nimble ‘Gunra’ Ransomware Evolves With Linux Variant

Auto-Color Backdoor Malware Exploits SAP Vulnerability

Critical Authentication Flaw Identified in Base44 Vibe Coding Platform

7/28/2025

Flights Grounded as Russia’s Largest Airline Aeroflot Hacked and Systems ‘Destroyed’

‘Partisans’ Who Paralyzed Russian Airports Have Track Record of Disruptive Hacks

Naval Group Denies Hack Claims, Alleges “Reputational Attack”

Microsoft: macOS Sploitlight Flaw Leaks Apple Intelligence Data

The UK Is Slogging Through an Online Age-Gate Apocalypse

An Inside Look Into How a Coalition of State Legislators Plans to Take On Data Brokers

The Internet Archive Is Now a U.S. Federal Depository Library
Tea App Leak Worsens With Second Database Exposing User Chats

Endgame Gear Mouse Config Tool Infected Users With Malware

CISA Flags Papercut RCE Bug as Exploited in Attacks, Patch Now

Exploit Available for Critical Cisco ISE Bug Exploited in Attacks

Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide

Flaw in Gemini CLI AI Coding Assistant Allowed Stealthy Code Execution

New York State Cyber Chief Calls Out Trump for Cybersecurity Cuts

7/25-27/2025

Patchwork Targets Turkish Defense Firms with Spear-Phishing Using Malicious LNK Files

Microsoft Probing if Chinese Hackers Learned Sharepoint Flaws Through Alert

Cyber Espionage Campaign ‘CargoTalon’ Hits Russian Aerospace Sector Using EAGLET Backdoor

‘Quishing’ Scams Dupe Millions of Americans as Cybercriminals Turn the QR Code Bad

Scattered Spider is Running a VMware ESXi Hacking Spree

Amazon AI Coding Agent Hacked to Inject Data Wiping Commands

SpaceX Probes for Cause of Starlink’s Global Satellite Network Outage

U.S. Sanctions North Korean Firm, Nationals Behind IT Worker Schemes
Allianz Life Confirms Data Breach Impacts Majority of 1.4 Million Customers

Women’s Dating App Tea Reports 72,000 Images Stolen in Security Breach

Parents Concerned After Personal Information of Hundreds of Dearborn Heights (MI) Children Exposed Online

NASCAR Confirms Data Breach After March Cyberattack

Email Scam Demanding Money Targets Hull University

New Chaos Ransomware Emerges, Launches Wave of Attacks

Post SMTP Plugin Flaw Exposes 200K WordPress Sites to Hijacking Attacks

Security Awareness: Why Security Nudges Majorly Took Off

7/24/2025

China-Based APTs Deploy Fake Dalai Lama Apps to Spy on Tibetan Community

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

Satya Nadella Seeks to Reassure Microsoft Employees in Layoffs Memo

Microsoft Put Older Versions of Sharepoint on Life Support. Hackers Are Taking Advantage

DHS and HHS Among Federal Agencies Hacked in Microsoft Sharepoint Breach

Microsoft Says Some SharePoint Server Hackers Now Using Ransomware

U.S. Lawmaker Presses for Details of Pentagon Use of Chinese Engineers Under Microsoft Deal

Temu Lawsuits Pit States Against a Digital Superpower

UK and Romania Crack Down on ATM Fraudster Network

BlackSuit Ransomware Leak Sites Seized in Operation Checkmate

FBI Exposes The Com’s Criminal Activities and Involvement of Minors

U.S. Woman Gets 8-Year Sentence for Stealing Identities to Give North Koreans Jobs
A Premium Luggage Service’s Web Bugs Exposed the Travel Plans of Every User—Including Diplomats

Krebs: Phishers Target Aviation Execs to Scam Customers

SarangTrap: Malware Campaign Masquerades as Dating Apps to Steal Data

New Koske Linux Malware Hides in Cute Panda Images

Hacker Sneaks Infostealer Malware Into Early Access Steam Game

Soco404: Active Campaign Exploits Cloud Flaws for Cryptomining

CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing

Hackers Breach Toptal Github Account, Publish Malicious npm Packages

Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access

Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems

Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices

Why ISO 42001 Matters for AI Governance at Scale

7/23/2025

U.S. Nuclear Weapons Agency Reportedly Breached in Microsoft Sharepoint Attacks

CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

Microsoft SharePoint Victim Count Hits 400+ Orgs in Ongoing Attacks

Nothing to See Here: Brave Browser Blocks Privacy-Busting Microsoft Recall

Proton Is Launching a Privacy-Focused AI Chatbot

ChatGPT Is Rolling Out ‘Personality’ Toggles to Become Your Assistant

After $380M Hack, Clorox Sues Its “Service Desk” Vendor for Simply Giving Out Passwords

Suspected XSS Forum Admin Arrested in Ukraine

5 Nevada Men Sentenced to Prison for Running Jetflicks Pirated Content Site

Russia Turns to Kyrgyzstan’s Booming Crypto Sector to Evade Sanctions, Researchers Say
France: New Data Breach Could Affect 340,000 Jobseekers

Radiology Associates of Richmond Data Breach Affects 1.4 Million Patients

Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware

CISA Warns: SysAid Flaws Under Active Attack Enable Remote File Access and SSRF

NPM Package ‘Is’ With 2.8m Weekly Downloads Infected Devs With Malware

NPM ‘Accidentally’ Removes Stylus Package, Breaks Builds and Pipelines

VMware Prevents Some Perpetual License Holders From Downloading Patches

New York Unveils New Cyber Regulations, $2.5 Million Grant Program for Water Systems

IRL Com Recruits Teens for Real-Life Stabbings, Shootings, FBI Warns

7/22/2025

Microsoft Says Chinese Hacking Groups Are Behind Sharepoint Attacks

Linen Typhoon, Violet Typhoon & Storm-2603

Microsoft Knew of SharePoint Security Flaw but Failed to Effectively Patch It, Timeline Shows

Russian Threat Actors Target NGOs with New OAuth Phishing Tactics

YouTube Wipes Out Thousands of Propaganda Channels Linked to China, Russia, Others

Russian-Speaking Hacker Group Disrupted by Local Researchers

Silicon Valley Engineer Admits Theft of U.S. Missile Tech Secrets

UK Confirms Ransomware Payment Ban for Public Sector and CNI

UK Government Wants Ransomware Victims to Report Breaches So It Can Carry Out ‘Targeted Disruptions’ Against Hackers

Australian Regulator Alleges Financial Firm Exposed Clients to Unacceptable Cyber Risks

Citizen Will Share Crime Videos With the NYPD

AI’s High Cost Pushes Smaller Cybersecurity Companies to Sell
Major European Healthcare Network AMEOS Group Discloses Security Breach

158-Year-Old Company Knights of Old Forced to Close After Ransomware Attack Precipitated by a Single Guessed Password — 700 Jobs Lost After Hackers Demand Unpayable Sum

Widespread Net RFQ Scam Targets High-Value Goods

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate

CISA and FBI Warn of Escalating Interlock Ransomware Attacks

Lumma Infostealer Malware Returns After Law Enforcement Disruption

Coyote Malware Abuses Windows Accessibility Framework for Data Theft

Arch Linux Users Told to Purge Firefox Forks After AUR Malware Scare

Cisco Confirms Active Exploits Targeting ISE Flaws Enabling Unauthenticated Root Access

Critical Infrastructure Security Is a Critical Concern

Humans Can Be Tracked With Unique ‘Fingerprint’ Based on How Their Bodies Block Wi-Fi Signals

7/21/2025

China Denies Link to Espionage Group Accused of Attacking Singapore Critical Infrastructure

China-Linked APT41 Hackers Launch Targeted Espionage Campaign on African IT Infrastructure

Iranian Hackers Deploy New Android Spyware Version

This ‘Violently Racist’ Hacker Claims to Be the Source of the New York Times’ Mamdani Scoop

Malicious Implants Are Coming to AI Components, Applications

Poland Investigates Sabotage After Air Traffic Control Disruption Delayed Flights

Alaska Airlines Lifts Ground Stop Caused by Software Outage

UK Wants to Weasel Out of Demand for Apple Encryption Back Door

Ring Reintroduces Video Sharing With Police

Intel Announces End of Clear Linux OS Project, Archives GitHub Repos
Krebs: Microsoft Fix Targets Attacks on SharePoint Zero-Day

Microsoft Server Hack Hit About 100 Organizations, Researchers Say

Dell Confirms Breach of Test Lab Platform by World Leaks Extortion Group

Ring Denies Breach After Users Report Suspicious Logins

Dior Begins Sending Data Breach Notifications to U.S. Customers

Indian Crypto Exchange CoinDCX Says $44 Million Stolen from Reserves

ExpressVPN Bug Leaked User IPs in Remote Desktop Sessions

3,500 Websites Hijacked to Secretly Mine Crypto Using Stealth JavaScript and WebSocket Tactics

Accounting Firm Targeted by Malware Campaign Using New Crypter Ghost Crypt

Fake Receipt Generators Fuel Rise in Online Fraud

7/18-20/2025

Singapore Says Cyber Espionage Group UNC3886 Targeting Critical Infrastructure

Microsoft to Stop Using Engineers in China for Tech Support of U.S. Military, Hegseth Orders Review

How China’s Patriotic ‘Honkers’ Became the Nation’s Elite Cyberspies

UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns

Russia APT28 Linked to New Malware ‘Authentic Antics’ Targeting Email Accounts for Espionage

Krebs: Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai

Ex-IDF Cyber Chief on Iran, Scattered Spider, and Why Social Engineering Worries Him More Than 0-Days

New Phobos and 8Base Ransomware Decryptor Recover Files for Free

Retail Becomes New Target as Healthcare Ransomware Attacks Slow

At Least 750 U.S. Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds

Securing the Budget: Demonstrating Cybersecurity’s Return
Malware Injected into 5 npm Packages After Maintainer Tokens Stolen in Phishing Attack

AI-Generated Lcryx Ransomware Discovered in Cryptomining Botnet

Arch Linux Pulls AUR Packages that Installed Chaos RAT Malware

Threat Actors Downgrade FIDO2 MFA Auth in PoisonSeed Phishing Attack

EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware

HPE Warns of Hardcoded Passwords in Aruba Access Points

Hackers Scanning for TeleMessage Signal Clone Flaw Exposing Passwords

Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers

Ivanti Zero-Days Exploited to Drop MDifyLoader and Launch In-Memory Cobalt Strike Attacks

Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company Servers

CISA Issues Advisories on Critical ICS Vulnerabilities Across Multiple Sectors

Citrix Bleed 2 Exploited Weeks Before PoCs as Citrix Denied Attacks

7/17/2025

Personal Details of UK Special Forces and Spies Were Included in Afghan Data Breach

Lawmakers Call On DNI to Review Intel Sharing With Spain Over Huawei Revelations

AI Cloaking Tools Enable Harder-to-Detect Cyber-Attacks

Microsoft Exposes Scattered Spider’s Latest Tactics

One in 12 US/UK Employees Uses Chinese GenAI Tools

Crypto Crime in 2025 Is Topping Last Year’s Totals Already

Quantum Code Breaking? You’d Get Further With an 8-Bit Computer, an Abacus, and a Dog

Google Sues to Disrupt BadBox 2.0 Botnet Infecting 10 Million Devices

Armenian, Ukrainian Nationals Among Ryuk Ransomware Actors Facing U.S. Hacking Charges

UK NCA Officer Jailed for Stealing Bitcoin From Darknet Criminal He Previously Helped Investigate

Meta Investors, Zuckerberg Settle $8 Billion Privacy Lawsuit Tied to Cambridge Analytica Scandal

Elite Russian University Launches Degree Program on Sanctions Evasion
Thai Officials Restore Ministry of Labor Website After Hack, Defacement

Co-op Confirms Data of 6.5 Million Members Stolen in Cyberattack

Hacker Steals $27 Million in BigONE Exchange Crypto Breach

Russian Vodka Producer Reports Disruptions After Ransomware Attack

Mower County (MN) Still Working to Restore Systems After Cyber Attack

Malware-as-a-Service Campaign Exploits GitHub to Deliver Payloads

Hackers Are Finding New Ways to Hide Malware in DNS Records

LameHug Malware Uses AI LLM to Craft Windows Data-Theft Commands in Real-Time

Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency Miner

Cisco Warns of Critical ISE Flaw Allowing Unauthenticated Attackers to Execute Root Code

VMware Fixes Four ESXi Zero-Day Bugs Exploited at Pwn2Own Berlin

Why Cybersecurity Still Matters for America’s Schools

7/16/2025

Ukrainian Hackers Claim to Have Destroyed Major Russian Drone Maker’s Entire Network

What We Know So Far About Afghan Data Breach

China-Linked Hackers Target Taiwan’s Chip Industry With Increasing Attacks, Researchers Say

Senate Panel Passes Intelligence Authorization Act That Takes Aim At Telecom Hacks

Chinese Authorities Are Using a New Tool to Hack Seized Phones and Extract Data

Dark Web Travel Agencies Take Flight

Cloudflare Says 1.1.1.1 Outage Not Caused by Attack or BGP Hijack

Pro-Russian Cybercrime Network NoName057(16) Demolished in Operation Eastwood

Co-op Aims to Divert More Young Hackers into Cyber Careers
Adoption Agency Data Exposure Revealed Information About Children and Parents

Louis Vuitton Says Regional Data Breaches Tied to Same Cyberattack

DragonForce Claims Belk Data Breach from May, Says Belk Refuse to Pay Up

SquidLoader Malware Campaign Targets Hong Kong Financial Sector

Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms

New Konfety Malware Variant Evades Detection by Manipulating APKs and Dynamic Code

New Fortinet FortiWeb Hacks Likely Linked to Public RCE Exploits

UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit

Urgent: Google Releases Critical Chrome Update for CVE-2025-6558 Exploit Active in the Wild

7/15/2025

U.S. National Guard Unit Was ‘Extensively’ Hacked by Salt Typhoon in 2024, Memo Says

NSA: Volt Typhoon Was ‘Not Successful’ at Persisting in Critical Infrastructure

State-Backed HazyBeacon Malware Uses AWS Lambda to Steal Data from SE Asian Governments

North Korean Actors Expand Contagious Interview Campaign with New Malware Loader XORIndex

Krebs: DOGE Denizen Marko Elez Leaked API Key for xAI

MITRE Launches New Framework to Tackle Crypto Risks

ICEBlock Isn’t ‘Completely Anonymous’

Ex-U.S. Soldier Who Googled ‘Can Hacking Be Treason’ Pleads Guilty to Extortion

Police Disrupt “Diskstation” Ransomware Gang Attacking NAS Devices
Louis Vuitton Says Customers in Turkey, South Korea and UK Impacted by Data Breaches

Albemarle County (VA) IDs INC Ransom Group Behind Ransomware Attack

Threat Actors Exploit SVG Files in Stealthy JavaScript Redirects

AsyncRAT’s Open-Source Code Sparks Surge in Dangerous Malware Variants Across the Globe

Android Malware Konfety Uses Malformed APKs to Evade Detection

Hyper-Volumetric DDoS Attacks Reach Record 7.3 Tbps, Targeting Key Global Sectors

Google Says ‘Big Sleep’ AI Tool Found Bug Hackers Planned to Use

Curl Creator Mulls Nixing Bug Bounty Awards to Stop AI Slop

Abacus Dark Web Market Shutters After Exit Scam, Say Experts

7/14/2025

Russia-Linked Group Storm-1516 Spoofing European Journalists to Spread Disinformation

Elmo’s Hacked X Account Posted Racist Messages. Sesame Workshop Is Trying to Regain Control

Grok-4 Jailbroken Two Days After Release Using Combined Attack

AI ‘Nudify’ Websites Are Raking in Millions of Dollars

CBI Shuts Down £390K U.K. Tech Support Scam, Arrests Key Operatives in Noida Call Center

Romanian Police Arrest 13 Scammers Targeting UK’s Tax Authority

Piracy Sites for Nintendo Switch, PS4 Games Taken Down by FBI

Federal IT Contractor Hill Associates to Pay $14.75 Fine Over ‘Cyber Fraud’ Allegations
Gardendale (AL) Purportedly Compromised by INC Ransom Group

Malicious VSCode Extension in Cursor IDE Led to $500K Crypto Theft

Interlock Ransomware Unleashes New RAT in Widespread Campaign

Gigabyte Motherboards Vulnerable to UEFI Malware Bypassing Secure Boot

IoT Devices at Risk Due to eSIM Flaw in Kigen eUICC Cards

Exploited Wing File Transfer Bug Risks ‘Total Server Compromise,’ CISA Warns

UK Launches Vulnerability Research Program for External Experts

The Dark Side of Global Power Shifts & Demographic Decline

7/11-13/2025

MPs Warn of “Significant” Iranian Cyber-Threat to UK

Spain Awards Huawei Contracts to Manage Intelligence Agency Wiretaps

Former Mexican President Investigated Over Allegedly Taking Bribes From Spyware Industry

Mounting Ransomware Gang Prevalence Met With Decline in Victimization

Trump Blocks Acquisition of Equipment Supplier Jupiter Systems by Hong Kong Firm

TikTok Loses Bid to Dismiss Lawsuit Alleging Its ‘Addictive Design’ Exploits Kids

Over Half of “Finfluencer” Victims Have Lost Money, Says TSB

Google Gemini Flaw Hijacks Email Summaries for Phishing

Airline Executive Agrees to Dismiss Litigation Around Alleged Hack-For-Hire Scheme

British Man Sentenced for Network Rail Wi-Fi Hack

Indonesia Extradites Russian Accused of Selling Personal Data on Telegram

ISACA Addresses Experience Gap with CISA Associate Designation
Louis Vuitton Says UK Customer Data Stolen in Cyber-Attack

Hacker Returns Cryptocurrency Stolen From GMX Exchange After $5 Million Bounty Payment

GPUHammer: New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs

WordPress Gravity Forms Developer Hacked to Push Backdoored Plugins

Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub

Hackers Are Exploiting Critical RCE Flaw in Wing FTP Server

Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild

Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)

CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises

Windows 11 Now Uses JScript9Legacy Engine for improved Security

Factoring Cybersecurity Into Finance’s Digital Strategy

7/10/2025

Security Through Quality: Navigating the Latest Cybersecurity Executive Order

Hackers Target Eldercare Homes

New AI Malware PoC Reliably Evades Microsoft Defender

LLMs Fall Short in Vulnerability Discovery and Exploitation

Krebs: UK Arrests Four in ‘Scattered Spider’ Ransom Group

Russian Pro Basketball Player Arrested in France for Alleged Role in Ransomware Attacks

Ex-ASML Engineer Who Stole Chip Tech for Russia Gets Three Years in Dutch Prison

Lovestruck U.S. Air Force Worker Admits Leaking Secrets on Dating App

Windows 11 Now Uses JScript9Legacy Engine for Improved Security
Nippon Steel IT Subsidiary Hit by “Zero-Day Attack,” Causing Data Breach

Albemarle County (VA) Warns of Cybersecurity Breach

Florida Lung, Asthma and Sleep Specialists Warn Patients of Data Breach After Russian Group Claims Responsibility

Microsoft Outlook Hit With Hours-Long Outage

Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord

New ZuRu Malware Variant Targeting Developers via Trojanized Termius macOS App

Critical MCP-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads

PerfektBlue Bluetooth Flaws Impact Mercedes, Volkswagen, Skoda Cars

7/9/2025

French Intel Chief Warns of Evolving Russian Hybrid Operations, ‘Existential Threat’ to Europe

Rubio Impersonator Signals Growing Security Threat From Deepfakes

DoNot APT Expands Operations, Targets European Foreign Ministries with LoptikMod Malware

Fake CNN and BBC Sites Used to Push Investment Scams

After Setback, Tech Firms Renew Push for Federal AI Regulation

Israel’s Cyberstarts Launches $300 Million Fund to Help Startups Retain Talent

Microsoft Authenticator on iOS Moves Backups Fully to iCloud

Samsung Announces Major Security Enhancements Coming to One UI 8

Google Reveals Details on Android’s Advanced Protection for Chrome

German Court Rules Meta Tracking Technology Violates European Privacy Laws

Treasury Sanctions North Korean Over IT Worker Malware Scheme

Know Your Enemy: Understanding Dark Market Dynamics
McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Using the Password ‘123456’

Ransomware Attack Stops Nova Scotia Power Meter Readings

M&S Confirms Social Engineering Led to Massive Ransomware Attack

Qantas Confirms Data Breach Impacts 5.7 Million Customers

Bitcoin Depot Breach Exposes Data of Nearly 27,000 Crypto Users

More Than $40 Million Stolen From GMX Crypto Platform

Ingram Micro Starts Restoring Systems After Ransomware Attack

New Android TapTrap Attack Fools Users With Invisible UI Trick

Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to Targets

New ServiceNow Flaw Lets Attackers Enumerate Restricted Data

Ruckus Networks Leaves Severe Flaws Unpatched in Management Devices

AMD Warns of New Meltdown, Spectre-Like Bugs Affecting CPUs

Krebs: Microsoft Patch Tuesday, July 2025 Edition

7/8/2025

Imposter Used AI to Pose as Marco Rubio and Contact Foreign Ministers

Suspected Chinese Silk Typhoon Cybersnoop Grounded in Italy After U.S. Tipoff

Iranian Ransomware Group Pay2Key.I2P Offers Bigger Payouts for Attacks on Israel, U.S.

Over 500 Scattered Spider Phishing Domains Poised to Target Multiple Industries

BaitTrap: Over 17,000 Fake News Websites Caught Fueling Investment Fraud Globally

4 Critical Steps in Advance of 47-Day SSL/TLS Certificates

SatanLock Ransomware to Leak All Stolen Data as Operation Shuts Down

Unless Users Take Action, Android Will Let Gemini Access Third-Party Apps

Chinese Video Surveillance Vendor Hikvision to Fight Canadian Ban

British Criminals Convicted Over Wagner Group-Linked Arson Attack on London Warehouse
UK Companies Should Have to Disclose Major Cyberattacks, Marks & Spencer Says

Marks & Spencer Chair Refuses to Say if Retailer Paid Hackers After Ransomware Attack

Activision Took Down Call of Duty Game After PC Players Hacked

Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play

Researchers Reveal 18 Malicious Chrome and Edge Extensions Disguised as Everyday Tools

Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension

RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks

Public Exploits Released for Citrix Bleed 2 NetScaler Flaw, Patch Now

Microsoft July 2025 Patch Tuesday Fixes One Zero-Day, 137 Flaws

CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active Exploitation

7/7/2025

Cyberattack Deals Blow to Russian Firmware Used to Repurpose Civilian Drones for Ukraine War

TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors

‘Batavia’ Windows Spyware Campaign Targets Dozens of Russian Orgs

Hundreds of Malicious Domains Registered Ahead of Prime Day

SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools

Hackers Target Employee Credentials Amid Spike in ID Attacks

Employee Gets $920 for Credentials Used in $140 Million Bank Heist
Russia’s St. Petersburg Hit by Major Internet Outage Amid Drone Strike Warnings

Qantas Is Being Extorted in Recent Data-Theft Cyberattack

Nearly 300,000 People Were Impacted by Cyberattack on Nova Scotia Power

Beware of Bert: New Ransomware Group Targets Healthcare, Tech Firms

Hackers Abuse Leaked Shellter Red Team Tool to Deploy Infostealers

Atomic macOS Infostealer Adds Backdoor for Persistent Attacks

Researchers Share CitrixBleed 2 Detection Analysis After Initial Hold

TikTok Recruits Senior UK Privacy Regulator as It Battles Fine and Investigation

7/4-6/2025

NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors

Ransomware: Hunters International Is Not Shutting Down, It’s Rebranding

Massive Spike in Use of .es Domains for Phishing Abuse

Qantas Attack Reveals One Phone Call Is All It Takes to Crack Cybersecurity’s Weakest Link: Humans

Android 16 Can Warn You That You Might Be Connected to a Fake Cell Tower

Taiwan Flags Chinese Apps Over Data Security Violations
Ingram Micro Confirms SafePay Ransomware Behind Multi-Day Outage

Hacker Leaks Telefónica Data Allegedly Stolen in a New Breach

Louis Vuitton Korea Says Systems Breach Led to Customer Data Leak

Coinbase Director Flags Possible Hack Behind $8B Bitcoin Awakening

WordPress Plugin Flaw Exposes 600,000 Sites to File Deletion

Leaks Hint at Operator-Like Tool in ChatGPT Ahead of GPT-5 Launch

South Korea Penalises ‘Negligent’ SK Telecom Over Major Data Leak

7/3/2025

Two New Pro-Russian Hacktivist Groups Target Ukraine, Recruit Insiders

Microsoft Shuts Down 3,000 Email Accounts Created by North Korean IT Workers

Top FBI Cyber Official: Salt Typhoon ‘Largely Contained’ in Telecom Networks

The Person in Charge of Testing Tech for U.S. Spies Has Resigned

CBP Wants New Tech to Search for Hidden Data on Seized Phones

Krebs: Big Tech’s Mixed Response to U.S. Treasury Sanctions

Automation and Vulnerability Exploitation Drive Mass Ransomware Breaches

The Sky-High Cyber Risk in Healthcare: WSJ Readers Weigh In

Ransomware Crew Hunters International Shuts Down, Hands Out Keys to Victims

Russia Jails Man for 16 Years Over Pro-Ukraine Cyberattacks on Critical Infrastructure
IdeaLab Confirms Data Stolen in Ransomware Attack Last Year

Young Consulting Finds Even More Folks Affected in Breach Mess – Now Over 1 Million

Gloucester County (VA) Says April Ransomware Attack Exposed Employee SSNs

Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams

IDE Extensions Pose Hidden Risks to Software Supply Chain

Privilege Escalation Flaw Found in Azure Machine Learning Service

Grafana Releases Critical Security Update for Image Renderer Plugin

Linux Users Urged to Patch Critical Sudo CVE

CVE Program Launches Two New Forums to Enhance CVE Utilization

Microsoft Windows Firewall Complains About Microsoft Code

Google Open-Sources Privacy Tech for Age Verification

7/2/2025

Scattered Spider: A Group of Young Cybercriminals Poses the ‘Most Imminent Threat’ of Cyberattacks Right Now

Chinese Hackers Target France in Ivanti Zero-Day Exploit Campaign

China-Linked Hackers Spoof Big-Name Brand Websites to Steal Shoppers’ Payment Info

North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign

AI Models Mislead Users on Login URLs

States Notch Victory Over 10-Year AI Law Ban

California Jury Orders Google to Pay $314 Million Over Data Transfers From Android Phones

DOJ Investigates Ex-Ransomware Negotiator Over Extortion Kickbacks

Spain Arrests Hackers Who Targeted Politicians and Journalists

CISA Warns the Signal Clone Used by Natsec Staffers Is Being Attacked, so Patch Now

Germany Seeks Deeper Partnership With Israel on Cybersecurity

1 Year Later: Lessons Learned From the CrowdStrike Outage
Airline Qantas Hit by Cyber Attack, Leaving 6 Million Customer Records at Risk of Data Breach

Amid Scattered Spider Aviation Breaches

Ransomware Gang Attacks German Charity That Feeds Starving Children

Medical Device Company Surmodics Reports Cyberattack, Says It’s Still Recovering

Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns

Dozens of Fake Wallet Add-Ons Flood Firefox Store to Drain Crypto

Data Breach Reveals Catwatchful ‘Stalkerware’ Is Spying on Thousands of Phones

Android SMS Stealer Infects 100,000 Devices in Uzbekistan

NimDoor Crypto-Theft macOS Malware Revives Itself When Killed

Forminator Plugin Flaw Exposes WordPress Sites to Takeover Attacks

Cisco Scores a Perfect 10 – Sadly for a Critical Flaw in Its Comms Platform

Citrix Warns of Login Issues After Netscaler Auth Bypass Patch

7/1/2025

New Report Uncovers Major Overlaps in Cybercrime and State-Sponsored Espionage

Cyberattack on Russian Independent Media Had Links to U.S.-Sanctioned Institute, Researchers Find

Columbia Cyberattack Appears Politically Motivated, University Says

TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns

Aeza Group Sanctioned for Hosting Ransomware, Infostealer Servers

AT&T Now Lets You Lock Down Your Account to Prevent SIM Swapping Attacks

Cloudflare Now Blocks AI Web Scraping by Default

Why Cybersecurity Should Come Before AI in Schools
Kelly Benefits Says 2024 Data Breach Impacts 550,000 Customers

Esse Health Says Recent Data Breach Affects Over 263,000 Patients

Johnson Controls Starts Notifying People Affected by 2023 Breach

DragonForce Ransomware Variant Tied to Emerging DEVMAN Threat Actor

New FileFix Attack Runs JScript While Bypassing Windows MoTW Alerts

New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status

Critical Vulnerability in Anthropic’s MCP Exposes Developer Machines to Remote Exploits

Google Issues Emergency Patch for Fourth Chrome Zero-Day of 2025

6/30/2025

Iran-Linked Hackers May Target U.S. Firms and Critical Infrastructure, U.S. Government Warns

DOJ Raids 29 ‘Laptop Farms’ in Operation Against North Korean IT Worker Scheme

Identities of More Than 80 Americans Stolen for North Korean IT Worker Scams

Krebs: Senator Chides FBI for Weak Advice on Mobile Security

FBI: Cybercriminals Steal Health Data Posing as Fraud Investigators

Sinaloa Drug Cartel Hired a Cybersnoop to Identify and Kill FBI Informants

International Taskforce Dismantles €460m Crypto Fraud Network

IT Worker Jailed After Revenge Attack on Employer

Germany Asks Google, Apple to Remove DeepSeek AI From App Stores

Cloudflare Confirms Russia Restricting Access to Services Amid Free Internet Crackdown
ICC Says New Cybersecurity Incident Has Been Contained

Swiss Nonprofit Health Organization Breached by Sarcoma Ransomware Group

Switzerland Says Government Data Stolen in Ransomware Attack

Integrated Oncology Network Reports Data Breach Affecting cCARE Patients

Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks

Over 1,200 Citrix Servers Unpatched Against Critical Auth Bypass Flaw

Vulnerability Debt: How Do You Put a Price on What to Fix?

Microsoft Warns of Windows Update Delays Due to Wrong Timestamp

Microsoft Defender for Office 365 Now Blocks Email Bombing Attacks

Microsoft Authenticator Is Ending Support for Passwords