9/30/2025

Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware

North Korea IT Worker Scheme Expanding to More Industries, Countries Outside of U.S. Tech Sector

Tile’s Lack of Encryption Could Make Tracker Owners Vulnerable to Stalking

Microsoft’s New Security Store Is Like an App Store for Cybersecurity

Google Releases AI-Powered Ransomware Detection Features for Cloud Files

Google’s Latest AI Ransomware Defense Only Goes So Far

‘Trifecta’ of Google Gemini Flaws Turn AI Into Attack Vehicle

Why Burnout Is a Growing Problem in Cybersecurity

Israeli High-Tech Funding and M&A Gain in 2025 Despite Ongoing Gaza War

Trump Visa Curbs Push U.S. Firms to Consider Shifting More Work to India

Sendit Sued by the FTC for Illegal Collection of Children Data

CPPA Fines Tractor Supply Company $1.4 Million for Privacy Violations

UK Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust of ‘Bitcoin Queen’

Afghanistan Plunged Into Nationwide Internet Blackout, Disrupting Air Travel, Medical Care
Harbor Mental Health Services Organization (OH) Investigating Data Breach

Smishing Campaigns Exploit Cellular Routers to Target Belgium

New MatrixPDF Toolkit Turns PDFs into Phishing and Malware Lures

New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events

New Android RAT Klopatra Targets Financial Data

Critical WD My Cloud Bug Allows Remote Command Injection

$50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections

Nearly 50,000 Cisco Firewalls Vulnerable to Actively Exploited Flaws

CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems

CISA Orders Federal Gov to Patch Critical Fortra File Transfer Bug

Broadcom Fixes High-Severity VMware NSX Bugs Reported by NSA

Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024

Tech Companies Should Be Shielded From Spyware Lawsuits, Report Says

Cyber Information-Sharing Law and State Grants Set to Go Dark as Congress Stalls Over Funding

9/29/2025

Ukrainian Cops Spoofed in Fileless Phishing Attacks on Kyiv

Tile Tracking Tags Can Be Exploited by Tech-Savvy Stalkers, Researchers Say

How to Use a Password Manager to Share Your Logins After You Die

UK Gov’t Backs Jaguar Land Rover (JLR) With £1.5 Billion Loan Guarantee After Cyberattack

Chinese Scammer Pleads Guilty After UK Seizes Nearly $7 Billion in Bitcoin

Ukraine’s Digital Chief Pushes for AI-First State Amid War and Cyber Threats

European AI Company’s ‘Reputation Reports’ Are Inaccurate and Illegal, Watchdog Claims

Law Enforcement Is Using AI to Synthesize Evidence. Is the Justice System Ready for It?
‘You’ll Never Need to Work Again’: Criminals Offer Reporter Money to Hack BBC

Canada’s WestJet Says Some Passenger Data Exposed in Cybersecurity Breach

Asahi Runs Dry as Online Attackers Take Down Japanese Brewer

EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations

Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security

National Cyber Authorities Launch OT Security Guidance

DHS, CISA Kick Off Cybersecurity Awareness Month

CISA to Furlough 65% of Staff if Government Shuts Down This Week

9/26-28/2025

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks

Dutch Teens Arrested for Trying to Spy on Europol for Russia

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks

Netanyahu Broadcasts United Nations Message Into Gaza Accusing World Leaders of Appeasing ‘Evil’

Trump Signs ‘Saving TikTok’ Order to Start Resolving Its Big Ban Problem

Singapore Threatens Meta With Fines Over Facebook Impersonation Scams

Krebs: Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms

Interpol Cracks Down on Large-Scale African Scamming Networks

‘No Harm, No Foul:’ Courts Take Tougher Line on Data-Breach Suits

Salesforce Facing Multiple Lawsuits After Salesloft Breach

As Fraud Surges, UK Prepares to Replace Its Massively Broken Reporting Services

Datacenter Fire Takes 647 South Korean Government Services Offline

A New Front Opens Between Zuckerberg and Musk Over Robots
Harrods Says Customers’ Data Stolen in It Breach

Volvo North America Confirms Staff Data Stolen Following Ransomware Attack on It Supplier

Union County (OH) Suffers Ransomware Attack Impacting 45,000 People

Fake Microsoft Teams Installers Push Oyster Malware via Malvertising

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

New LockBit Ransomware Variant Emerges as Most Dangerous Yet

Akira Ransomware Breaching MFA-Protected SonicWall VPN Accounts

ArcaneDoor Threat Actor Resurfaces in Continued Attacks Against Cisco Firewalls

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

Microsoft Edge to Block Malicious Sideloaded Extensions

Microsoft’s New AI Feature Will Organize Your Photos Automatically

EU Probes SAP Over Anti-Competitive ERP Support Practice

9/25/2025

Microsoft Disables Some Cloud Services Used by Israel’s Defense Ministry

DOGE Might Be Storing Every American’s SSN on an Insecure Cloud Server

Phishing Campaign Evolves into PureRAT Deployment, Linked to Vietnamese Threat Actors

Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network

Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds

Teen Suspected of Vegas Casino Cyberattacks Released to Parents

Empty Shelves, Empty Coffers: Co-Op Pegs Cyber Hit at £80M

Google, Period-Tracking App to Pay Combined $56 Million to Settle Privacy Claims
Callous Crims Break Into Preschool Network, Publish Toddlers’ Data

Jaguar Land Rover Restarts Some IT Systems as Suppliers Call for Urgent Support

Malicious Postmark MCP Server AI Agent Server Reportedly Steals Emails

Experts Warn of Global Breach Risk from Indian Third Party Suppliers

Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

ForcedLeak: Critical Vulnerability in Salesforce AI-Powered AgentForce Exposed

Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

Amazon Pays $2.5 Billion to Settle Prime Memberships Lawsuit from FTC

9/24/2025

Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike

UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors

Collins Aerospace Working on Restoring Software for Airlines Hit by Cyberattack

UK Arrests Man in Airport Ransomware Attack That Caused Delays Across Europe

Krebs: Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms

Police Seizes $439 Million Stolen by Cybercrime Rings Worldwide

Phone Spyware Scandal in Greece Moves to Court as Critics Claim Cover-up

OpenAI is Testing a New GPT-5-Based AI agent “GPT-Alpha”

Kali Linux 2025.3 Released With 10 New Tools, WiFi Enhancements

Senators Introduce Bill Directing FTC to Establish Standards for Protecting Consumers’ Neural Data
Vegas Gambling Giant Boyd Gaming Corporation Hit by Cyber Incident, Employee Data Exposed

Rhysida Ransomware Gang Known for Government Attacks Claims Maryland Transit Incident

CISA Urges Orgs to Review Software After ‘Shai-Hulud’ Supply Chain Compromise

New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus

GitHub Notifications Abused to Impersonate Y Combinator for Crypto Theft

New String of Phishing Attacks Targets Python Developers

Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials

Unpatched Flaw in OnePlus Phones Lets Rogue Apps Text Messages

Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models

Cisco Warns of iOS Zero-Day Vulnerability Exploited in Attacks

9/23/2025

U.S. Secret Service Agents Dismantle Network That Could Shut Down New York Cellphone System

Found Near UN General Assembly

300 SIM Servers, 100K Cards

‘SIM Farms’ Are a Spam Plague

CISA Says Hackers Breached Federal Agency Using Geoserver Exploit

European Airports Still Dealing With Disruptions Days After Ransomware Attack

Drones and Cyber Outages Exposing Aviation Weak Spots Since 2017

Critical Security Flaws Grow With AI Use, New Report Shows

Attacker Breakout Time Falls to 18 Minutes

Deepfake Attacks Hit Two-Thirds of Businesses

DHS Has Been Collecting U.S. Citizens’ DNA for Years

WhatsApp Adds Message Translation to iPhone and Android Apps

GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security

15 Years of Zero Trust: Why It Matters More Than Ever

Cloudflare Mitigates New Record-Breaking 22.2 Tbps DDoS Attack
Jaguar Land Rover Extends Production Pause Again

Suspected Cyberattack Disrupts Circle K Chain’s Operations in Hong Kong

South Korea Probes Credit Card Company Lotte Card Data Breach Affecting 3 Million Customers

Iranian Hacking Group Nimbus Manticore Expands European Targeting

ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks

BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells

ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service

NPM Package ‘fezbox’ Caught Using QR Code to Fetch Cookie-Stealing Malware

Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security

Libraesva ESG Issues Emergency Fix for Bug Exploited by State Hackers

SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw

SonicWall Releases SMA100 Firmware Update to Wipe Rootkit Malware

9/22/2025

EU Agency Confirms Ransomware Attack Behind Airport Disruptions

Airport Chaos Highlights Rise in High-Profile Ransomware Attacks, Cyber Experts Say

New Plan Would Give Congress Another 18 Months to Revisit Section 702 Surveillance Powers

Deal to Keep TikTok in U.S. Is Near. These Are the Details.

Russia Steps up Disinformation Efforts to Sway Moldova’s Parliamentary Vote

$100M Cyberattack on Vegas Strip Involved Teen Hacker, Police Say

Organizations Must Update Defenses to Scattered Spider Tactics, Experts Urge

Major Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test
Car Giant Stellantis Says Customer Data Nicked After Partner Vendor Pwned

American Archive of Public Broadcasting Fixes Bug Exposing Restricted Media

Verified Steam Game Steals Streamer’s Cancer Treatment Donations

Lorain County (OH) Data Breach May Have Exposed Employee and Vendor Social Security, Bank Information

ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks

New EDR-Freeze Tool Uses Windows WER to Suspend Security Software

As Scientists Show They Can Read Inner Speech, Brain Implant ‘Pioneers’ Fight for Neural Data Privacy, Access Rights

9/19-21/2025

Russian State Hackers Gamaredon and Turla Collaborate in Attacks Against Ukraine

DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams

UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware

White House Outlines TikTok Deal That Would Give U.S. Control of Algorithm

China’s ByteDance Will Get 1 of 7 Board Seats for TikTok’s U.S. Operations, Official Says

Lachlan Murdoch, Michael Dell, Ellison Involved in TikTok Deal, Trump Says

Failed Stopgap Funding Bill Puts Key Federal Cybersecurity Legislation in Jeopardy

DOJ: Scattered Spider Took $115 Million in Ransoms, Breached a U.S. Court System

Canada Dismantles TradeOgre Exchange, Seizes $40 Million in Crypto

MI6 Launches Darkweb Portal to Recruit Foreign Spies

Watchdog Finds MrBeast Improperly Collected Children’s Data
Airport Cyberattack Disrupts More and More Flights Across Europe

What We Know About the Cyberattack That Hit Major European Airports

Russia’s Main Airport in St. Petersburg Says Its Website Was Hacked

Attackers Abuse AI Tools to Generate Fake CAPTCHAs in Phishing Attacks

17,500 Lighthouse and Lucid Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge

LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer

Ivanti EPMM Holes Let Miscreants Plant Shady Listeners, CISA Says

Fortra Releases Critical Patch for CVSS 10.0 GoAnywhere MFT Vulnerability

Transforming Cyber Frameworks to Take Control of Cyber-Risk

FBI Warns of Cybercriminals Using Fake FBI Online Crime Reporting Portals

ChatGPT Search is Now Smarter as OpenAI Takes on Google Search

9/18/2025

Senate Confirms Sutton as Pentagon Cyber Policy Chief

This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

Cybercriminals Have a Weird New Way to Target You With Scam Texts

NCA Singles Out “The Com” as it Chairs Five Eyes Group

‘Scattered Spider’ Teens Charged Over London Transportation Hack

Cybersecurity Firm Netskope Notches $8.8 Billion Valuation as Shares Jump in Nasdaq Debut

CrowdStrike Pops Nearly 13% on Upbeat Long-Term Guidance at Investor Day

Brazil Enacts Sweeping Bill Requiring Online Age Verification, Safeguards for Children’s Data

Taliban Bans Fiber-Optic Internet in Several Afghan Provinces to Curb ‘Immorality’
Russian Regional Airline KrasAvia Disrupted by Suspected Cyberattack

Cloudflare DDoSed Itself with React useEffect Hook Blunder

CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader

SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers

SystemBC Malware Turns Infected VPS Systems Into Proxy Highway

PyPi Invalidates Tokens Stolen in Ghostaction Supply Chain Attack

WatchGuard Warns of Critical Vulnerability in Firebox Firewalls

Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions

OpenAI Fixes Zero-Click Shadowleak Vulnerability Affecting ChatGPT Deep Research Agent

9/17/2025

House Lawmakers Move to Extend Two Key Cyber Programs, for Now

Italy Enacts AI Law Covering Privacy, Oversight and Child Access

Israel’s Glilot Capital Raises $500 Million for New AI and Cybersecurity Investments

Five Point-Backed WaterBridge Raises $634 Million in U.S. IPO

Axiom Space Aims for Orbit With Its Orbital Data Center Node

TaskUs Employees Behind Coinbase Breach, U.S. Court Filing Alleges

Judge Rejects Meta Attempt to Overturn Flo Privacy Verdict

Labour Politician Charged Over ‘Honey Trap’ WhatsApp Messages Sent to MPs
Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts

Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims

ShinyHunters Claims 1.5 Billion Salesforce Records Stolen in Drift Hacks

VC Firm Insight Partners Says Thousands of Staff and Limited Partners Had Personal Data Stolen in a Ransomware Attack

TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks

Shai-Hulud Worm Prowls npm to Steal Hundreds of Secrets

SonicWall Warns Customers to Reset Credentials After Breach

9/16/2025

A DHS Data Hub Exposed Sensitive Intel to Thousands of Unauthorized Users

Krebs: Self-Replicating Worm Hits 180+ Software Packages

Microsoft Seizes 340 Websites Linked to Growing Phishing Subscription Service

We Set Out to Craft the Perfect Phishing Scam. Major AI Chatbots Were Happy to Help.

OpenAI to Predict Ages in Bid to Stop ChatGPT From Discussing Self Harm With Kids

Want to Foil an AI Deepfake? Tell It to Draw a Smiley Face

How to Set Up and Use a Burner Phone

CrowdStrike to Buy AI Security Company Pangea

Israeli Cybersecurity Startup Vega Raises $65 Million, Valued at $400 Million

Cybersecurity Provider Netskope Boosts IPO Range as It Tests Tech Hot Streak
Jaguar Land Rover (JLR) Stuck in Neutral as Losses Skyrocket Amid Cyberattack Cleanup

Fifteen Ransomware Gangs, including Scattered Spider, ShinyHunters and Lapsus$, “Retire,” Future Unclear

New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site

UK: Tax Refund-Themed Phishing Slows in 2025

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids

Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover

Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack

BreachForums Hacking Forum Admin Resentenced to Three Years in Prison

TikTok’s Journey From Global Sensation to Trump Target

9/15/2025

Ukraine Claims Cyberattacks on Russian Election Systems; Moscow Confirms Disruptions

New Zealand Sanctions Russian Military Hackers Over Cyberattacks on Ukraine

Russia Tests Hypersonic Missile at NATO’s Doorstep—And Shares the Video

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

AI-Forged Military IDs Used in North Korean Phishing Attack

Google Confirms Hackers Gained Access to Law Enforcement Portal

France Threatens to Block Crypto Licence ‘Passporting’ in EU Regulatory Fight

U.S. National Charged in Finnish Psychotherapy Center Extortion

Europol Adds Spanish Academic Suspected of Aiding Pro-Russian Hackers to Most Wanted List
Gucci, Balenciaga and Alexander McQueen Private Data Ransomed by Hackers

Union County (NC) Town Government Hacked in Recent Cyber Attack

FinWise Insider Breach Impacts 689K American First Finance Customers

SEO Poisoning Targets Chinese Users with Fake Software Sites

Phishing Campaigns Drop RMM Tools for Remote Access

New Phoenix Attack Bypasses Rowhammer Defenses in DDR5 Memory

AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns

Microsoft: Exchange 2016 and 2019 Reach End of Support in 30 Days

Building Highly Resilient IT Infrastructure Throughout the Enterprise From the Start

9/12-14/2025

France Warns Apple Users of New Spyware Campaign

Philippine Military Company Spied Upon With New China-Linked Malware

Charlie Kirk Shooting Suspect Tyler Robinson Had ‘Leftist Ideology’ but Motive Unclear, Utah Gov. Says

‘Not Co-Operating’

Alleged Transgender Partner Is Cooperating and Not Believed to be Involved

Inside Our Investigation of Jeffrey Epstein’s Personal Yahoo Account

Data Destruction Done Wrong Could Cost Your Company Millions

Companies Are Competing for Employees With AI Skills. So Are Hackers.

Man Gets Over 4 Years in Prison for Selling Unreleased Movies

Hacker Convicted of Extorting 20,000 Psychotherapy Victims Walks Free During Appeal

DHS IG: CISA Mismanaged Multimillion-Dollar Employee Incentives Program
Vietnam Investigates Cyberattack on Creditors Data

Ransomware Attack Cancels School for Several Days at  Uvalde Consolidated Independent School District (TX)

Attackers Adopting Novel LOTL Techniques to Evade Detection

New VoidProxy Phishing Service Targets Microsoft 365, Google Accounts

‘WhiteCobra’ Floods VSCode Market with Crypto-Stealing Extensions

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks

Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues Warning

New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit

Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks

CISA Official Calls on Lawmakers to Immediately Extend Cyber Info-Sharing Law

9/11/2025

Chinese APT Actor Compromises Military Firm with Novel Fileless Malware Toolset

How China’s Propaganda and Surveillance Systems Really Operate

Didi Global’s $740 Million IPO Settlement Likely Ready Next Month, Plaintiffs’ Lawyer Says

Krebs: Bulletproof Host Stark Industries Evades EU Sanctions

Four Years After Kaseya’s Nightmare Hack, a Cyber Turnaround Is Underway

Swiss Government Looks to Undercut Privacy Tech, Stoking Fears of Mass Surveillance

FTC Opens Inquiry Into How AI Chatbots Impact Child Safety, Privacy

Cyberattacks Against Schools Driven by a Rise in Student Hackers, ICO Warns

California Legislature Passes Bill Forcing Web Browsers to Let Consumers Automatically Opt Out of Data Sharing
France: Three Regional Healthcare Agencies Targeted by Cyber-Attacks

Panama Ministry of Economy Discloses Breach Claimed by INC Ransomware

DDoS Defender Targeted in 1.5 Bpps Denial-of-Service Attack

Fileless Malware Deploys Advanced RAT AsyncRAT via Legitimate Tools

Fake Madgicx Plus and SocialMetrics Extensions Are Hijacking Meta Business Accounts

New VMScape Attack Breaks Guest-Host Isolation on AMD, Intel CPUs

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers

CISA Launches Roadmap for the CVE Program

Apple Warns Customers Targeted in Recent Spyware Attacks

Microsoft Adds Malicious Link Warnings to Teams Private Chats

9/10/2025

China-Linked APT41 Hackers Target U.S. Trade Officials Amid 2025 Negotiations

Poland Downs Drones in Its Airspace, Becoming First NATO Member to Fire During War in Ukraine

U.S. Warns Hidden Radios May Be Embedded in Solar-Powered Highway Infrastructure

U.S. Investment in Spyware Is Skyrocketing

Apple Says the iPhone 17 Comes With a Massive Security Upgrade

U.S. Senator Wyden Pushes FTC to Investigate Microsoft for ‘Gross Cybersecurity Negligence’

Ransomware Payments Plummet in Education Amid Enhanced Resiliency

Chinese Companies and Bosses to Face Major Fines Over Cybersecurity Incidents

Nepal Lifts Social Media Ban After Deadly Youth Protests

Ukraine’s Ousted Cyber Chief Posts Bail in Corruption Case

Oracle, OpenAI Sign Massive $300 Billion Cloud Computing Deal
KillSec Ransomware Hits Brazilian Healthcare IT Vendor

Jaguar Land Rover Admits Hackers May Have Taken Data

Flu Jab Email Mishap Exposes Hundreds of Students’ Personal Data

Researchers Find Spyware on Phones Belonging to Kenyan Filmmakers

European Crypto Platform Swissborg to Reimburse Users After $41 Million Theft

Hackers Left Empty-Handed After Massive NPM Supply-Chain Attack

CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems

Cursor Autorun Flaw Lets Repositories Execute Code Without Consent

Krebs: Microsoft Patch Tuesday, September 2025 Edition

EoP Flaws Again Lead Microsoft Patch Tuesday

Microsoft Waives Fees for Windows Devs Publishing to Microsoft Store

Pixel 10 Fights AI Fakes With New Android Photo Verification Tech

9/9/2025

House Lawmakers to Make Official Visit to China for the First Time Since 2019

Massive Leak Shows How a Chinese Company Is Exporting the Great Firewall to the World

New Cybersecurity Rules Land for Defense Department Contractors

Defense Dept Didn’t Protect Social Media Accounts, Left Stream Keys Out in Public

Cyber Command, NSA to Remain Under Single Leader as Officials Shelve Plan to End ‘Dual Hat’

New Cyber Director Cairncross Calls on Industry to Help Put ‘America First’ in Cyberspace

Krebs: 18 Popular Code Packages Hacked, Rigged to Steal Crypto

Claude’s New AI File Creation Feature Ships With Deep Security Risks Built In

A New Platform Offers Privacy Tools to Millions of Public Servants

Former WhatsApp Security Boss in Lawsuit Likens Meta’s Culture to a “Cult”

Mitsubishi Electric to Buy Nozomi Networks in $1 Billion Deal

U.S. Charges Admin of LockerGoga, MegaCortex, Nefilim Ransomware

Kosovo Hacker Pleads Guilty to Running BlackDB Cybercrime Marketplace
Plex Tells Users to Reset Passwords After New Data Breach

New York Blood Center Says Thousands Had Data Leaked in January Ransomware Attack

No Gains, Just Pains as 1.6m HelloGym Fitness Phone Call Recordings Exposed Online

Brazil Lesbian Dating App Sapphos Shuts Down After Security Flaw Exposes Sensitive User Data

Salty2FA Phishing Kit Unveils New Level of Sophistication

Threat Actor Accidentally Exposes AI-Powered Operations

TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs

RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities

Adobe Patches Critical SessionReaper Flaw in Magento eCommerce Platform

SAP Fixes Maximum Severity NetWeaver Command Execution Flaw

Microsoft September 2025 Patch Tuesday Fixes 81 Flaws, Two Zero-Days

Windows 10 KB5065429 Update Includes 14 Changes and Fixes

Microsoft: Anti-Spam Bug Blocks Links in Exchange Online, Teams

9/8/2025

Salt Typhoon Used Dozens of Domains, Going Back Five Years. Did You Visit One?

Update: Noisy Bear Campaign Targeting Kazakhstan Energy Sector Outed as a Planned Phishing Test

Remote Access Abuse Biggest Pre-Ransomware Indicator

Silicon Valley’s Graying Workforce: Gen Z Staff Cut in Half at Tech Companies as the Average Age Goes up by 5 Years

SoFi Launches New AI-Themed ETF as Skepticism Grows

Cyberattack on Jaguar Land Rover Threatens to Hit British Economic Growth

The U.S. Government Has No Idea How Many Cybersecurity Pros It Employs

Sports Streaming Piracy Service With 123M Yearly Visits Shut Down

U.S. Sanctions Companies Behind Cyber Scam Centers in Cambodia, Myanmar

Nepal Social Media Ban Sparks Protests, Dozens Injured
Qualys, Tenable Latest Victims of Salesloft Drift Hack

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

GhostAction Supply Chain Attack Compromises 3000+ Secrets

Wealthsimple Confirms Data Breach After Supply Chain Attack

Lovesac Confirms Data Breach After Ransomware Attack Claims

VC Giant Insight Partners Notifies Staff and Limited Partners After Data Breach

MostereRAT Targets Windows Users With Stealth Tactics

Hackers Hijack npm Packages With 2 Billion Weekly Downloads in Supply Chain Attack

Surge in Networks Scans Targeting Cisco ASA Devices Raise Concerns

The Critical Failure in Vulnerability Management

Signal Adds Secure Cloud Backups to Save and Restore Chats

9/5-7/2025

Chinese Hackers Pretended to Be a Top U.S. Lawmaker During Trade Talks

U.S. Says It Is Restricting Visas of Some Central American Nationals Over China Ties

U.S. Is Increasingly Exposed to Chinese Election Threats, Lawmakers Say

Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

Ukraine’s Cyber Chief on Russian Hackers’ Shifting Tactics, U.S. Cyber Aid

Krebs: GOP Cries Censorship Over Spam Filters That Work

Qantas Penalizes Executives for July Cyberattack

Roblox to Verify Ages of All Gamers Who Use Chat and Text Features

Embracing the Next Generation of Cybersecurity Talent

Why Threat Hunting Should Be Part of Every Security Program

CISA Orders Federal Agencies to Patch Sitecore Zero-Day Following Hacking Reports
School District Five of Lexington & Richland Counties (SC) Data Breach Affects 31,000 People

Navy Federal Credit Union Data Breach Exposes Backup Files on Credit Union Serving Military Members

Data Breach at American Credit Union Exposes Financial Data

‘SEO Fraud-As-A-Service’ Scheme Hijacks Windows Servers to Promote Gambling Websites

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages

iCloud Calendar Abused to Send Phishing Emails from Apple’s Servers

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Security

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild

9/4/2025

How North Korean Hackers Are Using Fake Job Offers to Steal Cryptocurrency

‘Unrestrained’ Chinese Cyberattackers May Have Stolen Data From Almost Every American

Czech Cyber Agency Warns Against Using Services and Products That Send Data to China

GhostRedirector Emerges as New China-Aligned Threat Actor

U.S. Says It Is Restricting Visas of Some Central American Nationals Over China Ties

U.S. and 14 Allies Release Joint Guidance on Software Bill of Materials

Britain Rules Out Backing for Global Defence Bank

Google Fined $379 Million by French Regulator for Cookie Consent Violations

Texas Sues PowerSchool Over Breach Exposing 62M Students, 880K Texans
Ukraine’s Cyber Chief on Russian Hackers’ Shifting Tactics, U.S. Cyber Aid

Blast Radius of Salesloft Drift Attacks Remains Uncertain

Chess.com Discloses Recent Data Breach via File Transfer App

Tire Giant Bridgestone Confirms Cyberattack Impacts Manufacturing

Delivery Giant OnTrac Data Breach Exposes 40,000 Personal Records

Attackers Snooping Around Sitecore, Dropping Malware via Public Sample Keys

CMS Provider Sitecore Patches Exploited Critical Zero Day

CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited

Microsoft Says Recent Windows Updates Cause App Install Issues

European Court Rejects Challenge to EU-U.S. Data Transfer Agreement

9/3/2025

Russian APT28 Expands Arsenal with ‘NotDoor’ Outlook Backdoor

U.S. Offers $10 Million Bounty for Info on Russian FSB Hackers

Venezuela’s President Thinks American Spies Can’t Hack Huawei Phones

Iranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Targeting Diplomats

Automated Sextortion Spyware Takes Webcam Pics of Victims Watching Porn

It Looks Like You’re Ransoming Data. Would You Like Some Help?

How Passkeys Work—And How to Use Them

Finland’s IQM Quantum Computers Raises $320 Million in New Funding Round

Israel’s Cato Networks Buys Aim Security, Raises Another $50 Million

More Personal Injury Lawyers Are Chasing Data-Breach Settlements

Police Disrupts Streameast, Largest Pirated Sports Streaming Network

U.S. Sues Robot Toy Maker Apitor Technology for Exposing Children’s Data to Chinese Devs
Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

SaaS Giant Workiva Discloses Data Breach After Salesforce Attack

M&S Hackers ‘Scattered Lapsus$ Hunters’ Claim to Be Behind Jaguar Land Rover Cyber Attack

Matrix.org Homeserver Grinds to a Halt After Raid Meltdown

Hackers Breach Fintech Firm Sinqia S.A. in Attempted $130M Bank Heist

Threat Actors Abuse X’s Grok AI to Spread Malicious Links

Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers

Major IPTV Piracy Network Uncovered Spanning 1100 Domains

Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure

Android Security Alert: Google Patches 120 Flaws, Including Two Zero-Days Under Attack

With Less Than a Month to Go, House Panel Votes to Extend Popular Cyber Programs

Corruption Case Against Ousted Cyber Chief Is ‘Revenge,’ Ukraine’s Security Service Says

9/2/2025

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

Moscow Reportedly Hires Hackers Who Breached City’s School System

Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices

ICE Reinstates Contract with Spyware Vendor Paragon

Who Watches the Watchmen? Surveillanceware Firms Make Bank, Avoid Oversight

Disney Agrees to $10 Million Settlement for Collecting Data From Children

That Supposed ‘Gmail Hack’: Google Says It’s False, but Watch Out for Phishing Anyway

FBI, Cybersecurity Experts Warn of 3-Phase Scam That Is Draining Bank Accounts

AI Chatbot Users Beware – Hackers Are Now Hiding Malware in the Images Served up by LLMs
Krebs: The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft

Stolen OAuth Tokens Expose Palo Alto Customer Data

Cloudflare Hit by Data Breach in Salesloft Drift Supply Chain Attack

Cloudflare Blocks Largest Recorded DDoS Attack Peaking at 11.5 Tbps

Britain’s Jaguar Land Rover Hit by Cyber Incident That Disrupts Production, Sales

Pennsylvania AG Says Recovery Continues After Office Refused to Pay Ransomware Gang

Azure AD Credentials Exposed in Public App Settings File

Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets

Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control

Hackers Are Sophisticated & Impatient — That Can Be Good

9/1/2025

Silver Fox APT Exploits Signed Drivers to Deploy ValleyRAT Backdoor

China Is About to Show Off Its New High-Tech Weapons to the World

North Korea’s Kim Inspects New Missile Production Line, KCNA Says

Google: Gmail’s Protections Are Strong and Effective, and Claims of a Major Gmail Security Warning Are False

Spanish Government Cancels €10M Contract Using Huawei Equipment

LegalPwn: Tricking LLMs by Burying Badness in Lawyerly Fine Print
Zscaler Data Breach Exposes Customer Info After Salesloft Drift Compromise

Ransomware Attack on Pennsylvania’s AG Office Disrupts Court Cases

Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans

High-Risk SQLi Flaw Exposes WordPress Memberships Plugin Users

DDoS Is the Neglected Cybercrime That’s Getting Bigger. Let’s Kill It Off

Proof-of-Concept in 15 Minutes? AI Turbocharges Exploitation