10/30/2025

Diplomatic Entities in Belgium and Hungary Hacked in China-Linked Spy Campaign

Leaker Reveals Which Pixels Are Vulnerable to Cellebrite Phone Hacking

Shadow AI: One In Four Employees Use Unapproved AI Tools, Research Finds

LinkedIn Phishing Targets Finance Execs With Fake Board Invites

Proton Trains New Service to Expose Corporate Infosec Cover-Ups

NASA’s Quiet Supersonic Jet Takes Flight

Coalition Calls on FTC to Block Meta From Using Chatbot Interactions to Target Ads, Personalize Content
Threat Actors Utilize AdaptixC2 for Malicious Payload Delivery

Critical Flaws Found in Elementor King Addons Affect 10,000 Sites

Massive Surge of NFC Relay Malware Steals Europeans’ Credit Cards

Malicious NPM Packages Fetch Infostealer for Windows, Linux, macOS

CISA Orders Feds to Patch VMware Tools Flaw Exploited by Chinese Hackers

Cyber Info Sharing ‘Holding Steady’ Despite Lapse in CISA 2015, Official Says

The AI Trust Paradox: Why Security Teams Fear Automated Remediation

10/29/2025

U.S. Company Ribbon Communications With Access to Biggest Telecom Firms Uncovers Breach by Unnamed Nation-State Hackers

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

New Names Surface for NSA Director, Other Top Jobs at Spy Agency

The Microsoft Azure Outage Shows the Harsh Reality of Cloud Failures

Krebs: Aisuru Botnet Shifts from DDoS to Residential Proxies

New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts

Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm

CISOs Finally Get a Seat at the Board’s Table — But There’s a Big Catch
Canada Says Hacktivists Breached Water and Energy Facilities

Cloud Atlas Hackers Target Russian Agriculture Sector Ahead of Industry Forum

EY Exposes 4TB+ SQL Database to Open Internet for Who Knows How Long

Tata Motors Confirms It Fixed Security Flaws, Which Exposed Company and Customer Data

More Than 10 Million Impacted by Breach of Government Contractor Conduent

Investment Scams Spread Across Asia With International Reach

PhantomRaven: Npm Malware Uses Invisible Dependencies to Infect Dozens of Packages

WordPress Security Plugin Exposes Private Data to Site Subscribers

Windows 11 KB5067036 Update Rolls out Administrator Protection Feature

10/28/2025

SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats

Researchers Expose GhostCall and GhostHire: BlueNoroff’s New Malware Chains

Nation-State Cyber Ecosystems Weakened by Sanctions, Report Reveals

Clearview AI Faces Criminal Heat for Ignoring EU Data Fines

AI Browsers Face a Security Flaw as Inevitable as Death and Taxes

Palo Alto Networks Debuts Automated AI Agents to Fight Cyberattacks

Sublime Raises $150 Million for AI-Powered Email Security

A Quarter of Scam Victims Have Considered Self-Harm
Advertising Giant Dentsu Reports Data Breach at Subsidiary Merkle

New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human

New Atroposia Malware Comes With a Local Vulnerability Scanner

New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves

CISA Warns of Two More Actively Exploited Dassault Vulnerabilities

Google Chrome to Warn Users by Default Before Opening Insecure HTTP Sites

FCC Adopts New Rule Targeting Robocalls

F5 Expects Big Revenue Hit From Recent Cyber Attack Compromising Many

10/27/2025

Chatbots Are Pushing Sanctioned Russian Propaganda

Iran’s School for Cyberspies Could’ve Used a Few More Lessons in Preventing Breaches

Italian Spyware Vendor Linked to Chrome Zero-Day Attacks

Europol Warns of Rising Threat From Caller ID Spoofing Attacks

‘There Isn’t Really Another Choice:’ Signal Chief Explains Why the Encrypted Messenger Relies on AWS

X: Re-Enroll 2FA Security Keys by November 10 or Get Locked Out

You Have One Week to Opt Out or Become Fodder for LinkedIn AI Training

Shaquille O’Neal’s Custom Range Rover Stolen During Transport in Suspected Hack
Hundreds of People With ‘Top Secret’ Clearance Exposed by House Democrats’ Website

Google Disputes False Claims of Massive Gmail Data Breach

Sweden’s Power Grid Operator Confirms Data Breach Claimed by Everest Ransomware Gang

Qilin Ransomware Group Publishes Over 40 Cases Monthly

Ransomware Profits Drop as Victims Stop Paying Hackers

QNAP Warns of Critical ASP.NET Flaw in its Windows Backup Software

CISA Releases Warning About Windows Server Update Service Bug, Orders Agencies to Patch

Google Says Everyone Will Be Able to Vibe Code Video Games

10/24-26/2025

Blitz Spear Phishing Campaign Targets NGOs Supporting Ukraine

UN Cybercrime Treaty to Be Signed in Hanoi to Tackle Global Offences

Fake LastPass Death Claims Used to Breach Password Vaults

MPs Urge Government to Stop Britain’s Phone Theft Wave Through Tech

How Hacked Card Shufflers Allegedly Enabled a Mob-Fueled Poker Scam That Rocked the NBA

Hackers Earn $1,024,750 for 73 Zero-Days at Pwn2Own Ireland
Everest Ransomware Says It Stole 1.5m Dublin Airport Passenger Records

New LockBit Ransomware Victims Identified by Security Researchers

Hackers Steal Discord Accounts With RedTiger-Based Infostealer

Hackers Launch Mass Attacks Exploiting Outdated WordPress Plugins

Windows Server Emergency Patches Fix WSUS Bug with PoC Exploit

Critical WSUS Flaw in Windows Server Now Exploited in Attacks

10/23/2025

Lazarus Group’s Operation DreamJob Targets European Defense Firms

Pakistani-Linked Hacker Group Targets Indian Government with DeskRAT

Hackers Posing as Kyrgyz Officials Target Russian Agencies in Cyber Espionage Campaign

Europe’s Offshore Wind Sector Faces Dilemma Over China’s Grip on Sector

UK Cyber Law Delays ‘Deeply Concerning,’ Say MPs

The ‘Universal Browser’ Privacy Browser Has Dangerous Hidden Features

23andMe’s Data-Theft Victims Offered ‘Genetic Monitoring’ to Ward Off Hackers

Former Polish Official Indicted Over Spyware Purchase
Playtime’s Over: Crooks Swipe Toys R Us Canada Customer Data and Dump It Online

“Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards

Spoofed AI Sidebars Can Trick Atlas, Comet Users Into Dangerous Actions

Tired of Unpaid Toll Texts? Blame the ‘Smishing Triad’

CISA Warns of Lanscope Endpoint Manager Flaw Exploited in Attacks

Microsoft Disables File Explorer Preview for Downloads to Block Attacks

Google Nukes 3,000 YouTube Videos That Sowed Malware Disguised as Cracked Software

Trump Pardons Former Binance CEO After Guilty Plea in Letting Cybercrime Proceeds Flow Through Platform

10/22/2025

PhantomCaptcha Campaign Targets Ukraine Relief Organizations

MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign

The Long Tail of the AWS Outage

Scattered Lapsus$ Hunters Signal Shift in Tactics

UN Cybercrime Pact to Be Signed in Hanoi Raises Hopes, Concerns

Krebs: Canada Fines Cybercrime Friendly Cryptomus $176M

JLR Hack UK’s Costliest Ever, Hitting Economy with £1.9bn Loss

No, ICE (Probably) Didn’t Buy Guided Missile Warheads

SpaceX Disables More Than 2,000 Starlink Devices Used in Myanmar Scam Compounds

It Takes Only 250 Documents to Poison Any AI Model
Cyber Incidents in Texas, Tennessee and Indiana Impacting Critical Government Services

Ransomware Gang Steals Meeting Videos, Financial Secrets From Fence Wholesaler

Summit Golf Brands Allegedly Subjected to Massive INC Ransom Breach

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys

TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution

Hackers Exploiting Critical “SessionReaper” Flaw in Adobe Magento

Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft’s July Patch

Pwn2Own Day 2: Hackers Exploit 56 Zero-Days for $790,000

10/21/2025

Russian Coldriver Hackers Deploy New ‘NoRobot’, ‘YesRobot’, and ‘MaybeRobot’ Malware

‘PassiveNeuron’ Cyber Spies Target Orgs With Custom Malware

Lumma Stealer Developers Doxxed in Underground Rival Cybercrime Campaign

Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams

How Malware Vaccines Could Stop Ransomware’s Rampage

Medical Specialist Group Fined £100K After Hack Exposed Patient Data

Cloud Data Firm Veeam to Buy Securiti AI for $1.73 Billion

Russia Pressures Apple to Make Russian Search Engines Default on Locally-Sold iPhones
Amazon Says AWS Cloud Service Back to Normal After Outage Disrupts Businesses Worldwide

Singapore Officials Impersonated in Sophisticated Investment Scam

Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network

Vidar Stealer 2.0 Adds Multi-Threaded Data Theft, Better Evasion

PolarEdge Targets Cisco, ASUS, QNAP, Synology Routers in Expanding Botnet Campaign

Cursor, Windsurf IDEs Riddled with 94+ N-Day Chromium Vulnerabilities

TP-Link Warns of Critical Command Injection Flaw in Omada Gateways

Hackers Exploit 34 Zero-Days on the First Day of Pwn2Own Ireland 2025

10/20/2025

Amazon’s AWS Struggles to Recover After Major Outage Disrupts Apps, Services Worldwide

What the Huge AWS Outage Reveals About the Internet

Salt Typhoon Uses Citrix Flaw in Global Cyber-Attack

Flawed Vendor Guidance Exposes Enterprises to Avoidable Risk

Cyberattacks Cripple Small Businesses, Even When They Aren’t Hacked

DNS0.EU Private DNS Service Shuts Down Over Sustainability Issues

Evilginx’s Creator Reckons With the Dark Side of Red-Team Tools

Judge Bars NSO From Targeting WhatsApp Users With Spyware, Reduces Damages in Landmark Case

What to Know About the Shocking Louvre Jewelry Heist

The Fraudster Behind Steve Ballmer’s NBA Nightmare
Retail Giant Muji Halts Online Sales After Ransomware Attack on Supplier

Home Security Firm Verisure Reports Data Breach at Swedish Subsidiary

Japanese Retailer Askul Halts Online Orders, Shipments After Ransomware Attack

131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign

Self-Spreading GlassWorm Malware Hits OpenVSX, VS Code Registries

Cyber Defenders From All Around Sound the Alarm as F5 Hack Exposes Broad Risks

CISA: High-Severity Windows SMB Flaw Now Exploited in Attacks

Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets

Microsoft Warns of Windows Smart Card Auth Issues After October Updates

10/17-19/2025

Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials

North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware

Teen Tied to Russian Hackers in Dutch Cyber Espionage Probe

Over 266,000 F5 BIG-IP Instances Exposed to Remote Attacks

China Accuses U.S. of Cyberattack on National Time Center

Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide

Experian Fined $3.2 Million for Mass-Collecting Personal Data

Labor Unions Sue Trump Administration Over Social Media Surveillance
American Airlines Subsidiary Envoy Air Confirms Oracle Data Theft Attack

AI Girlfriend Apps Leak Millions of Private Chats

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

Krebs: Email Bombs Exploit Lax Authentication in Zendesk

Google Ads for Fake Homebrew, LogMeIn Sites Push Infostealers

TikTok Videos Continue to Push Infostealers, Including Aura Stealer, in ClickFix Attacks

Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices

ConnectWise Fixes Automate Bug Allowing AiTM Update Attacks

Microsoft Fixes Highest-Severity ASP.NET Core Flaw Ever

10/16/2025

Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

Breach at U.S.-Based Cybersecurity Provider F5 Blamed on China, Say Sources

Cybersecurity Firm F5′S Stock Sinks 10%

‘Categorically Untrue’ That China Hacked UK Intelligence Systems, Say Officials

Hacked Airport P.A. Systems Broadcast Anti-Trump and Pro-Hamas Messages

North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts

Microsoft Disrupts Ransomware Attacks Targeting Teams Users

Microsoft Debuts Copilot Actions for Agentic AI-Driven Windows Tasks

Ring to Partner With Flock, Giving Law Enforcement Easier Access to Home Security Camera Footage

Cambodia to Repatriate South Koreans Ensnared by Scam Industry Amid Diplomatic Pressure

Ex-Trump National Security Adviser Bolton Charged With Storing and Sharing Classified Information

Vulnerability Scores, Huh, What Are They Good For? Almost Nothing
Nintendo Denies Data Leak After Online Reports

Auction Giant Sotheby’s Says Data Breach Exposed Customer Information

Have I Been Pwned: Prosper Data Breach Impacts 17.6 Million Accounts

List of Major Companies Hit by Massive Salesforce Data Breach Continues to Grow

Dairy Farmers of America Confirms June Cyberattack Leaked Personal Data

Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites

Microsoft Warns of a 32% Surge in Identity Hacks, Mainly Driven by Stolen Passwords

LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets

New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence

Gladinet Fixes Actively Exploited Zero-Day CVE-2025-11371 in File-Sharing Software

CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack

10/15/2025

U.S. Warns That Hackers Using F5 Devices to Target Government Networks

Emergency Order

F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion

Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months

When Face Recognition Doesn’t Know Your Face Is a Face

Google Will Let Friends Help You Recover an Account

Outsourcing Firm Capita Fined £14M After Millions Had Data Stolen

New York Secures $14 Million in Fines From 8 Car Insurance Companies After Data Breaches

UK, U.S. Sanction Southeast Asia-Based Online Scam Network

PowerSchool Hacker Gets Sentenced to Four Years in Prison

Scouts Can Now Earn AI and Cybersecurity Badges

Cisco Must Share More Information About Effects of Severe Bugs on Businesses, Senator Cassidy Says
Salesforce-Linked Security Breach Fallout Escalates With Qantas Leak

Clothing Giant MANGO Discloses Data Breach Exposing Customer Info

Texas Electric Cooperatives Purportedly Breached by Qilin

Whisper 2FA Behind One Million Phishing Attempts Since July

Fake LastPass, Bitwarden Breach Alerts Lead to PC Hijacks

Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access

Flaw in Slider Revolution Plugin Exposed 4m WordPress Sites

New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login

RMPocalypse: Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing

Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control

Krebs: Patch Tuesday, October 2025 ‘End of 10’ Edition

Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped

10/14/2025

Chinese Hackers Use Trusted ArcGIS App For Year-Long Persistence

Taiwan Flags Rise in Chinese Cyberattacks, Warns of ‘Online Troll Army’

Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data

Salesforce Deepens AI Ties With OpenAI, Anthropic to Power Agentforce Platform

Senior Execs Falling Short on Cyber-Attack Preparedness, NCSC Warns

Cyber Attack Contingency Plans Should Be Put On Paper, Firms Told

NCSC Reports 130% Spike in “Nationally Significant” Cyber Incidents

UK Firms Lose Average of £2.9m to AI Risk

Critical infrastructure CISOs Can’t Ignore ‘Back-Office Clutter’ Data

Feds Seize Record-Breaking $15 Billion in Bitcoin From Alleged Scam Empire

Florida Sues Roku for Illegally Selling Children’s Data, Including Precise Geolocation

Security Firms Dispute Credit for Overlapping CVE Reports
Discord Blamed a Vendor for Its Data Breach — Now the Vendor Says It Was ‘Not Hacked’

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels

Personal Data Potentially Stolen in Asahi Cyber-Attack

Harvard Says ‘Limited Number of Parties’ Impacted by Breach Linked to Oracle Zero-Day

Michigan City (IN) Confirms Ransomware Hackers Behind September Incident

Hacker Group TA585 Emerges With Advanced Attack Infrastructure

Malicious Crypto-Stealing VSCode Extensions Resurface on OpenVSX

New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions

Secure Boot Bypass Risk Threatens Nearly 200,000 Linux Framework Laptops

Legacy Windows Protocols Still Expose Networks to Credential Theft

Microsoft October 2025 Patch Tuesday Fixes 6 Zero-Days, 172 Flaws

Oracles Silently Fixes Zero-Day Exploit Leaked by ShinyHunters

10/13/2025

Ukraine Takes Steps to Launch Dedicated Cyber Force for Offensive Strikes

China Probes Qualcomm’s Autotalks Deal Amid Rising U.S. Trade Tensions

Dutch Government Puts Nexperia on a Short Leash Over Chip Security Fears

UK Ofcom Fines 4chan £20K and Counting for Pretending UK’s Online Safety Act Doesn’t Exist

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor

Apple Bug Bounty Payouts Can Now Top $5m

Fired California Cybersecurity Chief Speaks Out on Sudden Termination, Security Concerns
Scattered Lapsus$ Hunters Rage-Quit the Internet (Again), Promise to Return Next Year

Harvard Investigating Breach Linked to Oracle Zero-Day Exploit

SimonMed Says 1.2 Million Patients Impacted in January Data Breach

Goosehead Insurance Confirms Data Breach Exposes SSNs Following Ransomware Attack

Wellborn & Company Data Breach Affecting Clients’ Personal Information

Hackers Target ScreenConnect Features For Network Intrusions

Massive Multi-Country Botnet Targets RDP Services in the U.S.

New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

SonicWall VPN Accounts Breached Using Stolen Creds in Widespread Attacks

10/10-12/2025

What Are the Latest Sticking Points in U.S.-China Tensions?

White House Lays off Thousands of U.S. Government Workers, Blaming Shutdown

Federal Cyber Cuts Raise National Security Alarms

Acting U.S. Cyber Command, NSA Chief Won’t Be Nominated for the Job, Sources Say

North Korean Scammers Are Doing Architectural Design Now

Krebs: DDoS Botnet Aisuru Blankets U.S. ISPs in Record DDoS

Spyware Maker NSO Group Confirms Acquisition by U.S. Investors

Led by Hollywood Producer

Cops Nuke BreachForums (Again) Amid Cybercrime Supergroup Extortion Blitz

Spain Dismantles “GXC Team” Cybercrime Syndicate, Arrests Leader

Prosecutors Seek 7-Year Prison Term for ‘Sophisticated’ PowerSchool Hacker

Finland’s Trial of Men Charged Over Baltic Sea Cable Damage Hits Choppy Waters

Microsoft Violated EU Law in Handling of Kids’ Data, Austrian Privacy Regulator Finds
UK Techies’ Union Prospect Warns Members After Breach Exposes Sensitive Personal Details

Australian Airline Qantas Airways Says Hackers Leaked Data on Its Customers

Private Data Exposed in Georgia Department of Human Services Email Breach

Kearney Public Schools (NE) Hit by a Cybersecurity Attack

Houston Suburb Sugar Land (TX) Says Some Online Services Taken Down by Cyberattack

Fake ‘Inflation Refund’ Texts Target New Yorkers in New Scam

175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign

Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers

From Detection to Patch: Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation

Hackers Exploiting Zero-Day in Gladinet File Sharing Software

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits

10/9/2025

China Honing Abilities for a Possible Future Attack, Taiwan Defence Report Warns

From HealthKick to GOVERSHELL: The Evolution of UTA0388’s Espionage Malware

Pro-Russian Hacktivist Group ‘Twonet’ Target Critical Infrastructure, Hit Decoy Plant

Claude’s New AI File-Creation Feature Ships With Security Risks Built In

Researchers Warn of Security Gaps in AI Browsers

It’s Trivially Easy to Poison LLMs Into Spitting Out Gibberish, Says Anthropic

GitHub Copilot ‘CamoLeak’ AI Attack Exfiltrates Data

Take Note: Cyber-Risks With AI Notetakers

High Number of Windows 10 Users Remain as End-of-Life Looms

Renewal of Cyber Information-Sharing Law Must Mind the Gap, Senator Says
Google Says ‘Likely Over 100’ Affected by Oracle-Linked Hacking Campaign

All SonicWall Cloud Backup Users Have Firewall Configuration Files Stolen

Hackers Claim Discord Breach Exposed Data of 5.5 Million Users

Rhode Island Lottery Tech Supplier Brightstar Lottery Group Breach Impacted Thousands

Qilin Ransomware Gang Claims San Francisco’s Cal Club, Exposing Members of Exclusive Golf Club

ClayRat Spyware Campaign Targets Android Users in Russia

Microsoft: Storm-2657 Hackers Target Universities in “Payroll Pirate” Attacks

Hackers Now Use Velociraptor DFIR Tool in Ransomware Attacks

Chaos Ransomware Upgrades With Aggressive New C++ Variant

RondoDox Botnet Targets 56 N-Day Flaws in Worldwide Attacks

10/8/2025

OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks

Russian Hackers Turn to AI as Old Tactics Fail, Ukrainian CERT Says

Russia Is at ‘Hybrid War’ With Europe, Warns EU Chief, Calling for Members ‘To Take It Very Seriously’

Nezha Tool Used by Chinese Hackers in New Cyber Campaign Targeting Web Applications

Bybit Theft Drives Record-Breaking $2bn Haul for North Korea

U.S. Government Shutdown: Who Is Still Working and Who Has Been Furloughed?

Digital Fraud Costs Companies Worldwide 7.7% of Annual Revenue

Salesforce Says It Won’t Pay Extortion Demand in 1 Billion Records Breach

Krebs: ShinyHunters Wage Broad Corporate Extortion Spree

Cybersecurity Gets C-Suite Attention as Companies Dive Into AI

1Password Says It Can Fix Login Security for AI Browser Agents

Germany Slams Brakes on EU’s Chat Control Device-Scanning Snoopfest
Discord Says 70,000 Users May Have Had Their Government IDs Leaked in Breach

Major U.S. Law Firm Williams & Connolly Says Hackers Broke Into Attorneys’ Emails Accounts

LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem

Crimson Collective Hackers Target AWS Cloud Instances for Data Theft

New FileFix Attack Uses Cache Smuggling to Evade Security Software

Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks

Hackers Exploit Auth Bypass in Service Finder WordPress Theme

Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now

Docker Makes Hardened Images Catalog Affordable for Small Businesses

California Enacts Law Giving Consumers Ability to Universally Opt Out of Data Sharing

Time’s Running Out to Claim Your Part of the $177 Million AT&T Data Breach Settlement

10/7/2025

Russia Blocks Mobile Internet for Foreign SIM Cards, Citing Drone Threats

OpenAI Bans Suspected Chinese Accounts Using ChatGPT to Plan Surveillance

Employees Regularly Paste Company Secrets into ChatGPT

Despite AI-Related Job Loss Fears, Tech Hiring Holds Steady – And Here Are the Most In-Demand Skills

Google Won’t Fix New ASCII Smuggling Attack in Gemini

Google’s New AI Bug Bounty Program Pays up to $30,000 for Flaws

Man and Teenage Boy Arrested Over Cyber-Attack on London Nurseries
Cyberattacks Upset British Life, Disrupting Car Factories and Grocery Stores

‘Qilin’ Cybercrime Gang Claims Hack on Japan’s Asahi Group

Qilin Claims Ransomware Attack on Mecklenburg Schools (VA)

Electronics Giant Avnet Confirms Breach, Says Stolen Data Unreadable

DraftKings Warns of Account Breaches in Credential Stuffing Attacks

BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers

California Sets 30 Day Deadline for Data Breach Notifications

10/6/2025

Suspected Chinese Cyber Spies Targeted Serbian Aviation Agency

New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations

One iPhone Led Police to Gang Suspected of Sending up to 40,000 Stolen UK Phones to China

Vibe Coding Is the New Open Source—In the Worst Way Possible

Google Confirms Android Dev Verification Will Have Free and Paid Tiers, No Public List of Devs

OpenAI, AMD Announce Massive Computing Deal, Marking New Phase of AI Boom

A Biological 0-Day? Threat-Screening Tools May Miss AI-Designed Proteins.

The True Cost of Cyber Attacks – And the Business Weak Spots That Allow Them to Happen

SAIC to Acquire Silveredge Government Solutions for $205 Million

Europol Calls for Stronger Data Laws to Combat Cybercrime

Signal Calls on Germany to Vote Against ‘Chat Control,’ Saying It Would Leave EU Market
Scattered Lapsus$ Hunters Offering $10 in Bitcoin to ‘Endlessly Harass’ Execs

Red Hat Data Breach Escalates as ShinyHunters Joins Extortion

Ransomware Group “Trinity of Chaos” Launches Data Leak Site

Doctors Imaging Group (FL) Suffers Data Breach – 171,800+ Users Data Exposed

XWorm Malware Resurfaces With Ransomware Module, Over 35 Plugins

New Malware Sorvepotel Leverages WhatsApp to Target Brazilian Government and Businesses

Redis Warns of Critical Flaw Impacting Thousands of Instances

Microsoft: Critical GoAnywhere Bug Exploited by Storm-1175 in Medusa Ransomware Attacks

Steam and Microsoft Warn of Unity Flaw Exposing Gamers to Attacks

Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks

Zeroday Cloud Hacking Contest Offers $4.5 Million in Bounties

Phishing Is Moving From Email to Mobile. Is Your Security?

10/3-5/2025

ShinyHunters Launches Salesforce Data Leak Site to Extort 39 Victims

Salesforce Providing Support to Customers Listed on Scattered Spider Extortion Site

Apple Drops ICE-Tracking Apps From App Store

Google Too

ICE Wants to Build Out a 24/7 Social Media Surveillance Team

Congress Let Cyber-Intel Sharing Act Lapse. Does it Matter?

National Security, Legal Readiness, and U.S. Engagement for International Dual-Use Technology Companies

UK Government Says Digital ID Won’t Be Compulsory – Honest

Consumers More Likely to Pay for ‘Responsible’ AI Tools, Deloitte Survey Says

ChatGPT Social Could Be a Thing, as Leak Shows Direct Messages Support

OpenAI Wants ChatGPT to be Your Emotional Support

Signal Adds New Cryptographic Defense Against Quantum Attacks

Munich Airport Chaos After Drone Sightings Spook Air Traffic Control

ParkMobile Pays… $1 Each for 2021 Data Breach That Hit 22 Million

LinkedIn Sues Software Company Allegedly Scraping Data From Millions of Profiles

California AG Sues City for Allowing Out-Of-State Searches of License Plate Reader Database
Oracle Links Clop Extortion Attacks to July 2025 Vulnerabilities

Discord Customer Service Data Breach Leaks User Info and Scanned Photo IDs

Renault and Dacia UK Warn of Data Breach Impacting Customers

Six Out of 10 UK Secondary Schools Hit by Cyber-Attack or Breach in Past Year

Japan Faces Asahi Beer Shortage After Cyber-Attack

New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT

Massive Surge in Scans Targeting Palo Alto Networks Login Portals

Chinese-Speaking Cybercrime Group Hijacks IIS Servers for SEO Fraud

Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer

Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads

Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL

CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief

Hackers Exploited Zimbra Flaw as Zero-Day Using iCalendar Files

CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild

License Plate Reader Company Flock Launches New Product That Detects Human Voices

10/2/2025

U.S. to Provide Ukraine With Intelligence for Missile Strikes Deep Inside Russia

Trump’s Drone Deal With Ukraine to Give U.S. Access to Battlefield Tech

U.S. Government Shutdown to Slash Federal Cybersecurity Staff

Shutdown Guts U.S. Cybersecurity Agency at Perilous Time

U.S. Stocks Rally on Shutdown’s Second Day

Google Says Self-Reported Cl0p Hackers Are Sending Extortion Emails to Corporate Executives

Gmail’s End-To-End Encryption for Organizations Now Works Across Email Providers

EU Funds Are Flowing Into Spyware Companies, and Politicians Are Demanding Answers

HackerOne Paid $81 Million in Bug Bounties Over the Past Year
Cybercrims Claim Raid on 28,000 Red Hat Repos, Say They Have Sensitive Customer Files

Subpoena Tracking Platform Blames Outage on AWS Social Engineering Attack

Concerns for Patient Data After Suspected Cyberattack on Shamir Medical Center

Confucius Shifts from Document Stealers to Python Backdoors

Warning: Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro

Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown

DrayTek Warns of Remote Code Execution Bug in Vigor Routers

Microsoft Outlook Stops Displaying Inline SVG Images Used in Attacks

Microsoft Defender Bug Triggers Erroneous BIOS Update Alerts

10/1/2025

Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs

Geopolitics Drives More Cyberattacks

China Imposes One-Hour Reporting Rule for Major Cyber Incidents

Expiration of Cyber Information-Sharing Act Leaves U.S. Very Vulnerable

F-Droid Project Threatened by Google’s New Dev Registration Rules

Schools and Colleges Are Swotting up on Security Yet Still Flunk Recovery When Cyberattacks Inevitably Strike

Seniors Targeted in Global Facebook Scam Spreading New Android Malware

AI Data Analytics Startup Dataiku Picked Multiple Banks for U.S. IPO, Sources Say
Allianz Life Says July Data Breach Impacts 1.5 Million People

Data Breach at Dealership Software Provider Motility Software Solutions Impacts 766K Clients

Adobe Analytics Bug Leaked Customer Tracking Data to Other Tenants

Hackers Exploit Milesight Routers to Send Phishing SMS to European Users

Shortcut-based Credential Lures Deliver DLL Implants

New WireTap Attack Extracts Intel SGX ECDSA Key via DDR4 Memory-Bus Interposer

‘Delightful’ Root-Access Bug in Red Hat OpenShift AI Allows Full Cluster Takeover

OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps