11/27-30/2025

Bloody Wolf Threat Actor Expands Activity Across Central Asia

North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware

Chinese Cyberattack Campaign Likely Impacted Every American, Former FBI Official Says

Critical New FBI Warning: This Simple Hack Can Empty Your Bank Account

Poems Can Trick AI Into Helping You Make a Nuclear

Malicious LLMs Empower Inexperienced Hackers With Advanced Tools

Threat Actors Exploit Calendar Subscriptions for Phishing and Malware Delivery

FCC Warns of Hackers Hijacking Radio Equipment For False Alerts

The Wired Guide to Digital OPSEC for Teens

Three Black Friday Scams to Watch Out For This Year

TryHackMe Races to Add Women to Christmas Cyber Challenge Roster After Backlash

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

GrapheneOS Bails on OVHcloud Over France’s Privacy Stance

Man Behind In-Flight Evil Twin WiFi Attacks Gets 7 Years in Prison

Poland Arrested Suspected Russian Citizen for Hacking Local Organizations’ Computer Networks

GreyNoise Launches Free Scanner to Check if You’re Part of a Botnet
Asahi Confirms 1.5 Million Customers Affected in Major Cyber-Attack

Top South Korean E-Commerce Firm Coupang Apologises Over Massive Data Breach

Korean Web Giant Naver Acquired Crypto Exchange Upbit, Which Reported a $30M Heist a Day Later

French Football Federation Suffers Data Breach

Brit Telco Brsk Confirms Breach as Bidding Begins for 230K+ Customer Records

Data Copied in Kensington and Chelsea Cyber Attack

At Least 35,000 Impacted by Dartmouth College Breach Through Oracle EBS Campaign

Computer Services Impacted After Ransomware Attack Hits Golf Manor (OH)

OpenAI Warns of Mixpanel Data Breach Impacting API Users

Public GitLab Repositories Exposed More Than 17,000 Secrets

PostHog Admits Shai-Hulud 2.0 Was Its Biggest Ever Security Bungle

Scattered Lapsus$ Hunters Take Aim At Zendesk Users

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

California Law Regulating Web Browsers Could Have National Data Privacy Impact, Experts Say

11/26/2025

Bug in Jury Systems Used by Several U.S. States Exposed Sensitive Personal Data

New ShadowV2 Botnet Malware Used AWS Outage as a Test Opportunity

Gainsight CEO Downplays Breach, Says Only a ‘Handful’ of Customers Had Data Stolen

Krebs: Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’

The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been ‘Performative’

House Energy and Commerce Committee Unveils New Draft Children’s Online Safety Bill
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps

Popular Forge Library Gets Fix for Signature Verification Bypass Flaw

ASUS Warns of New Critical Auth Bypass Flaw in AiCloud Routers

11/25/2025

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

FBI: Cybercriminals Stole $262M by Impersonating Bank Support Teams

Scammers Hacked Her Phone and Stole Thousands – So How Did They Get Her Details?

Crime Rings Enlist Hackers to Hijack Trucks

ICE Offers up to $280 Million to Immigrant-Tracking ‘Bounty Hunter’ Firms

HashJack Attack Shows AI browsers Can Be Fooled With a Simple ‘#’

Tor Switches to New Counter Galois Onion Relay Encryption Algorithm

The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals

Russia Arrests Young Cybersecurity Entrepreneur on Treason Charges
Multiple London Councils ‘Hit by Cyber-Attacks’

Georgia Court Filing Organization Warns of Outages After Ransomware Allegations

Clop’s Oracle EBS Rampage Reaches Dartmouth College

OnSolve CodeRED Cyberattack Disrupts Emergency Alert Systems Nationwide

Smishing Triad Impersonation Campaigns Expand Globally

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers

11/24/2025

Russian-Linked Malware Campaign Hides in Blender 3D Files

Hackers Knock Out Systems at Moscow-Run Postal Operator in Occupied Ukraine

Krebs: Is Your Android TV Streaming Box Part of a Botnet?

Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs

UK Privacy Regulator Has Seen ‘Collapse in Enforcement Activity,’ Rights Coalition Says

Software Companies Must Be Held Liable for British Economic Security, Say MPs

Comcast to Pay $1.5 Million U.S. Fine After Vendor Data Breach

This Hacker Conference Installed a Literal Antivirus Monitoring System

With AI Reshaping Entry-Level Cyber, What Happens to the Security Talent Pipeline?
Harvard University Discloses Data Breach Affecting Alumni, Donors

AI Nude Photo Link Appears on Kansas AG’s Website After Apparent Hack

Fresh ClickFix Attacks Use Windows Update Trick-Pics to Steal Credentials

Malicious Blender Model Files Deliver StealC Infostealing Malware

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Flaws Expose Risks in Fluent Bit Logging Agent

Amazon Is Using Specialized AI Agents for Deep Bug Hunting

Microsoft to Remove WINS Support after Windows Server 2025

11/21-23/2025

China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services

More Companies Are Shifting Workers to Passwordless Authentication

Google Enables Pixel-to-iPhone File Sharing via Quick Share, AirDrop

Press a Button and This SSD Will Self-Destruct With All Your Data

Russia-Linked Crooks Bought a Bank for Christmas to Launder Cyber Loot

Four Charged Over Alleged Plot to Smuggle Nvidia AI Chips Into China

‘Scattered Spider’ Teens Plead Not Guilty to UK Transport Hack

CrowdStrike Catches Insider Feeding Information to Hackers

Flock Safety Cameras Used to Monitor Protesters, Rights Group Finds

Google Begins Showing Ads in AI Mode (AI Answers)
A Swath of Bank Customer Data Was Hacked at Real Estate Technology Vendor SitusAMC. The FBI. Is Investigating

Wall Street Banks Scramble to Assess Fallout From Hack of Real-Estate Data Firm

Cox Enterprises Discloses Oracle E-Business Suite Data Breach

Iberia Discloses Customer Data Leak After Vendor Security Breach

Local Law Enforcement Agencies in Oklahoma, Massachusetts Responding to Cyber Incidents

ShinyHunters ‘Does Not Like Salesforce at All,’ Claims the Crew Accessed Gainsight 3 Months Ago

Matrix Push C2: Cybercriminals Exploit Browser Push Notifications to Deliver Malware

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability

11/20/2025

Google Exposes BadAudio Malware Used in APT24 Espionage Campaigns

Russia Blacklists S.T.A.L.K.E.R. Game Developer, Accusing It of Aiding Ukraine’s War Effort

With the Rise of AI, Cisco Sounds an Urgent Alarm About the Risks of Aging Tech

LLM-Generated Malware Is Improving, but Don’t Expect Autonomous Attacks Tomorrow

CISA Issues New Guidance on Bulletproof Hosting Threat

Krebs: Mozilla Says It’s Finally Done With Two-Faced Onerep

The FCC Is Rolling Back Steps Meant to Stop a Repeat of a Massive Telecom Hack

U.S. SEC Dismisses Case Against SolarWinds, Top Security Officer

NSO Seeks to Overturn Whatsapp Case, Saying It Is ‘Catastrophic’ for the Spyware Maker

Fired Techie Admits Sabotaging Ex-Employer, Causing $862K in Damage

Samourai Crypto Mixer Founders Sent to Prison for Laundering Over $237 Million

TV Streaming Piracy Service Photocall With 26M Yearly Visits Shut Down
Salesforce Investigates Customer Data Theft via Gainsight Breach

Salesforce-Linked Data Breach Claims 200+ Victims, Has ShinyHunters’ Fingerprints All Over It

Hacker Claims to Steal 2.3TB Data From Italian Rail Group, Almavia

GlobalProtect VPN Portals Probed with 2.3 Million Scan Sessions

UNC2891 Money Mule Network Reveals Full Scope of ATM Fraud Operation

TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows

New SonicWall SonicOS Flaw Allows Hackers to Crash Firewalls

D-Link Warns of New RCE Flaws in End-of-Life DIR-878 Routers

Lawmakers Reintroduce Bill to Bolster Cybersecurity at Securities and Exchange Commission

Privacy Oversight Board Finds FBI Does Not Buy Real-Time Location Data

11/19/2025

China-Linked Operation “WrtHug” Hijacks Thousands of ASUS Routers

Cloudflare Shows Internet Outages Aren’t a Matter of If — but When

Krebs: The Cloudflare Outage May Be a Security Roadmap

Airline Data Broker Airlines Reporting Corporation to Stop Selling Individuals’ Travel Records to Government Agencies

Vaping Is ‘Everywhere’ in Schools—Sparking a Bathroom Surveillance Boom

Half of Ransomware Access Due to Hijacked VPN Credentials

Russian Bulletproof Hosting Provider Sanctioned Over Ransomware Ties

California Man Admits to Laundering Crypto Stolen in $230M Heist

Coordinated Europol Operation Disrupts $55m in Cryptocurrency For Piracy

Palo Alto Tops Earnings Expectations, Announces Chronosphere Acquisition

What AI Bubble? Nvidia’s Strong Earnings Signal There’s More Room to Grow

Canadian Privacy Regulators Say Schools Share Blame for PowerSchool Hack
Major Russian Insurer VSK Facing Widespread Outages After Cyberattack

Email Breach at St. Anthony Hospital (IL) May Have Exposed the Information of More Than 6,600 People

Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime

PlushDaemon Hackers Unleash New Malware in China-Aligned Spy Campaigns

Meet ShinySp1d3r: New Ransomware-as-a-Service Created by ShinyHunters

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

W3 Total Cache WordPress Plugin Vulnerable to PHP Command Injection

CISA Gives Gov’t Agencies 7 Days to Patch New Fortinet Flaw

Google Search Is Now Using AI to Create Interactive UI to Answer Your Questions

The AI Attack Surface: How Agents Raise the Cyber Stakes

Lawmakers Reintroduce Bill to Bolster Cybersecurity at Securities and Exchange Commission

11/18/2025

White House Goes on Cyber Offensive

CISA 2015 Receives Extension, Offering Brief Relief for Cyber Information Sharing

FCC Looks to Torch Biden-Era Cyber Rules Sparked by Salt Typhoon Mess

CBO Director Testifies That Hackers Have Been Expelled From Email Systems

MI5 Warns of Chinese Spies Using LinkedIn to Gain Intel on Lawmakers

Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks

A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

GenAI and Deepfakes Drive Digital Forgeries and Biometric Fraud

Microsoft Teams to Let Users Report Messages Wrongly Flagged as Threats

Microsoft Is Turning Windows Into an ‘Agentic OS,’ Starting With the Taskbar

Microsoft to Integrate Sysmon Directly Into Windows 11, Server 2025

Windows 11 Gets New Cloud Rebuild, Point-In-Time Restore Tools

Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This Year

Amazon, Google Named by EU Among ‘Critical’ Tech Providers for Finance Industry

Zoomers Are Officially Worse at Passwords Than 80-Year-Olds

Russian Suspect Detained in Thailand Is Allegedly Tied to Void Blizzard Group
Cloudflare Outage Disrupts X, ChatGPT and Other Parts of the Internet

Cloudflare Says Outage That Hit X, ChatGPT and Other Sites Is Resolved

Pro-Russian Group Claims Hits on Danish Party Websites as Voters Head to Polls

French Agency Pajemploi Reports Data Breach Affecting 1.2m People

LG Battery Subsidiary Says Ransomware Attack Targeted Overseas Facility

Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach

Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet

Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar

New ShadowRay Attacks Convert Ray Clusters Into Crypto Miners

Researchers Detail Tuoni C2’s Role in an Attempted 2025 Real-Estate Cyber Intrusion

New npm Malware Campaign Redirects Victims to Crypto Sites

RondoDox Botnet Malware Now Hacks Servers Using XWiki Flaw

Fortinet Warns of New FortiWeb Zero-Day Exploited in Attacks

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

Microsoft: Windows 10 KB5072653 OOB Update Fixes ESU Install Errors

Bug Bounty Programs Rise as Key Strategic Security Solutions

11/17/2025

Pentagon and Soldiers Let Too Many Secrets Slip on Social Networks, Watchdog Says

Hackers Steal Maternity Ward CCTV Videos in India Cybercrime Racket

Google Is Collecting Troves of Data From Downgraded Nest Thermostats

X Launches Chat, Its New Encrypted DMs

UK Twitter Hacker Who Breached Obama’s Account Ordered to Repay $5.4 Million in Bitcoin

Govini Founder Eric Gillespie’s Lawyer Calls Child Sex Chat ‘Internet Fantasy,’ Not a Crime

Dutch Police Seizes 250 Servers Used by “Bulletproof Hosting” Service

Kamel Ghali on What’s ‘Theoretically Possible’ in Car Hacking
Kenyan Gov’t Websites Back Online After Hackers Deface Pages With White Supremacist Messages

Princeton University Discloses Data Breach Affecting Donors, Alumni

Pennsylvania AG Confirms Data Breach After INC Ransom Attack

Eurofiber France Warns of Breach After Hacker Tries to Sell Customer Data

DoorDash Email Spoofing Vulnerability Sparks Messy Disclosure Dispute

‘Largest-Ever’ Cloud DDoS Attack Pummels Azure With 3.64b Packets per Second

New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

11/14-16/2025

U.S. Announces New Strike Force Targeting Chinese Crypto Scammers

Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

Anthropic Claims of Claude AI-Automated Cyberattacks Met With Doubt

Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns

Google to Flag Android Apps With Excessive Battery Use on the Play Store

Google Backpedals on New Android Developer Registration Rules

Civil Society Decries Digital Rights ‘Rollback’ as European Commission Pushes Data Protection Changes

DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound

Suspected Russian Hacker Reportedly Detained in Thailand, Faces Possible U.S. Extradition

Five Plead Guilty to Helping North Koreans Infiltrate U.S. Firms

Uncertain Economy Takes Toll on Cybersecurity Teams

CISO Pay Increases 7% As Budget Growth Slows
FBI Flags Scam Targeting Chinese Speakers With Bogus Surgery Bills

Cyberattack on Russian Port Operator Aimed to Disrupt Coal, Fertilizer Shipments

DoorDash Hit by New Data Breach in October Exposing User Information

Checkout.com Snubs Hackers After Data Breach, to Donate Ransom Instead

Logitech Leaks Data After Zero-Day Attack

Decades-Old ‘Finger’ Protocol Abused in ClickFix Malware Attacks

Kraken Ransomware Benchmarks Systems for Optimal Encryption Choice

CISA Warns of Akira Ransomware Linux Encryptor Targeting Nutanix VMs

Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts

ASUS Warns of Critical Auth Bypass Flaw in DSL Series Routers

Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

Krebs: Microsoft Patch Tuesday, November 2025 Edition

Microsoft: Windows 10 KB5068781 ESU Update May Fail With 0x800f0922 Errors

11/13/2025

Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks

U.S. Dismisses Chinese Accusation of Extensive LuBian Mining Pool Hack

Two Key Cyber Laws Are Back as President Trump Signs Bill to End Shutdown

Microsoft Rolls Out Screen Capture Prevention for Teams Users

Google Will Let ‘Experienced Users’ Keep Sideloading Android Apps

Krebs: Google Sues to Disrupt Chinese SMS Phishing Triad

Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown

FBI: Akira Gang Has Received Nearly $250 Million in Ransoms

NHS Supplier Ends Probe Into Ransomware Attack That Contributed to Patient Death

Kazakhstan Becomes Latest Country to Ban ‘LGBT Propaganda’ Online

Kenya Kicks Off ‘Code Nation’ With a Nod to Cybersecurity

Orgs Move to SSO, Passkeys to Solve Bad Password Habits
Washington Post Data Breach Impacts Nearly 10K Employees, Contractors

Popular Android-Based Photo Frames Download Malware on Boot

Phishing Campaign Targets Customers of Major Italian Web Hosting Provider

Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data

Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain

“IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages

Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack

RCE Flaw in ImunifyAV Puts Millions of Linux-Hosted Sites at Risk

CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks

CISA Warns Feds to Fully Patch Actively Exploited Cisco Flaws

Ubuntu 25.10’s Rusty Sudo Holes Quickly Welded Shut

11/12/2025

Australia at Risk of ‘High-Impact Sabotage’ From China, Says Spy Chief

UK Plans Tougher Laws to Protect Public Services From Cyberattacks

British Government Unveils Long-Awaited Landmark Cybersecurity Bill

Army Officer With Indo-Pacific Experience Emerges as Potential Cyber Command, NSA Pick

U.S. Announces ‘Strike Force’ to Counter Southeast Asian Cyber Scams, Sanctions Myanmar Armed Group

Lighthouse: This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

German Extremist Arrested Over Operating Alleged Darknet Assassination Marketplace

DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules
Synnovis Notifies of Data Breach After 2024 Ransomware Attack

DanaBot Malware Is Back to Infecting Windows After 6-Month Break

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Windows 11 Now Supports 3rd-Party Apps for Native Passkey Management

Cybersecurity Firm Deepwatch Lays off Dozens, Citing Move to ‘Accelerate’ AI Investment

Bridging the Skills Gap: How Military Veterans Are Strengthening Cybersecurity

Russia Imposes 24-Hour Mobile Internet Blackout for Travelers Returning Home

Rhadamanthys Infostealer Disrupted as Cybercriminals Lose Server Access

11/10-11/2025

China-Aligned UTA0388 Uses AI Tools in Global Phishing Campaigns

Android Devices Targeted By KONNI APT in Find Hub Exploitation

CISA Orders Feds to Patch Samsung Zero-Day Used in Spyware Attacks

UK Asks Cyberspies to Probe Whether Chinese Buses Can Be Switched off Remotely

China Accuses U.S. of Orchestrating $13 Billion Bitcoin Hack

America’s Cybersecurity Defenses Are Cracking

Shutdown Deal Would Revive Cyber Intelligence-Sharing Bill

EU’s Reforms of GDPR, AI Slated by Privacy Activists for ‘Playing Into Big Tech’s Hands’

Yanluowang Initial Access Broker Pleaded Guilty to Ransomware Attacks

“Bitcoin Queen” Gets 11 Years in Prison for $7.3 Billion Bitcoin Scam

Mozilla Firefox Gets New Anti-Fingerprinting Defenses

Data Privacy Whistleblowers Would Get Expanded Protections Under California Proposal

Former Trump Official Named NSO Group Executive Chairman

Microsoft Releases KB5068781 — The first Windows 10 Extended Security Update
Hitachi-Owned GlobalLogic Admits Data Stolen on 10K Current and Former Staff

Wakefield & Associates (TN) Announces Breach of Client Data

Qilin Ransomware Activity Surges as Attacks Target Small Businesses

Quantum Route Redirect PhaaS Targets Microsoft 365 Users Worldwide

WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks

Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware

Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers

Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories

Hackers Exploit Critical Flaw in Gladinet’s Triofox File Sharing Product

Popular JavaScript Library Expr-Eval Vulnerable to RCE Flaw

SAP Fixes Hardcoded Credentials Flaw in SQL Anywhere Monitor

Synology Fixes BeeStation Zero-Days Demoed at Pwn2Own Ireland

Microsoft November 2025 Patch Tuesday Fixes 1 Zero-Day, 63 Flaws

11/6-9/2025

U.S. Congressional Budget Office (CBO) Hit by Cybersecurity Incident

Congressional Budget Office Implementing New Security Controls Following Cyberattack

Data Breach at Chinese Infosec Firm Reveals Cyber-Weapons and Target List

Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine

Previously Unknown Landfall Spyware Used in 0-Day Attacks on Samsung Phones

Scam Ads Are Flooding Social Media. These Former Meta Staffers Have a Plan

Krebs: Cloudflare Scrubs Aisuru Botnet from Top Domains List

Krebs: Drilling Down on Uncle Sam’s Proposed TP-Link Ban

The Government Shutdown Is a Ticking Cybersecurity Time Bomb

Japan Plans to Revise Foreign Investment Law to Sharpen Security Screening

Mexico City Is the Most Video-Surveilled Metropolis in the Americas

Lost iPhone? Don’t Fall for Phishing Texts Saying It Was Found

Italian Communications Executive Reveals He Was Targeted With Paragon Spyware

Edtech Company Fined $5.1 Million for Poor Data Security Practices Leading to Hack

Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts
“I Paid Twice” Phishing Campaign Targets Booking.com

How a Ransomware Gang Encrypted Nevada Government’s Systems

Washington Post Confirms Data Breach Linked to Oracle Hacks

Louvre’s Pathetic Passwords Belong in a Museum, Just Not That One

Cybersecurity Investigation Closes Manassas City Public Schools (VA) Monday

Cybercrims Plant Destructive Time Bomb Malware in Industrial .Net Extensions

Curly COMrades Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection

GlassWorm Malware Returns on OpenVSX with 3 New VSCode Extensions

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities

ClickFix Malware Attacks Evolve with Multi-OS Support, Video Tutorials

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic

Multi-Turn Attacks Expose Weaknesses in Open-Weight LLM Models

Critical Cisco UCCX Flaw Lets Attackers Run Commands as Root

Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362

Dangerous runC Flaws Could Allow Hackers to Escape Docker Containers

QNAP Fixes Seven NAS Zero-Day Flaws Exploited at Pwn2Own

11/5/2025

SonicWall Says State-Sponsored Hackers Behind September Security Breach

Russia-Linked ‘Curly COMrades’ Turn to Malicious Virtual Machines for Digital Spy Campaigns

Zohran Mamdani Just Inherited the NYPD Surveillance State

China Sentences 5 Myanmar Scam Kingpins to Death

Operation Chargeback Uncovers €300m Fraud Scheme in 193 Countries

UK Carriers to Block Spoofed Phone Numbers in Fraud Crackdown

Telecoms Cyber Chiefs Adopt Financial Sector’s Model of Collective Defense

Google Gets the U.S. Government’s Green Light to Acquire Wiz for $32B

Armis Raises $435 Million, Valuing Cybersecurity Startup at $6.1 Billion

Cyberattack Ate up Profits for First Half of Year, Retailer M&S Says
UNK_SmudgedSerpent Targets Academics With Political Lures

Hyundai AutoEver America Data Breach Exposes SSNs, Drivers Licenses

Central New Jersey Medical Center Suffers Ransomware Attack

University of Pennsylvania Confirms Hacker Stole Data During Cyberattack

Gootloader Malware Is Back With a Bang With New Tricks After 7-Month Break

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

AMD Red-Faced Over Random-Number Bug That Kills Cryptographic Security

CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence

11/4/2025

Russian Spies Pack Custom Malware Into Hidden VMs on Windows Machines

Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense Sectors

Data Brokers Selling Location Info That Can Be Used to Track EU Officials, Report Finds

Europe Sees Increase in Ransomware, Extortion Attacks

A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces

DragonForce Cartel Emerges as Conti-Derived Ransomware Threat

Lawmakers Say Stolen Police Logins Are Exposing Flock Surveillance Cameras to Hackers

FBI Warns of Criminals Posing as ICE, Urges Agents to ID Themselves

Treasury Sanctions 8 for Laundering North Korea Earnings From Cybercrime, IT Worker Scheme

Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep

French Police Seize €1.6m Amid Crypto Scam Network Crackdown

Health Privacy Bill Seeks Protections for Data Collected by Apps, Smartwatches
Data Breach at Major Swedish Software Supplier Impacts 1.5 Million

Media Giant Nikkei Reports Data Breach Impacting 17,000 People

Polish Loan Platform Hacked; Mobile Payment System and Other Businesses Disrupted

Hundreds of South Gloucestershire Residents’ Details Shared in Data Breach

Penn Data Breach Involves Decades of Student and Alumni Information

Apache OpenOffice Disputes Data Breach Claims by Akira Ransomware Gang

Malicious Android Apps on Google Play Downloaded 42 Million Times

Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed

Hackers Exploit WordPress Plugin Post SMTP to Hijack Admin Accounts

Hackers Exploit Critical Auth Bypass Flaw in JobMonster WordPress Theme

Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit

Microsoft Removing Defender Application Guard From Office

11/3/2025

New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea

Homeland Security Biometric Policy for Foreign Travelers Poses Data-Theft Risks

Hack Exposes Kansas City’s Secret Police Misconduct List

Cybercrooks Team Up With Organized Crime to Steal Pricey Cargo

Ransomware Negotiator, Pay Thyself!

U.S. Cybersecurity Experts Indicted for BlackCat Ransomware Attacks

MIT Sloan Quietly Shelves AI Ransomware Study After Researcher Calls BS

AWS, Nvidia, CrowdStrike Seek Security Startups to Enter the Arena

Data Breach Costs Lead to 90% Drop In Operating Profit at South Korean Telecom Giant
Hackers Are Attacking Britain’s Drinking Water Suppliers

Hacker Steals Over $120 Million From Balancer DeFi Crypto Protocol

Japanese Retailer Askul Confirms Data Leak After Cyberattack Claimed by Russia-Linked Group

Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive

Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data

Microsoft: SesameOp Malware Abuses OpenAI Assistants API in Attacks

New GDI Flaws Could Enable Remote Code Execution in Windows

Microsoft: Patch for WSUS Flaw Disabled Windows Server Hotpatching

CISA and NSA Outline Best Practices to Secure Exchange Servers

10/31-11/2/2025

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack

How to Hack a Poker Game Revealed

Security Concerns Persist Over System at Heart of Digital ID

Krebs: Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody

Alleged Conti Ransomware Gang Affiliate Appears in Tennessee Court After Ireland Extradition

Russia Finally Bites the Cybercrooks It Raised, Arresting Suspected Meduza Infostealer Devs

FCC Plans Vote to Remove Cyber Regulations Installed After Theft of Trump Info From Telecoms

Sling TV Settles With California for Allegedly Violating State Consumer Privacy Law
Hackers Threaten to Leak ‘Woke’ University of Pennsylvania Student Data

Attackers Dig Up $11M in Garden Finance Crypto Exploit

Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery

Rhysida Oysterloader Malvertising Campaign Leverages 40+ Code-Signing Certificates

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability

CISA: High-Severity Linux Flaw Now Exploited by Ransomware Gangs

Chinese Hackers Scanning, Exploiting Cisco ASA Firewalls Used by Governments Worldwide

Microsoft Edge Gets Scareware Sensor for Faster Scam Detection

Cybersecurity Earnings Rise as AI Dominates Strategies