2/26/2026

UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor

Ransomware Payment Rate Drops to Record Low as Attacks Surge

Scattered Lapsus$ Hunters Auditioning Female Voices to Sharpen Social Engineering

This AI Agent Is Designed to Not Go Rogue

Momentum Builds for Offensive Private-Sector Cyber Roles

NATO Says iPhones & iPads Are Secure Enough to Handle Classified Data

Greece’s Watergate: Four Convicted Over Spyware Scandal That Shook Greece

Former Air Force Officer Arrested for Conspiring With Hacker to Provide Flight Training to Chinese Military

Justice Department Exposed Cooperating Witnesses in Epstein Files

New York Sues Valve for Promoting Illegal Gambling via Game Loot Boxes
Olympique Marseille Confirms ‘Attempted’ Cyberattack After Data Leak

European DYI Chain ManoMano Data Breach Impacts 38 Million Customers

ShinyHunters Hacking Group Begins Leaking Customer Data in Dutch Telecom Odido Hack

Aeternum Botnet Shifts Command Control to Polygon Blockchain

New AirSnitch Attack Breaks Wi-Fi Encryption in Homes, Offices, and Enterprises

Previously Harmless Google API Keys Now Expose Gemini AI Data

Critical Juniper Networks PTX Flaw Allows Full Router Takeover

Trend Micro Warns of Critical Apex One Code Execution Flaws

Exploitable Vulnerabilities Present in 87% of Organizations

Microsoft Expands Windows Restore to More Enterprise Devices

Wyden Blocks Rudd Confirmation to Lead Cyber Command, NSA

2/25/2026

Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries

Chinese Cyberspies Breached Dozens of Telecom Firms, Gov’t Agencies

Iran-Linked Group Claims Hack of Israel’s Largest Healthcare Network

Critical Cisco SD-WAN Bug Exploited in Zero-Day Attacks Since 2023

U.S. Orders Diplomats to Fight Data Sovereignty Initiatives

How Mexico’s ‘CJNG’ Drug Cartel Embraced AI, Drones, and Social Media

Here’s What a Google Subpoena Response Looks Like, Courtesy of the Epstein Files

ADT Just Bought the Company That Invented Wi-Fi Motion Sensing

Cyber Startups Ride AI Wave to Funding Highs

Israeli AI-Cyber Firm Gambit Security Raises $61 Million

Nvidia Beats Back Bubble Fears With Record $68 Billion in Sales in Fourth Quarter

Former Defense Contractor Boss Gets 7+ Years for Selling Zero Days

Inside the Story of the U.S. Defense Contractor Who Leaked Hacking Tools to Russia

Moscow Man Accused of Posing as FSB Officer to Extort Conti Ransomware Gang
Popular Sex Toy Company Tenga Admits Hacker Stole Sensitive Customer Information

Medical Device Maker UFP Technologies Warns of Data Stolen in Cyberattack

Health Insurance Tech Provider TriZetto Says More Than 3 Million Impacted by 2024 Breach

Phishing Campaign ‘Diesel Vortex’ Targets Freight and Logistics Orgs in the U.S., Europe

New York City Transit Union Purportedly Targeted by Qilin

Malicious NuGet Package Targets Stripe Developers

Fake ‘Interview’ Repos Lure Next.js Devs Into Running Secret-Stealing Malware

CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability

Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration

Zyxel Warns of Critical RCE Flaw Affecting Over a Dozen Routers

U.S. Cybersecurity Agency CISA Reportedly in Dire Shape Amid Trump Cuts and Layoffs

FTC Says It Won’t Enforce COPPA Against Proper Use of Age Verification Tools

Discord Puts Global Age Verification Policy on Hold After Backlash

Chinese Prosecutors Raise Alarm About Growth of Domestic IP Theft

2/24/2026

North Korean Lazarus Group Expands Ransomware Activity With Medusa

Phishing Operation With Links to Russia, Armenia Compromised Western Cargo Companies, Researchers Find

Chinese AI Firms Hit Claude with Distillation Attacks, Anthropic Warns

AI Has Gotten Good at Finding Bugs, Not So Good at Swatting Them

AI Is Transformative, but Won’t Replace Established Software Anytime Soon

Cost of Insider Incidents Surges 20% to Nearly $20m

UK Fines Reddit $19 Million for Using Children’s Data Unlawfully

Marquis Sues Firewall Provider SonicWall, Alleges Security Failings With Its Firewall Backup Led to Ransomware Attack

Binance Fired Staff Who Flagged $1 Billion Moving to Sanctioned Iran Entities

U.S. ‘Committed’ to Fighting Transnational Gangs Behind Southeast Asian Scam Compounds: FBI

U.S. Sanctions Russian Exploit Broker for Buying Cyber Tools Stolen From Defense Contractor

Ukraine Pushes Tighter Telegram Regulation, Citing Russian Recruitment of Locals
CarGurus Data Breach Exposes Information of 12.4 Million Accounts

Conduent Data Breach Grows, Affecting at Least 25M People

Wynn Resorts Says Hackers Stole Employee Data

ShinyHunters Extortion Gang Claims Odido Breach Affecting Millions

University of Mississippi Medical Center Clinics Remain Closed Nearly a Week After Cyber Attack

Crypto Platform Step Finance Shutting Down After $40 Million Theft

Multifaceted Phishing Scheme Deceives Bitpanda Customers

UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware

UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors

1Campaign Platform Helps Malicious Google Ads Evade Detection

Android Mental Health Apps With 14.7m Installs Filled With Security Flaws

RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN

Critical SolarWinds Serv-U Flaws Offer Root Access to Servers

2/23/2026

APT28 Targeted European Entities Using Webhook-Based Macro Malware

Ukraine Says Cyberattacks on Energy Grid Now Used to Guide Missile Strikes

Ransomware Gangs Advancing Moscow’s Geopolitical Aims, Romanian Cyber Chief Warns

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

Cybersecurity Stocks Drop for a Second Day as New Anthropic Tool Fuels AI Disruption Fears

IQM Quantum Computers to List Shares in Us at Initial $1.8 Billion Valuation

Suspected Anonymous Members Detained in Spain Over Post-Flood DDoS Blitz
Air Côte d’Ivoire Confirms Cyberattack Following Ransomware Claims

Ad Tech Firm Optimizely Confirms Data Breach Affecting Customers After Vishing Attack

Supply Chain Shai-Hulud-Like Worm Targets Developers via npm and AI Tools

Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb

PayPal Fraud Investigation Reveals Sophisticated Python Malware

CISA: Two Recently Patched RoundCube Webmail Flaws Now Exploited in Attacks

Global Data Protection Authorities Warn Generative AI Companies Against Replicating Real People

2/20-22/2026

UAE Foils Cyber Attacks, State News Agency Says

Hackers Breach Contractor Linked to Ukraine’s Central Bank Collectible Coin Store

Russia Stepping up Hybrid Attacks, Preparing for Long Standoff With West, Dutch Intelligence Warns

Dramatic Escalation in Frequency and Power of DDoS Attacks

Predator Spyware Hooks iOS SpringBoard to Hide Mic, Camera Activity

Krebs: ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

DHS Wants a Single Search Engine to Flag Faces and Fingerprints Across Agencies

New Cybersecurity Rules for U.S. Defense Industry Create Barrier for Some Small Suppliers

Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case

Two Former Google Engineers and Spouse Indicted Over Trade Secret Transfers to Iran
ShinyHunters Demands $1.5m Not to Leak Vegas Casino Wynn Resorts and Resort Chain Data

Japanese Tech Giant Advantest Hit by Ransomware Attack

AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries

PayPal App Code Error Leaked Personal Info and a ‘Few’ Unauthorized Transactions

ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware

Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems

Arkanix Stealer Pops up as Short-Lived AI Info-Stealer Experiment

BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

Romanian Hacker Faces up to 7 Years for Breaching Oregon Emergency Management Dept

2/19/2026

Researchers Warn Volt Typhoon Still Embedded in U.S. Utilities and Some Breaches May Never Be Found

Nation-State Hackers Hit Businesses For Commercial Edge

Industrial Control System Vulnerabilities Hit Record Highs

The AI Security Nightmare Is Here and It Looks Suspiciously Like Lobster

Researchers Reveal Six New OpenClaw Vulnerabilities

How to Organize Safely in the Age of Surveillance

Crims Hit a $20M Jackpot via Malware-Stuffed ATMs

INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown

Nigerian Man Gets Eight Years in Prison for Hacking Tax Firms

UK to Demand Social Platforms Take Down Abusive Intimate Images Within 48 Hours

West Virginia Sues Apple for Alleged Child Sexual Abuse Material Failures

Google Blocked Over 1.75 Million Play Store App Submissions From Obtaining Excessive Access in 2025

Orange Shares Hit 16-Year High on Profit Beat, New Targets and M&A Hopes
Cyberattack Cripples University of Mississippi Medical Center Systems, Forces Clinic Closures

Attackers Breach France’s National Bank Account Database

Rhysida Ransomware Gang Threatens Cheyenne and Arapaho Tribes After Shutting Down Schools

Microsoft Error Sees Confidential Emails Exposed to AI Tool Copilot

Bug in Student Admissions Website Ravenna Hub Exposed Children’s Personal Information

Billions of Records Exposed by Unsecured IDMerit Database

Industrial-Scale Fake Coretax Apps Drive $2m Fraud in Indonesia

Starkiller: New ‘Commercial-Grade’ Phishing Kit Bypasses MFA

Hackers Target Microsoft Entra Accounts in Device Code Vishing Attacks

Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users

PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence

Remcos RAT Expands Real-Time Surveillance Capabilities

Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center

2/18/2026

New Backdoor Found in Android Tablets Targeting Users in Russia, Germany and Japan

Predator Spyware Used to Infect Phone Belonging to Angolan Journalist

Parents Angered by Lack of Online Safety Strategy

Spain Orders NordVPN, ProtonVPN to Block LaLiga Piracy Sites

Glendale Man Gets 5 Years in Prison for Role in Darknet Drug Ring

Fraudster Hacked Hotel System, Paid 1 Cent for Luxury Rooms, Spanish Cops Say

Texas Sues TP-Link Over China Links and Security Vulnerabilities

Poland Bans Chinese-Made Cars From Entering Military Sites

Hacking Conference Def Con Bans Three People Linked to Jeffrey Epstein
A Vast Trove of Exposed Social Security Numbers May Put Millions at Risk of Identity Theft

Data Breach at Fintech Firm Figure Affects Nearly 1 Million Accounts

ShinyHunters Allegedly Drove off With 1.7m Cargurus Records

Cryptojacking Campaign Exploits Driver to Boost Monero Mining

Telegram Channels Expose Rapid Weaponization of SmarterMail Flaws

Fed Agencies Ordered to Patch Dell Bug by Saturday After Exploitation Warning

Dell’s Hard-Coded Flaw: A Nation-State Goldmine

Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution

Critical Infra Honeywell CCTVs Vulnerable to Auth Bypass Flaw

2/17/2026

China Remains Embedded in U.S. Energy Networks ‘For the Purpose of Taking It Down’

Chinese Hackers Exploiting Dell Zero-Day Flaw Since Mid-2024

A Defector Explains the Remote-Work Scam Helping North Korea Pay for Nukes

Low-Skilled Cybercriminals Use AI to Perform “Vibe Extortion” Attacks

Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies

Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers

Significant Rise in Ransomware Attacks Targeting Industrial Operations

Wrongly Sent Emails ‘Most Common Data Breach’

Palo Alto Networks Slumps 6% as Third Quarter Profit Guidance Falls Short

U.S. Lawyers Fire Up Privacy Class Action Accusing Lenovo of Bulk Data Transfers to China

Poland Arrests Suspect Linked to Phobos Ransomware Operation
Hackers Target Supporters of Iran Protests in New Espionage Campaign

Citizen Lab: Kenyan Authorities Used Cellebrite to Break Into Phone of Dissident

Fake Milano Cortina Sites Target Thousands With Discount Scams, Cybersecurity Firm Says

SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates

RMM Abuse Explodes as Hackers Ditch Malware

Flaws in Popular VSCode Extensions Expose Developers to Attacks

Notepad++ Boosts Update Security With ‘Double-Lock’ Mechanism

Android 17 Beta Introduces Secure-By-Default Architecture

Apple Expands RCS Encryption and Memory Protections in iOS 26.4

Ireland Now Also Investigating X Over Grok-Made Sexual Images

2/13-16/2026

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations

China May Be Rehearsing a Digital Siege, Taiwan Warns

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs

UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors

Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third

NATO Must Impose Costs on Russia, China Over Cyber and Hybrid Attacks, Says Deputy Chief

Europe Must Adapt to ‘Permanent’ Cyber and Hybrid Threats, Sweden Warns

EU Can’t Be ‘Naive’ About Enemies Shutting Down Critical Infrastructure, Warns Tech Official

Space Emerges as New Front in Great Power Competition, Officials Warn

AI Coding Platform’s Flaws Allow BBC Reporter to Be Hacked

Vulnerabilities in Password Managers Allow Hackers to View and Change Passwords

The El Paso No-Fly Debacle Is Just the Beginning of a Drone Defense Mess

Robot Dogs Are on Going on Patrol at the 2026 World Cup in Mexico

Ring Ends Partnership Plans With Flock Days After Privacy Blowback From Super Bowl Ad

Dutch Cops Arrest Man After Sending Him Confidential Files by Mistake

Louis Vuitton, Dior, and Tiffany Fined $25 Million Over Data Breaches

U.S. Needs to Impose ‘Real Costs’ on Bad Actors, State Department Cyber Official Says
Washington Hotel in Japan Discloses Ransomware Infection Incident

Canada Goose Ruffles Feathers Over 600K Record Dump, Says Leak Is Old News

Eurail Says Stolen Traveler Data Now up for Sale on Dark Web

Over 500,000 Vkontakte Accounts Hijacked Through Malicious Chrome Extensions

Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft

Snail Mail Letters Target Trezor and Ledger Users in Crypto-Theft Attacks

Pastebin Comments Push ClickFix JavaScript Attack to Hijack Crypto Swaps

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

New ClickFix Attack Abuses Nslookup to Retrieve Powershell Payload via DNS

Claude LLM Artifacts Abused to Push Mac Infostealers in ClickFix Attack

Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens

OysterLoader Evolves With New C2 Infrastructure and Obfuscation

CISA Flags Critical Microsoft Sccm Flaw as Exploited in Attacks

CISA Gives Feds 3 Days to Patch Actively Exploited BeyondTrust Flaw

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released

Starlink Restrictions Hit Russian Forces as Moscow Seeks Workarounds

Infosec Exec Sold Eight Zero-Day Exploit Kits to Russia, Says DOJ

2/12/2026

Palo Alto Chose Not to Tie China to Hacking Campaign for Fear of Retaliation From Beijing, Sources Say

Nation-State Hackers Embrace Gemini AI for Malicious Campaigns, Google Finds

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Kim Jong Un Chooses Teen Daughter as Heir, Says Seoul

Cloudflare Rises 5% as AI Agent Wave Led by Viral Moltbot Boosts Security Demand

Check Point Software Lifts Profit Outlook as AI-Driven Cyber Threats Surge

AI Skills Represent Dangerous New Attack Surface, Says TrendAI

Those ‘Summarize With AI’ Buttons May Be Lying to You

Crypto-Funded Human Trafficking Is Exploding

Guthrie Doorbell Video Delayed by Difficult Data Recovery, but Privacy Advocates Still Worry

FTC Push for Age Verification a ‘Major Landmark’ for Spread of the Tool

WhatsApp Says Russia Tried to Fully Block Platform, Push Users to State App
Odido Data Breach Exposes Personal Info of 6.2 Million Customers

Romania’s Oil Pipeline Operator Conpet Confirms Data Stolen in Attack

Fake AI Chrome Extensions With 300K Users Steal Credentials, Emails

World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks

83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure

Critical BeyondTrust RCE Flaw Now Exploited in Attacks, Patch Now

WordPress Plugin With 900K Installs Vulnerable to Critical RCE Flaw

Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Other Devices

Microsoft: New Windows LNK Spoofing Issues Aren’t Vulnerabilities

Bitwarden Introduces ‘Cupid Vault’ for Secure Password Sharing

A Hard Truth in Munich: Cyber Defense Runs Through Silicon Valley

U.S. Wants Cyber Partnerships to Send ‘Coordinated, Strategic Message’ to Adversaries

2/11/2026

APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities

Krebs: Kimwolf Botnet Swamps Anonymity Network I2P

Posting AI-Generated Caricatures on Social Media Is Risky, Infosec Killjoys Warn

CBP Signs Clearview AI Deal to Use Face Recognition for ‘Tactical Targeting’

AI Rising: Do We Know Enough About the Data Populating It?

40 State AGs Warn House KOSA Bill Falls Short of Protecting Children Online

Police Arrest Seller of JokerOTP MFA Passcode Capturing Tool

Moscow Moves to Throttle Telegram as Kremlin Pushes Its Own Messaging App

UK Blames Legacy Systems as Ministers Promise No Repeat of Afghan Breach
Georgia Healthcare Company ApolloMD Data Breach Impacts More Than 620,000

Tulsa International Airport Hit With Ransomware Attack

LummaStealer Infections Surge After Castleloader Malware Campaigns

Crazy Ransomware Gang Abuses Employee Monitoring Tool in Attacks

First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials

Microsoft Fixes Notepad Flaw That Could Trick Users Into Clicking Malicious Markdown Links

Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms

Interim CISA Chief: ‘When the Government Shuts Down, Cyber Threats Do Not’

Is Spyware Hiding on Your Phone? How to Find Out and Remove It – Fast

2/10/2026

DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies

North Korean Hackers Use New macOS Malware in Crypto-Theft Attacks

“Digital Parasite” Warning as Attackers Favor Stealth for Extortion

White House to Meet With GOP Lawmakers on FISA Section 702 Renewal

Cyber Command, NSA Nominee Rudd Advances to Senate Floor

British Army Splashes $86M on AI Gear to Speed up the Battlefield Kill Chain

Fugitive Behind $73M ‘Pig Butchering’ Scheme Gets 20 Years in Prison

Google Secures EU Antitrust Approval for $32 Billion Wiz Acquisition

Microsoft Announces New Mobile-Style Windows Security Controls
Nearly 17,000 Volvo Staff Dinged in Supplier Breach

Phorpiex Phishing Delivers Low-Noise Global Group Ransomware

New Mobile Spyware ZeroDayRAT Targets Android and iOS

Malicious 7-Zip Site Distributes Installer Laced With Proxy Tool

Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools

New Linux Botnet SSHStalker Uses Old-School IRC for C2 Comms

Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution

Krebs: Patch Tuesday, February 2026 Edition

Microsoft Is Keeping Secure Boot Alive With Windows Updates

What Organizations Need to Change When Managing Printers

2/9/2026

China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign

Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

Senegal Confirms Breach of National ID Card Department After Ransomware Claims

EU, Dutch Government Announce Hacks Following Ivanti Zero-Days

European Commission Discloses Breach That Exposed Staff Data

Leaked Technical Documents Show China Rehearsing Cyberattacks on Neighbors’ Critical Infrastructure

Iran’s Digital Surveillance Machine Is Almost Complete

AI Is Here to Replace Nuclear Treaties. Scared Yet?

Researchers Find 40,000+ Exposed OpenClaw Instances

Social Media Platforms Earn Billions from Scam Ads

Hacked, Leaked, Exposed: Why You Should Never Use Stalkerware Apps

Two Connecticut Men Charged In Alleged $3m Gambling Fraud Scheme
Hackers Breach SmarterTools Network Using Flaw in Its Own Software

SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers

Discord Faces Backlash Over Age Checks After Data Breach Exposed 70,000 IDs

Payment Tech Provider for Texas, Florida Governments BridgePay Working With FBI to Resolve Ransomware Attack

Suspected Sabotage Disrupts Trains in Northern Italy as Winter Games Begin

TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure

VoidLink Malware Exhibits Multi-Cloud Capabilities and AI Code

New Zero-Click Flaw in Claude Desktop Extensions, Anthropic Declines Fix

BeyondTrust Warns of Critical RCE Flaw in Remote Support Software

Microsoft: Exchange Online Flags Legitimate Emails as Phishing

Russia Grants Asylum to Spanish Professor Wanted for Alleged Pro-Moscow Cyber Operations

2/6-8/2026

German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists

Norwegian Intelligence Discloses Country Hit by Salt Typhoon Campaign

Unsettled Cyber Intel Law Erodes Private-Sector Trust

U.S. Software Stocks Slammed on Mounting Fears Over AI Disruption, Lose $1 Trillion in Week

NYC Explores Using AI Cameras to Spot Subway Fare Evaders

EU Says TikTok Faces Large Fine Over “Addictive Design”

Illinois Man Pleads Guilty to Hacking Nearly 600 Women’s Snapchat Accounts
DKnife: Chinese-Made Malware Kit Targets Chinese-Based Routers and Edge Devices

Flickr Emails Users About Data Breach, PINs It on 3rd Party

Payments Platform BridgePay Confirms Ransomware Attack Behind Outage

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

CISA Warns of SmarterMail RCE Flaw Used in Ransomware Attacks

OpenClaw Integrates VirusTotal Scanning to Detect Malicious ClawHub Skills

New Tool Blocks Imposter Attacks Disguised as Safe Commands

2/5/2026

Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends

Protests Don’t Impede Iranian Spying on Expats, Syrians, Israelis

Russian Hackers Attacking European Maritime and Transport Orgs Using Microsoft Office Exploit

Asia-Based Government Spies TGR-STA-1030 Quietly Broke Into Critical Networks Across 37 Countries

ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are

Smartphones Now Involved in Nearly Every Police Investigation

AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+

UNICEF Calls for Criminalization of AI Content Depicting Child Sex Abuse

Dark Patterns Undermine Security, One Click at a Time

CISA Gives Federal Agencies One Year to Rip Out End-Of-Life Devices
Spain’s Ministry of Science Shuts Down Systems After Breach Claims

Romanian Oil Pipeline Operator Conpet Discloses Cyberattack

Italian University la Sapienza Goes Offline After Cyberattack

Substack Data Breach Exposed Users’ Emails and Phone Numbers

Data Breach at Govtech Giant Conduent Balloons, Affecting Millions More Americans

Betterment Breach May Expose 1.4m Users After Social Engineering Attack

Zendesk Spam Wave Returns, Floods Users With ‘Activate Account’ Emails

AISURU/Kimwolf Botnet Launches Record-Setting 31.4 Tbps DDoS Attack

Ransomware Gang Uses ISPsystem VMs for Stealthy Payload Delivery

Malicious Commands in GitHub Codespaces Enable RCE

2/4/2026

U.S. Used Cyber Weapons to Disrupt Iranian Air Defenses During 2025 Strikes

Ukraine Tightens Controls on Starlink Terminals to Counter Russian Drones

Italy Foiled Russia-Linked Cyberattacks on Embassies, Olympic Sites, Minister Says

How 2026 Winter Olympics Security Is Preparing for the Opening Ceremony

China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns

OpenClaw’s AI ‘Skill’ Extensions Are a Security Nightmare

Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models

Google Cloud’s Customer Chief Returns to Microsoft as Head of Security

With AI Accountability Stalling, Boards Must Push Tech Giants for Greater Transparency

Super Bowl Prepares for Potential AI Cybersecurity Threat

Owner of Incognito Dark Web Drugs Market Gets 30 Years in Prison

DragonForce Ransomware Gang Goes Full ‘Godfather’ With Cartel
Hackers Compromise NGINX Servers to Redirect User Traffic

Coinbase Confirms Insider Breach Linked to Leaked Support Tool Screenshots

Cybercrime Group Claims Responsibility for Penn Email Hack, Leaks Additional Internal Files

Hackers Publish Personal Information Stolen During Harvard, UPenn Data Breaches

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers

Global SystemBC Botnet Found Active Across 10,000 Infected Systems

New Technical Markers Reveal Expanding ShadowSyndicate Cybercriminal Infrastructure

EDR Killer Tool Uses Signed Kernel Driver From Forensic Software

Nitrogen Ransomware Is So Broken Even the Crooks Can’t Unlock Your Files

CISA Warns of Five-Year-Old GitLab Flaw Exploited in Attacks

CISA: VMware ESXi Flaw Now Exploited in Ransomware Attacks

Critical n8n Flaws Disclosed Along With Public Exploits

2/3/2026

Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days

Poland Detains Defense Ministry Employee on Suspicion of Spying for Russia

U.S. Senator Says AT&T, Verizon Blocking Release of Salt Typhoon Security Assessment Reports

CISA Official Says CIRCIA Cyber Reporting Update Is ‘Weeks’ Away

CISA Updated Ransomware Intel on 59 Bugs Last Year Without Telling Defenders

Trump Administration Eyes 10-Year Extension of Cybersecurity Law

How Data Brokers Can Fuel Violence Against Public Servants

X Marks the Raid: French Cops Swoop on Musk’s Paris Ops

UK ICO Launches Investigation into X Over AI Generated Non-Consensual Sexual Imagery

UK Investigating First Suspected Breach of Cyber Sanctions

Polish Cops Bail 20-Year-Old Bedroom Botnet Operator

Varonis to Acquire AllTrue as AI Security Concerns Mount

OpenAI CEO Altman Dismisses Moltbook as Likely Fad, Backs the Tech Behind It

The Rise of Moltbook Suggests Viral AI Prompts May Be the Next Big Security Threat
Iron Mountain: Data Breach Mostly Limited to Marketing Materials

Step Finance Says Compromised Execs’ Devices Led to $40M Crypto Theft

New Password-Stealing Phishing Campaign Targets Corporate Dropbox Credentials

Wave of Citrix NetScaler Scans Use Thousands of Residential Proxies

Researchers Warn of New “Vect” RaaS Variant

DockerDash Exposes AI Supply Chain Weakness In Docker’s Ask Gordon

Critical React Native Metro Dev Server Bug Under Attack as Researchers Scream Into the Void

Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package

CISA Flags Critical SolarWinds RCE Flaw as Exploited in Attacks

SQL Injection Flaw Affects 40,000 WordPress Sites

8-Minute Access: AI Accelerates Breach of AWS Environment

Microsoft Finally Sends TLS 1.0 and 1.1 to the Cloud Retirement Home

California City Turns off Flock Cameras After Company Shared Data Without Authorization

Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox

Spain Will Ban Social Media for Kids Under 16

2/2/2026

Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks

Notepad++ Updates Got Hijacked for Months and Could Have Spied for China

Spyware Maker Is Hijacking Diplomatic Efforts to Limit Commercial Hacking, Civil Society Warns

From Clawdbot to Moltbot to OpenClaw: Meet the AI Agent Generating Buzz and Fear Globally

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

Malicious MoltBot Skills Used to Push Password-Stealing Malware

Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users

Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site

Hackers Recruit Unhappy Insiders to Bypass Data Security

Drone Sightings Have Doubled Near UK Military Bases, Warns British Government
Krebs: Please Don’t Feed the Scattered Lapsus ShinyHunters

Hackers Attempt to Extort Parents After School Refuses to Pay Ransom Fee

StopICE Hacked to Send Alarming Text Messages, Admins Accuse Border Patrol Agent of Sabotage

Panera Bread Breach Impacts 5.1 Million Accounts, Not 14 Million Customers

McDonald’s Is Not Lovin’ Your BigMac, Happy Meal, and McNuggets McPasswords

NationStates Confirms Data Breach, Shuts Down Game Site

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos

NSA Publishes New Zero Trust Implementation Guidelines

Netherlands Latest European Country to Mull Social Media Ban for Children

1/30-2/1/2026

Labyrinth Chollima Evolves into Three North Korean Hacking Groups

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

RedKitten: New AI-Developed Malware SloppyMIO Campaign Targets Iranian Protests

I Mocked the Saudi Leader on YouTube – Then My Phone Was Hacked and I Was Beaten up in London

Informant Told FBI That Jeffrey Epstein Had a ‘Personal Hacker’

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

Coupang CEO Questioned by Police Investigating Obstruction of Probe Into Data Breach

Thoma Bravo Explores Sale of Identity Software Firm Imprivata, Sources Say

Operation Switch Off Dismantles Major Pirate TV Streaming Services

Department of Justice Seizes Domains for Bulgarian Piracy Sites

Crypto Wallets Received a Record $158 Billion in Illicit Funds Last Year
New Britain (CT) ‘Network Disruption’ Was Due to Ransomware Attack, Mayor Says

Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms

Cloud Storage Payment Scam Floods Inboxes With Fake Renewals

National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat

Exposed MongoDB Instances Still Targeted in Data Extortion Attacks

Researcher Reveals Evidence of Private Instagram Profiles Leaking Photos

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

New Apple Privacy Feature Limits Location Tracking on iPhones, iPads

AI Security Startup CEO Posts a Job. Deepfake Candidate Applies, Inner Turmoil Ensues.

Open-Source AI Is a Global Security Nightmare Waiting to Happen, Say Researchers