11/5/2025

SonicWall Says State-Sponsored Hackers Behind September Security Breach

Russia-Linked ‘Curly COMrades’ Turn to Malicious Virtual Machines for Digital Spy Campaigns

Zohran Mamdani Just Inherited the NYPD Surveillance State

China Sentences 5 Myanmar Scam Kingpins to Death

Operation Chargeback Uncovers €300m Fraud Scheme in 193 Countries

UK Carriers to Block Spoofed Phone Numbers in Fraud Crackdown

Telecoms Cyber Chiefs Adopt Financial Sector’s Model of Collective Defense

Google Gets the U.S. Government’s Green Light to Acquire Wiz for $32B

Armis Raises $435 Million, Valuing Cybersecurity Startup at $6.1 Billion

Cyberattack Ate up Profits for First Half of Year, Retailer M&S Says
UNK_SmudgedSerpent Targets Academics With Political Lures

Hyundai AutoEver America Data Breach Exposes SSNs, Drivers Licenses

Central New Jersey Medical Center Suffers Ransomware Attack

University of Pennsylvania Confirms Hacker Stole Data During Cyberattack

Gootloader Malware Is Back With a Bang With New Tricks After 7-Month Break

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

AMD Red-Faced Over Random-Number Bug That Kills Cryptographic Security

CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence

11/4/2025

Russian Spies Pack Custom Malware Into Hidden VMs on Windows Machines

Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense Sectors

Data Brokers Selling Location Info That Can Be Used to Track EU Officials, Report Finds

Europe Sees Increase in Ransomware, Extortion Attacks

A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces

DragonForce Cartel Emerges as Conti-Derived Ransomware Threat

Lawmakers Say Stolen Police Logins Are Exposing Flock Surveillance Cameras to Hackers

FBI Warns of Criminals Posing as ICE, Urges Agents to ID Themselves

Treasury Sanctions 8 for Laundering North Korea Earnings From Cybercrime, IT Worker Scheme

Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep

French Police Seize €1.6m Amid Crypto Scam Network Crackdown

Health Privacy Bill Seeks Protections for Data Collected by Apps, Smartwatches
Data Breach at Major Swedish Software Supplier Impacts 1.5 Million

Media Giant Nikkei Reports Data Breach Impacting 17,000 People

Polish Loan Platform Hacked; Mobile Payment System and Other Businesses Disrupted

Hundreds of South Gloucestershire Residents’ Details Shared in Data Breach

Penn Data Breach Involves Decades of Student and Alumni Information

Apache OpenOffice Disputes Data Breach Claims by Akira Ransomware Gang

Malicious Android Apps on Google Play Downloaded 42 Million Times

Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed

Hackers Exploit WordPress Plugin Post SMTP to Hijack Admin Accounts

Hackers Exploit Critical Auth Bypass Flaw in JobMonster WordPress Theme

Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit

Microsoft Removing Defender Application Guard From Office

11/3/2025

New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea

Homeland Security Biometric Policy for Foreign Travelers Poses Data-Theft Risks

Hack Exposes Kansas City’s Secret Police Misconduct List

Cybercrooks Team Up With Organized Crime to Steal Pricey Cargo

Ransomware Negotiator, Pay Thyself!

U.S. Cybersecurity Experts Indicted for BlackCat Ransomware Attacks

MIT Sloan Quietly Shelves AI Ransomware Study After Researcher Calls BS

AWS, Nvidia, CrowdStrike Seek Security Startups to Enter the Arena

Data Breach Costs Lead to 90% Drop In Operating Profit at South Korean Telecom Giant
Hackers Are Attacking Britain’s Drinking Water Suppliers

Hacker Steals Over $120 Million From Balancer DeFi Crypto Protocol

Japanese Retailer Askul Confirms Data Leak After Cyberattack Claimed by Russia-Linked Group

Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive

Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data

Microsoft: SesameOp Malware Abuses OpenAI Assistants API in Attacks

New GDI Flaws Could Enable Remote Code Execution in Windows

Microsoft: Patch for WSUS Flaw Disabled Windows Server Hotpatching

CISA and NSA Outline Best Practices to Secure Exchange Servers

10/31-11/2/2025

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack

How to Hack a Poker Game Revealed

Security Concerns Persist Over System at Heart of Digital ID

Krebs: Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody

Alleged Conti Ransomware Gang Affiliate Appears in Tennessee Court After Ireland Extradition

Russia Finally Bites the Cybercrooks It Raised, Arresting Suspected Meduza Infostealer Devs

FCC Plans Vote to Remove Cyber Regulations Installed After Theft of Trump Info From Telecoms

Sling TV Settles With California for Allegedly Violating State Consumer Privacy Law
Hackers Threaten to Leak ‘Woke’ University of Pennsylvania Student Data

Attackers Dig Up $11M in Garden Finance Crypto Exploit

Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery

Rhysida Oysterloader Malvertising Campaign Leverages 40+ Code-Signing Certificates

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability

CISA: High-Severity Linux Flaw Now Exploited by Ransomware Gangs

Chinese Hackers Scanning, Exploiting Cisco ASA Firewalls Used by Governments Worldwide

Microsoft Edge Gets Scareware Sensor for Faster Scam Detection

Cybersecurity Earnings Rise as AI Dominates Strategies

10/30/2025

Diplomatic Entities in Belgium and Hungary Hacked in China-Linked Spy Campaign

Leaker Reveals Which Pixels Are Vulnerable to Cellebrite Phone Hacking

Shadow AI: One In Four Employees Use Unapproved AI Tools, Research Finds

LinkedIn Phishing Targets Finance Execs With Fake Board Invites

Proton Trains New Service to Expose Corporate Infosec Cover-Ups

NASA’s Quiet Supersonic Jet Takes Flight

Coalition Calls on FTC to Block Meta From Using Chatbot Interactions to Target Ads, Personalize Content
Threat Actors Utilize AdaptixC2 for Malicious Payload Delivery

Critical Flaws Found in Elementor King Addons Affect 10,000 Sites

Massive Surge of NFC Relay Malware Steals Europeans’ Credit Cards

Malicious NPM Packages Fetch Infostealer for Windows, Linux, macOS

CISA Orders Feds to Patch VMware Tools Flaw Exploited by Chinese Hackers

Cyber Info Sharing ‘Holding Steady’ Despite Lapse in CISA 2015, Official Says

The AI Trust Paradox: Why Security Teams Fear Automated Remediation

10/29/2025

U.S. Company Ribbon Communications With Access to Biggest Telecom Firms Uncovers Breach by Unnamed Nation-State Hackers

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

New Names Surface for NSA Director, Other Top Jobs at Spy Agency

The Microsoft Azure Outage Shows the Harsh Reality of Cloud Failures

Krebs: Aisuru Botnet Shifts from DDoS to Residential Proxies

New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts

Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm

CISOs Finally Get a Seat at the Board’s Table — But There’s a Big Catch
Canada Says Hacktivists Breached Water and Energy Facilities

Cloud Atlas Hackers Target Russian Agriculture Sector Ahead of Industry Forum

EY Exposes 4TB+ SQL Database to Open Internet for Who Knows How Long

Tata Motors Confirms It Fixed Security Flaws, Which Exposed Company and Customer Data

More Than 10 Million Impacted by Breach of Government Contractor Conduent

Investment Scams Spread Across Asia With International Reach

PhantomRaven: Npm Malware Uses Invisible Dependencies to Infect Dozens of Packages

WordPress Security Plugin Exposes Private Data to Site Subscribers

Windows 11 KB5067036 Update Rolls out Administrator Protection Feature

10/28/2025

SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats

Researchers Expose GhostCall and GhostHire: BlueNoroff’s New Malware Chains

Nation-State Cyber Ecosystems Weakened by Sanctions, Report Reveals

Clearview AI Faces Criminal Heat for Ignoring EU Data Fines

AI Browsers Face a Security Flaw as Inevitable as Death and Taxes

Palo Alto Networks Debuts Automated AI Agents to Fight Cyberattacks

Sublime Raises $150 Million for AI-Powered Email Security

A Quarter of Scam Victims Have Considered Self-Harm
Advertising Giant Dentsu Reports Data Breach at Subsidiary Merkle

New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human

New Atroposia Malware Comes With a Local Vulnerability Scanner

New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves

CISA Warns of Two More Actively Exploited Dassault Vulnerabilities

Google Chrome to Warn Users by Default Before Opening Insecure HTTP Sites

FCC Adopts New Rule Targeting Robocalls

F5 Expects Big Revenue Hit From Recent Cyber Attack Compromising Many

10/27/2025

Chatbots Are Pushing Sanctioned Russian Propaganda

Iran’s School for Cyberspies Could’ve Used a Few More Lessons in Preventing Breaches

Italian Spyware Vendor Linked to Chrome Zero-Day Attacks

Europol Warns of Rising Threat From Caller ID Spoofing Attacks

‘There Isn’t Really Another Choice:’ Signal Chief Explains Why the Encrypted Messenger Relies on AWS

X: Re-Enroll 2FA Security Keys by November 10 or Get Locked Out

You Have One Week to Opt Out or Become Fodder for LinkedIn AI Training

Shaquille O’Neal’s Custom Range Rover Stolen During Transport in Suspected Hack
Hundreds of People With ‘Top Secret’ Clearance Exposed by House Democrats’ Website

Google Disputes False Claims of Massive Gmail Data Breach

Sweden’s Power Grid Operator Confirms Data Breach Claimed by Everest Ransomware Gang

Qilin Ransomware Group Publishes Over 40 Cases Monthly

Ransomware Profits Drop as Victims Stop Paying Hackers

QNAP Warns of Critical ASP.NET Flaw in its Windows Backup Software

CISA Releases Warning About Windows Server Update Service Bug, Orders Agencies to Patch

Google Says Everyone Will Be Able to Vibe Code Video Games

10/24-26/2025

Blitz Spear Phishing Campaign Targets NGOs Supporting Ukraine

UN Cybercrime Treaty to Be Signed in Hanoi to Tackle Global Offences

Fake LastPass Death Claims Used to Breach Password Vaults

MPs Urge Government to Stop Britain’s Phone Theft Wave Through Tech

How Hacked Card Shufflers Allegedly Enabled a Mob-Fueled Poker Scam That Rocked the NBA

Hackers Earn $1,024,750 for 73 Zero-Days at Pwn2Own Ireland
Everest Ransomware Says It Stole 1.5m Dublin Airport Passenger Records

New LockBit Ransomware Victims Identified by Security Researchers

Hackers Steal Discord Accounts With RedTiger-Based Infostealer

Hackers Launch Mass Attacks Exploiting Outdated WordPress Plugins

Windows Server Emergency Patches Fix WSUS Bug with PoC Exploit

Critical WSUS Flaw in Windows Server Now Exploited in Attacks

10/23/2025

Lazarus Group’s Operation DreamJob Targets European Defense Firms

Pakistani-Linked Hacker Group Targets Indian Government with DeskRAT

Hackers Posing as Kyrgyz Officials Target Russian Agencies in Cyber Espionage Campaign

Europe’s Offshore Wind Sector Faces Dilemma Over China’s Grip on Sector

UK Cyber Law Delays ‘Deeply Concerning,’ Say MPs

The ‘Universal Browser’ Privacy Browser Has Dangerous Hidden Features

23andMe’s Data-Theft Victims Offered ‘Genetic Monitoring’ to Ward Off Hackers

Former Polish Official Indicted Over Spyware Purchase
Playtime’s Over: Crooks Swipe Toys R Us Canada Customer Data and Dump It Online

“Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards

Spoofed AI Sidebars Can Trick Atlas, Comet Users Into Dangerous Actions

Tired of Unpaid Toll Texts? Blame the ‘Smishing Triad’

CISA Warns of Lanscope Endpoint Manager Flaw Exploited in Attacks

Microsoft Disables File Explorer Preview for Downloads to Block Attacks

Google Nukes 3,000 YouTube Videos That Sowed Malware Disguised as Cracked Software

Trump Pardons Former Binance CEO After Guilty Plea in Letting Cybercrime Proceeds Flow Through Platform

10/22/2025

PhantomCaptcha Campaign Targets Ukraine Relief Organizations

MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign

The Long Tail of the AWS Outage

Scattered Lapsus$ Hunters Signal Shift in Tactics

UN Cybercrime Pact to Be Signed in Hanoi Raises Hopes, Concerns

Krebs: Canada Fines Cybercrime Friendly Cryptomus $176M

JLR Hack UK’s Costliest Ever, Hitting Economy with £1.9bn Loss

No, ICE (Probably) Didn’t Buy Guided Missile Warheads

SpaceX Disables More Than 2,000 Starlink Devices Used in Myanmar Scam Compounds

It Takes Only 250 Documents to Poison Any AI Model
Cyber Incidents in Texas, Tennessee and Indiana Impacting Critical Government Services

Ransomware Gang Steals Meeting Videos, Financial Secrets From Fence Wholesaler

Summit Golf Brands Allegedly Subjected to Massive INC Ransom Breach

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys

TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution

Hackers Exploiting Critical “SessionReaper” Flaw in Adobe Magento

Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft’s July Patch

Pwn2Own Day 2: Hackers Exploit 56 Zero-Days for $790,000

10/21/2025

Russian Coldriver Hackers Deploy New ‘NoRobot’, ‘YesRobot’, and ‘MaybeRobot’ Malware

‘PassiveNeuron’ Cyber Spies Target Orgs With Custom Malware

Lumma Stealer Developers Doxxed in Underground Rival Cybercrime Campaign

Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams

How Malware Vaccines Could Stop Ransomware’s Rampage

Medical Specialist Group Fined £100K After Hack Exposed Patient Data

Cloud Data Firm Veeam to Buy Securiti AI for $1.73 Billion

Russia Pressures Apple to Make Russian Search Engines Default on Locally-Sold iPhones
Amazon Says AWS Cloud Service Back to Normal After Outage Disrupts Businesses Worldwide

Singapore Officials Impersonated in Sophisticated Investment Scam

Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network

Vidar Stealer 2.0 Adds Multi-Threaded Data Theft, Better Evasion

PolarEdge Targets Cisco, ASUS, QNAP, Synology Routers in Expanding Botnet Campaign

Cursor, Windsurf IDEs Riddled with 94+ N-Day Chromium Vulnerabilities

TP-Link Warns of Critical Command Injection Flaw in Omada Gateways

Hackers Exploit 34 Zero-Days on the First Day of Pwn2Own Ireland 2025

10/20/2025

Amazon’s AWS Struggles to Recover After Major Outage Disrupts Apps, Services Worldwide

What the Huge AWS Outage Reveals About the Internet

Salt Typhoon Uses Citrix Flaw in Global Cyber-Attack

Flawed Vendor Guidance Exposes Enterprises to Avoidable Risk

Cyberattacks Cripple Small Businesses, Even When They Aren’t Hacked

DNS0.EU Private DNS Service Shuts Down Over Sustainability Issues

Evilginx’s Creator Reckons With the Dark Side of Red-Team Tools

Judge Bars NSO From Targeting WhatsApp Users With Spyware, Reduces Damages in Landmark Case

What to Know About the Shocking Louvre Jewelry Heist

The Fraudster Behind Steve Ballmer’s NBA Nightmare
Retail Giant Muji Halts Online Sales After Ransomware Attack on Supplier

Home Security Firm Verisure Reports Data Breach at Swedish Subsidiary

Japanese Retailer Askul Halts Online Orders, Shipments After Ransomware Attack

131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign

Self-Spreading GlassWorm Malware Hits OpenVSX, VS Code Registries

Cyber Defenders From All Around Sound the Alarm as F5 Hack Exposes Broad Risks

CISA: High-Severity Windows SMB Flaw Now Exploited in Attacks

Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets

Microsoft Warns of Windows Smart Card Auth Issues After October Updates

10/17-19/2025

Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials

North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware

Teen Tied to Russian Hackers in Dutch Cyber Espionage Probe

Over 266,000 F5 BIG-IP Instances Exposed to Remote Attacks

China Accuses U.S. of Cyberattack on National Time Center

Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide

Experian Fined $3.2 Million for Mass-Collecting Personal Data

Labor Unions Sue Trump Administration Over Social Media Surveillance
American Airlines Subsidiary Envoy Air Confirms Oracle Data Theft Attack

AI Girlfriend Apps Leak Millions of Private Chats

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

Krebs: Email Bombs Exploit Lax Authentication in Zendesk

Google Ads for Fake Homebrew, LogMeIn Sites Push Infostealers

TikTok Videos Continue to Push Infostealers, Including Aura Stealer, in ClickFix Attacks

Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices

ConnectWise Fixes Automate Bug Allowing AiTM Update Attacks

Microsoft Fixes Highest-Severity ASP.NET Core Flaw Ever

10/16/2025

Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

Breach at U.S.-Based Cybersecurity Provider F5 Blamed on China, Say Sources

Cybersecurity Firm F5′S Stock Sinks 10%

‘Categorically Untrue’ That China Hacked UK Intelligence Systems, Say Officials

Hacked Airport P.A. Systems Broadcast Anti-Trump and Pro-Hamas Messages

North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts

Microsoft Disrupts Ransomware Attacks Targeting Teams Users

Microsoft Debuts Copilot Actions for Agentic AI-Driven Windows Tasks

Ring to Partner With Flock, Giving Law Enforcement Easier Access to Home Security Camera Footage

Cambodia to Repatriate South Koreans Ensnared by Scam Industry Amid Diplomatic Pressure

Ex-Trump National Security Adviser Bolton Charged With Storing and Sharing Classified Information

Vulnerability Scores, Huh, What Are They Good For? Almost Nothing
Nintendo Denies Data Leak After Online Reports

Auction Giant Sotheby’s Says Data Breach Exposed Customer Information

Have I Been Pwned: Prosper Data Breach Impacts 17.6 Million Accounts

List of Major Companies Hit by Massive Salesforce Data Breach Continues to Grow

Dairy Farmers of America Confirms June Cyberattack Leaked Personal Data

Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites

Microsoft Warns of a 32% Surge in Identity Hacks, Mainly Driven by Stolen Passwords

LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets

New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence

Gladinet Fixes Actively Exploited Zero-Day CVE-2025-11371 in File-Sharing Software

CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack

10/15/2025

U.S. Warns That Hackers Using F5 Devices to Target Government Networks

Emergency Order

F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion

Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months

When Face Recognition Doesn’t Know Your Face Is a Face

Google Will Let Friends Help You Recover an Account

Outsourcing Firm Capita Fined £14M After Millions Had Data Stolen

New York Secures $14 Million in Fines From 8 Car Insurance Companies After Data Breaches

UK, U.S. Sanction Southeast Asia-Based Online Scam Network

PowerSchool Hacker Gets Sentenced to Four Years in Prison

Scouts Can Now Earn AI and Cybersecurity Badges

Cisco Must Share More Information About Effects of Severe Bugs on Businesses, Senator Cassidy Says
Salesforce-Linked Security Breach Fallout Escalates With Qantas Leak

Clothing Giant MANGO Discloses Data Breach Exposing Customer Info

Texas Electric Cooperatives Purportedly Breached by Qilin

Whisper 2FA Behind One Million Phishing Attempts Since July

Fake LastPass, Bitwarden Breach Alerts Lead to PC Hijacks

Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access

Flaw in Slider Revolution Plugin Exposed 4m WordPress Sites

New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login

RMPocalypse: Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing

Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control

Krebs: Patch Tuesday, October 2025 ‘End of 10’ Edition

Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped

10/14/2025

Chinese Hackers Use Trusted ArcGIS App For Year-Long Persistence

Taiwan Flags Rise in Chinese Cyberattacks, Warns of ‘Online Troll Army’

Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data

Salesforce Deepens AI Ties With OpenAI, Anthropic to Power Agentforce Platform

Senior Execs Falling Short on Cyber-Attack Preparedness, NCSC Warns

Cyber Attack Contingency Plans Should Be Put On Paper, Firms Told

NCSC Reports 130% Spike in “Nationally Significant” Cyber Incidents

UK Firms Lose Average of £2.9m to AI Risk

Critical infrastructure CISOs Can’t Ignore ‘Back-Office Clutter’ Data

Feds Seize Record-Breaking $15 Billion in Bitcoin From Alleged Scam Empire

Florida Sues Roku for Illegally Selling Children’s Data, Including Precise Geolocation

Security Firms Dispute Credit for Overlapping CVE Reports
Discord Blamed a Vendor for Its Data Breach — Now the Vendor Says It Was ‘Not Hacked’

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels

Personal Data Potentially Stolen in Asahi Cyber-Attack

Harvard Says ‘Limited Number of Parties’ Impacted by Breach Linked to Oracle Zero-Day

Michigan City (IN) Confirms Ransomware Hackers Behind September Incident

Hacker Group TA585 Emerges With Advanced Attack Infrastructure

Malicious Crypto-Stealing VSCode Extensions Resurface on OpenVSX

New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions

Secure Boot Bypass Risk Threatens Nearly 200,000 Linux Framework Laptops

Legacy Windows Protocols Still Expose Networks to Credential Theft

Microsoft October 2025 Patch Tuesday Fixes 6 Zero-Days, 172 Flaws

Oracles Silently Fixes Zero-Day Exploit Leaked by ShinyHunters

10/13/2025

Ukraine Takes Steps to Launch Dedicated Cyber Force for Offensive Strikes

China Probes Qualcomm’s Autotalks Deal Amid Rising U.S. Trade Tensions

Dutch Government Puts Nexperia on a Short Leash Over Chip Security Fears

UK Ofcom Fines 4chan £20K and Counting for Pretending UK’s Online Safety Act Doesn’t Exist

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor

Apple Bug Bounty Payouts Can Now Top $5m

Fired California Cybersecurity Chief Speaks Out on Sudden Termination, Security Concerns
Scattered Lapsus$ Hunters Rage-Quit the Internet (Again), Promise to Return Next Year

Harvard Investigating Breach Linked to Oracle Zero-Day Exploit

SimonMed Says 1.2 Million Patients Impacted in January Data Breach

Goosehead Insurance Confirms Data Breach Exposes SSNs Following Ransomware Attack

Wellborn & Company Data Breach Affecting Clients’ Personal Information

Hackers Target ScreenConnect Features For Network Intrusions

Massive Multi-Country Botnet Targets RDP Services in the U.S.

New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

SonicWall VPN Accounts Breached Using Stolen Creds in Widespread Attacks

10/10-12/2025

What Are the Latest Sticking Points in U.S.-China Tensions?

White House Lays off Thousands of U.S. Government Workers, Blaming Shutdown

Federal Cyber Cuts Raise National Security Alarms

Acting U.S. Cyber Command, NSA Chief Won’t Be Nominated for the Job, Sources Say

North Korean Scammers Are Doing Architectural Design Now

Krebs: DDoS Botnet Aisuru Blankets U.S. ISPs in Record DDoS

Spyware Maker NSO Group Confirms Acquisition by U.S. Investors

Led by Hollywood Producer

Cops Nuke BreachForums (Again) Amid Cybercrime Supergroup Extortion Blitz

Spain Dismantles “GXC Team” Cybercrime Syndicate, Arrests Leader

Prosecutors Seek 7-Year Prison Term for ‘Sophisticated’ PowerSchool Hacker

Finland’s Trial of Men Charged Over Baltic Sea Cable Damage Hits Choppy Waters

Microsoft Violated EU Law in Handling of Kids’ Data, Austrian Privacy Regulator Finds
UK Techies’ Union Prospect Warns Members After Breach Exposes Sensitive Personal Details

Australian Airline Qantas Airways Says Hackers Leaked Data on Its Customers

Private Data Exposed in Georgia Department of Human Services Email Breach

Kearney Public Schools (NE) Hit by a Cybersecurity Attack

Houston Suburb Sugar Land (TX) Says Some Online Services Taken Down by Cyberattack

Fake ‘Inflation Refund’ Texts Target New Yorkers in New Scam

175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign

Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers

From Detection to Patch: Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation

Hackers Exploiting Zero-Day in Gladinet File Sharing Software

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits

10/9/2025

China Honing Abilities for a Possible Future Attack, Taiwan Defence Report Warns

From HealthKick to GOVERSHELL: The Evolution of UTA0388’s Espionage Malware

Pro-Russian Hacktivist Group ‘Twonet’ Target Critical Infrastructure, Hit Decoy Plant

Claude’s New AI File-Creation Feature Ships With Security Risks Built In

Researchers Warn of Security Gaps in AI Browsers

It’s Trivially Easy to Poison LLMs Into Spitting Out Gibberish, Says Anthropic

GitHub Copilot ‘CamoLeak’ AI Attack Exfiltrates Data

Take Note: Cyber-Risks With AI Notetakers

High Number of Windows 10 Users Remain as End-of-Life Looms

Renewal of Cyber Information-Sharing Law Must Mind the Gap, Senator Says
Google Says ‘Likely Over 100’ Affected by Oracle-Linked Hacking Campaign

All SonicWall Cloud Backup Users Have Firewall Configuration Files Stolen

Hackers Claim Discord Breach Exposed Data of 5.5 Million Users

Rhode Island Lottery Tech Supplier Brightstar Lottery Group Breach Impacted Thousands

Qilin Ransomware Gang Claims San Francisco’s Cal Club, Exposing Members of Exclusive Golf Club

ClayRat Spyware Campaign Targets Android Users in Russia

Microsoft: Storm-2657 Hackers Target Universities in “Payroll Pirate” Attacks

Hackers Now Use Velociraptor DFIR Tool in Ransomware Attacks

Chaos Ransomware Upgrades With Aggressive New C++ Variant

RondoDox Botnet Targets 56 N-Day Flaws in Worldwide Attacks

10/8/2025

OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks

Russian Hackers Turn to AI as Old Tactics Fail, Ukrainian CERT Says

Russia Is at ‘Hybrid War’ With Europe, Warns EU Chief, Calling for Members ‘To Take It Very Seriously’

Nezha Tool Used by Chinese Hackers in New Cyber Campaign Targeting Web Applications

Bybit Theft Drives Record-Breaking $2bn Haul for North Korea

U.S. Government Shutdown: Who Is Still Working and Who Has Been Furloughed?

Digital Fraud Costs Companies Worldwide 7.7% of Annual Revenue

Salesforce Says It Won’t Pay Extortion Demand in 1 Billion Records Breach

Krebs: ShinyHunters Wage Broad Corporate Extortion Spree

Cybersecurity Gets C-Suite Attention as Companies Dive Into AI

1Password Says It Can Fix Login Security for AI Browser Agents

Germany Slams Brakes on EU’s Chat Control Device-Scanning Snoopfest
Discord Says 70,000 Users May Have Had Their Government IDs Leaked in Breach

Major U.S. Law Firm Williams & Connolly Says Hackers Broke Into Attorneys’ Emails Accounts

LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem

Crimson Collective Hackers Target AWS Cloud Instances for Data Theft

New FileFix Attack Uses Cache Smuggling to Evade Security Software

Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks

Hackers Exploit Auth Bypass in Service Finder WordPress Theme

Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now

Docker Makes Hardened Images Catalog Affordable for Small Businesses

California Enacts Law Giving Consumers Ability to Universally Opt Out of Data Sharing

Time’s Running Out to Claim Your Part of the $177 Million AT&T Data Breach Settlement

10/7/2025

Russia Blocks Mobile Internet for Foreign SIM Cards, Citing Drone Threats

OpenAI Bans Suspected Chinese Accounts Using ChatGPT to Plan Surveillance

Employees Regularly Paste Company Secrets into ChatGPT

Despite AI-Related Job Loss Fears, Tech Hiring Holds Steady – And Here Are the Most In-Demand Skills

Google Won’t Fix New ASCII Smuggling Attack in Gemini

Google’s New AI Bug Bounty Program Pays up to $30,000 for Flaws

Man and Teenage Boy Arrested Over Cyber-Attack on London Nurseries
Cyberattacks Upset British Life, Disrupting Car Factories and Grocery Stores

‘Qilin’ Cybercrime Gang Claims Hack on Japan’s Asahi Group

Qilin Claims Ransomware Attack on Mecklenburg Schools (VA)

Electronics Giant Avnet Confirms Breach, Says Stolen Data Unreadable

DraftKings Warns of Account Breaches in Credential Stuffing Attacks

BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers

California Sets 30 Day Deadline for Data Breach Notifications

10/6/2025

Suspected Chinese Cyber Spies Targeted Serbian Aviation Agency

New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations

One iPhone Led Police to Gang Suspected of Sending up to 40,000 Stolen UK Phones to China

Vibe Coding Is the New Open Source—In the Worst Way Possible

Google Confirms Android Dev Verification Will Have Free and Paid Tiers, No Public List of Devs

OpenAI, AMD Announce Massive Computing Deal, Marking New Phase of AI Boom

A Biological 0-Day? Threat-Screening Tools May Miss AI-Designed Proteins.

The True Cost of Cyber Attacks – And the Business Weak Spots That Allow Them to Happen

SAIC to Acquire Silveredge Government Solutions for $205 Million

Europol Calls for Stronger Data Laws to Combat Cybercrime

Signal Calls on Germany to Vote Against ‘Chat Control,’ Saying It Would Leave EU Market
Scattered Lapsus$ Hunters Offering $10 in Bitcoin to ‘Endlessly Harass’ Execs

Red Hat Data Breach Escalates as ShinyHunters Joins Extortion

Ransomware Group “Trinity of Chaos” Launches Data Leak Site

Doctors Imaging Group (FL) Suffers Data Breach – 171,800+ Users Data Exposed

XWorm Malware Resurfaces With Ransomware Module, Over 35 Plugins

New Malware Sorvepotel Leverages WhatsApp to Target Brazilian Government and Businesses

Redis Warns of Critical Flaw Impacting Thousands of Instances

Microsoft: Critical GoAnywhere Bug Exploited by Storm-1175 in Medusa Ransomware Attacks

Steam and Microsoft Warn of Unity Flaw Exposing Gamers to Attacks

Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks

Zeroday Cloud Hacking Contest Offers $4.5 Million in Bounties

Phishing Is Moving From Email to Mobile. Is Your Security?

10/3-5/2025

ShinyHunters Launches Salesforce Data Leak Site to Extort 39 Victims

Salesforce Providing Support to Customers Listed on Scattered Spider Extortion Site

Apple Drops ICE-Tracking Apps From App Store

Google Too

ICE Wants to Build Out a 24/7 Social Media Surveillance Team

Congress Let Cyber-Intel Sharing Act Lapse. Does it Matter?

National Security, Legal Readiness, and U.S. Engagement for International Dual-Use Technology Companies

UK Government Says Digital ID Won’t Be Compulsory – Honest

Consumers More Likely to Pay for ‘Responsible’ AI Tools, Deloitte Survey Says

ChatGPT Social Could Be a Thing, as Leak Shows Direct Messages Support

OpenAI Wants ChatGPT to be Your Emotional Support

Signal Adds New Cryptographic Defense Against Quantum Attacks

Munich Airport Chaos After Drone Sightings Spook Air Traffic Control

ParkMobile Pays… $1 Each for 2021 Data Breach That Hit 22 Million

LinkedIn Sues Software Company Allegedly Scraping Data From Millions of Profiles

California AG Sues City for Allowing Out-Of-State Searches of License Plate Reader Database
Oracle Links Clop Extortion Attacks to July 2025 Vulnerabilities

Discord Customer Service Data Breach Leaks User Info and Scanned Photo IDs

Renault and Dacia UK Warn of Data Breach Impacting Customers

Six Out of 10 UK Secondary Schools Hit by Cyber-Attack or Breach in Past Year

Japan Faces Asahi Beer Shortage After Cyber-Attack

New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT

Massive Surge in Scans Targeting Palo Alto Networks Login Portals

Chinese-Speaking Cybercrime Group Hijacks IIS Servers for SEO Fraud

Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer

Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads

Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL

CometJacking: One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief

Hackers Exploited Zimbra Flaw as Zero-Day Using iCalendar Files

CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild

License Plate Reader Company Flock Launches New Product That Detects Human Voices

10/2/2025

U.S. to Provide Ukraine With Intelligence for Missile Strikes Deep Inside Russia

Trump’s Drone Deal With Ukraine to Give U.S. Access to Battlefield Tech

U.S. Government Shutdown to Slash Federal Cybersecurity Staff

Shutdown Guts U.S. Cybersecurity Agency at Perilous Time

U.S. Stocks Rally on Shutdown’s Second Day

Google Says Self-Reported Cl0p Hackers Are Sending Extortion Emails to Corporate Executives

Gmail’s End-To-End Encryption for Organizations Now Works Across Email Providers

EU Funds Are Flowing Into Spyware Companies, and Politicians Are Demanding Answers

HackerOne Paid $81 Million in Bug Bounties Over the Past Year
Cybercrims Claim Raid on 28,000 Red Hat Repos, Say They Have Sensitive Customer Files

Subpoena Tracking Platform Blames Outage on AWS Social Engineering Attack

Concerns for Patient Data After Suspected Cyberattack on Shamir Medical Center

Confucius Shifts from Document Stealers to Python Backdoors

Warning: Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro

Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown

DrayTek Warns of Remote Code Execution Bug in Vigor Routers

Microsoft Outlook Stops Displaying Inline SVG Images Used in Attacks

Microsoft Defender Bug Triggers Erroneous BIOS Update Alerts

10/1/2025

Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs

Geopolitics Drives More Cyberattacks

China Imposes One-Hour Reporting Rule for Major Cyber Incidents

Expiration of Cyber Information-Sharing Act Leaves U.S. Very Vulnerable

F-Droid Project Threatened by Google’s New Dev Registration Rules

Schools and Colleges Are Swotting up on Security Yet Still Flunk Recovery When Cyberattacks Inevitably Strike

Seniors Targeted in Global Facebook Scam Spreading New Android Malware

AI Data Analytics Startup Dataiku Picked Multiple Banks for U.S. IPO, Sources Say
Allianz Life Says July Data Breach Impacts 1.5 Million People

Data Breach at Dealership Software Provider Motility Software Solutions Impacts 766K Clients

Adobe Analytics Bug Leaked Customer Tracking Data to Other Tenants

Hackers Exploit Milesight Routers to Send Phishing SMS to European Users

Shortcut-based Credential Lures Deliver DLL Implants

New WireTap Attack Extracts Intel SGX ECDSA Key via DDR4 Memory-Bus Interposer

‘Delightful’ Root-Access Bug in Red Hat OpenShift AI Allows Full Cluster Takeover

OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps

9/30/2025

Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware

North Korea IT Worker Scheme Expanding to More Industries, Countries Outside of U.S. Tech Sector

Tile’s Lack of Encryption Could Make Tracker Owners Vulnerable to Stalking

Microsoft’s New Security Store Is Like an App Store for Cybersecurity

Google Releases AI-Powered Ransomware Detection Features for Cloud Files

Google’s Latest AI Ransomware Defense Only Goes So Far

‘Trifecta’ of Google Gemini Flaws Turn AI Into Attack Vehicle

Why Burnout Is a Growing Problem in Cybersecurity

Israeli High-Tech Funding and M&A Gain in 2025 Despite Ongoing Gaza War

Trump Visa Curbs Push U.S. Firms to Consider Shifting More Work to India

Sendit Sued by the FTC for Illegal Collection of Children Data

CPPA Fines Tractor Supply Company $1.4 Million for Privacy Violations

UK Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust of ‘Bitcoin Queen’

Afghanistan Plunged Into Nationwide Internet Blackout, Disrupting Air Travel, Medical Care
Harbor Mental Health Services Organization (OH) Investigating Data Breach

Smishing Campaigns Exploit Cellular Routers to Target Belgium

New MatrixPDF Toolkit Turns PDFs into Phishing and Malware Lures

New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events

New Android RAT Klopatra Targets Financial Data

Critical WD My Cloud Bug Allows Remote Command Injection

$50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections

Nearly 50,000 Cisco Firewalls Vulnerable to Actively Exploited Flaws

CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems

CISA Orders Federal Gov to Patch Critical Fortra File Transfer Bug

Broadcom Fixes High-Severity VMware NSX Bugs Reported by NSA

Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024

Tech Companies Should Be Shielded From Spyware Lawsuits, Report Says

Cyber Information-Sharing Law and State Grants Set to Go Dark as Congress Stalls Over Funding

9/29/2025

Ukrainian Cops Spoofed in Fileless Phishing Attacks on Kyiv

Tile Tracking Tags Can Be Exploited by Tech-Savvy Stalkers, Researchers Say

How to Use a Password Manager to Share Your Logins After You Die

UK Gov’t Backs Jaguar Land Rover (JLR) With £1.5 Billion Loan Guarantee After Cyberattack

Chinese Scammer Pleads Guilty After UK Seizes Nearly $7 Billion in Bitcoin

Ukraine’s Digital Chief Pushes for AI-First State Amid War and Cyber Threats

European AI Company’s ‘Reputation Reports’ Are Inaccurate and Illegal, Watchdog Claims

Law Enforcement Is Using AI to Synthesize Evidence. Is the Justice System Ready for It?
‘You’ll Never Need to Work Again’: Criminals Offer Reporter Money to Hack BBC

Canada’s WestJet Says Some Passenger Data Exposed in Cybersecurity Breach

Asahi Runs Dry as Online Attackers Take Down Japanese Brewer

EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations

Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security

National Cyber Authorities Launch OT Security Guidance

DHS, CISA Kick Off Cybersecurity Awareness Month

CISA to Furlough 65% of Staff if Government Shuts Down This Week

9/26-28/2025

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks

Dutch Teens Arrested for Trying to Spy on Europol for Russia

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks

Netanyahu Broadcasts United Nations Message Into Gaza Accusing World Leaders of Appeasing ‘Evil’

Trump Signs ‘Saving TikTok’ Order to Start Resolving Its Big Ban Problem

Singapore Threatens Meta With Fines Over Facebook Impersonation Scams

Krebs: Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms

Interpol Cracks Down on Large-Scale African Scamming Networks

‘No Harm, No Foul:’ Courts Take Tougher Line on Data-Breach Suits

Salesforce Facing Multiple Lawsuits After Salesloft Breach

As Fraud Surges, UK Prepares to Replace Its Massively Broken Reporting Services

Datacenter Fire Takes 647 South Korean Government Services Offline

A New Front Opens Between Zuckerberg and Musk Over Robots
Harrods Says Customers’ Data Stolen in It Breach

Volvo North America Confirms Staff Data Stolen Following Ransomware Attack on It Supplier

Union County (OH) Suffers Ransomware Attack Impacting 45,000 People

Fake Microsoft Teams Installers Push Oyster Malware via Malvertising

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

New LockBit Ransomware Variant Emerges as Most Dangerous Yet

Akira Ransomware Breaching MFA-Protected SonicWall VPN Accounts

ArcaneDoor Threat Actor Resurfaces in Continued Attacks Against Cisco Firewalls

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

Microsoft Edge to Block Malicious Sideloaded Extensions

Microsoft’s New AI Feature Will Organize Your Photos Automatically

EU Probes SAP Over Anti-Competitive ERP Support Practice

9/25/2025

Microsoft Disables Some Cloud Services Used by Israel’s Defense Ministry

DOGE Might Be Storing Every American’s SSN on an Insecure Cloud Server

Phishing Campaign Evolves into PureRAT Deployment, Linked to Vietnamese Threat Actors

Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network

Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds

Teen Suspected of Vegas Casino Cyberattacks Released to Parents

Empty Shelves, Empty Coffers: Co-Op Pegs Cyber Hit at £80M

Google, Period-Tracking App to Pay Combined $56 Million to Settle Privacy Claims
Callous Crims Break Into Preschool Network, Publish Toddlers’ Data

Jaguar Land Rover Restarts Some IT Systems as Suppliers Call for Urgent Support

Malicious Postmark MCP Server AI Agent Server Reportedly Steals Emails

Experts Warn of Global Breach Risk from Indian Third Party Suppliers

Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

ForcedLeak: Critical Vulnerability in Salesforce AI-Powered AgentForce Exposed

Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

Amazon Pays $2.5 Billion to Settle Prime Memberships Lawsuit from FTC

9/24/2025

Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike

UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors

Collins Aerospace Working on Restoring Software for Airlines Hit by Cyberattack

UK Arrests Man in Airport Ransomware Attack That Caused Delays Across Europe

Krebs: Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms

Police Seizes $439 Million Stolen by Cybercrime Rings Worldwide

Phone Spyware Scandal in Greece Moves to Court as Critics Claim Cover-up

OpenAI is Testing a New GPT-5-Based AI agent “GPT-Alpha”

Kali Linux 2025.3 Released With 10 New Tools, WiFi Enhancements

Senators Introduce Bill Directing FTC to Establish Standards for Protecting Consumers’ Neural Data
Vegas Gambling Giant Boyd Gaming Corporation Hit by Cyber Incident, Employee Data Exposed

Rhysida Ransomware Gang Known for Government Attacks Claims Maryland Transit Incident

CISA Urges Orgs to Review Software After ‘Shai-Hulud’ Supply Chain Compromise

New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus

GitHub Notifications Abused to Impersonate Y Combinator for Crypto Theft

New String of Phishing Attacks Targets Python Developers

Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials

Unpatched Flaw in OnePlus Phones Lets Rogue Apps Text Messages

Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models

Cisco Warns of iOS Zero-Day Vulnerability Exploited in Attacks

9/23/2025

U.S. Secret Service Agents Dismantle Network That Could Shut Down New York Cellphone System

Found Near UN General Assembly

300 SIM Servers, 100K Cards

‘SIM Farms’ Are a Spam Plague

CISA Says Hackers Breached Federal Agency Using Geoserver Exploit

European Airports Still Dealing With Disruptions Days After Ransomware Attack

Drones and Cyber Outages Exposing Aviation Weak Spots Since 2017

Critical Security Flaws Grow With AI Use, New Report Shows

Attacker Breakout Time Falls to 18 Minutes

Deepfake Attacks Hit Two-Thirds of Businesses

DHS Has Been Collecting U.S. Citizens’ DNA for Years

WhatsApp Adds Message Translation to iPhone and Android Apps

GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security

15 Years of Zero Trust: Why It Matters More Than Ever

Cloudflare Mitigates New Record-Breaking 22.2 Tbps DDoS Attack
Jaguar Land Rover Extends Production Pause Again

Suspected Cyberattack Disrupts Circle K Chain’s Operations in Hong Kong

South Korea Probes Credit Card Company Lotte Card Data Breach Affecting 3 Million Customers

Iranian Hacking Group Nimbus Manticore Expands European Targeting

ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks

BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells

ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service

NPM Package ‘fezbox’ Caught Using QR Code to Fetch Cookie-Stealing Malware

Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security

Libraesva ESG Issues Emergency Fix for Bug Exploited by State Hackers

SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw

SonicWall Releases SMA100 Firmware Update to Wipe Rootkit Malware

9/22/2025

EU Agency Confirms Ransomware Attack Behind Airport Disruptions

Airport Chaos Highlights Rise in High-Profile Ransomware Attacks, Cyber Experts Say

New Plan Would Give Congress Another 18 Months to Revisit Section 702 Surveillance Powers

Deal to Keep TikTok in U.S. Is Near. These Are the Details.

Russia Steps up Disinformation Efforts to Sway Moldova’s Parliamentary Vote

$100M Cyberattack on Vegas Strip Involved Teen Hacker, Police Say

Organizations Must Update Defenses to Scattered Spider Tactics, Experts Urge

Major Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test
Car Giant Stellantis Says Customer Data Nicked After Partner Vendor Pwned

American Archive of Public Broadcasting Fixes Bug Exposing Restricted Media

Verified Steam Game Steals Streamer’s Cancer Treatment Donations

Lorain County (OH) Data Breach May Have Exposed Employee and Vendor Social Security, Bank Information

ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks

New EDR-Freeze Tool Uses Windows WER to Suspend Security Software

As Scientists Show They Can Read Inner Speech, Brain Implant ‘Pioneers’ Fight for Neural Data Privacy, Access Rights

9/19-21/2025

Russian State Hackers Gamaredon and Turla Collaborate in Attacks Against Ukraine

DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams

UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware

White House Outlines TikTok Deal That Would Give U.S. Control of Algorithm

China’s ByteDance Will Get 1 of 7 Board Seats for TikTok’s U.S. Operations, Official Says

Lachlan Murdoch, Michael Dell, Ellison Involved in TikTok Deal, Trump Says

Failed Stopgap Funding Bill Puts Key Federal Cybersecurity Legislation in Jeopardy

DOJ: Scattered Spider Took $115 Million in Ransoms, Breached a U.S. Court System

Canada Dismantles TradeOgre Exchange, Seizes $40 Million in Crypto

MI6 Launches Darkweb Portal to Recruit Foreign Spies

Watchdog Finds MrBeast Improperly Collected Children’s Data
Airport Cyberattack Disrupts More and More Flights Across Europe

What We Know About the Cyberattack That Hit Major European Airports

Russia’s Main Airport in St. Petersburg Says Its Website Was Hacked

Attackers Abuse AI Tools to Generate Fake CAPTCHAs in Phishing Attacks

17,500 Lighthouse and Lucid Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge

LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer

Ivanti EPMM Holes Let Miscreants Plant Shady Listeners, CISA Says

Fortra Releases Critical Patch for CVSS 10.0 GoAnywhere MFT Vulnerability

Transforming Cyber Frameworks to Take Control of Cyber-Risk

FBI Warns of Cybercriminals Using Fake FBI Online Crime Reporting Portals

ChatGPT Search is Now Smarter as OpenAI Takes on Google Search

9/18/2025

Senate Confirms Sutton as Pentagon Cyber Policy Chief

This Microsoft Entra ID Vulnerability Could Have Been Catastrophic

Cybercriminals Have a Weird New Way to Target You With Scam Texts

NCA Singles Out “The Com” as it Chairs Five Eyes Group

‘Scattered Spider’ Teens Charged Over London Transportation Hack

Cybersecurity Firm Netskope Notches $8.8 Billion Valuation as Shares Jump in Nasdaq Debut

CrowdStrike Pops Nearly 13% on Upbeat Long-Term Guidance at Investor Day

Brazil Enacts Sweeping Bill Requiring Online Age Verification, Safeguards for Children’s Data

Taliban Bans Fiber-Optic Internet in Several Afghan Provinces to Curb ‘Immorality’
Russian Regional Airline KrasAvia Disrupted by Suspected Cyberattack

Cloudflare DDoSed Itself with React useEffect Hook Blunder

CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader

SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers

SystemBC Malware Turns Infected VPS Systems Into Proxy Highway

PyPi Invalidates Tokens Stolen in Ghostaction Supply Chain Attack

WatchGuard Warns of Critical Vulnerability in Firebox Firewalls

Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions

OpenAI Fixes Zero-Click Shadowleak Vulnerability Affecting ChatGPT Deep Research Agent

9/17/2025

House Lawmakers Move to Extend Two Key Cyber Programs, for Now

Italy Enacts AI Law Covering Privacy, Oversight and Child Access

Israel’s Glilot Capital Raises $500 Million for New AI and Cybersecurity Investments

Five Point-Backed WaterBridge Raises $634 Million in U.S. IPO

Axiom Space Aims for Orbit With Its Orbital Data Center Node

TaskUs Employees Behind Coinbase Breach, U.S. Court Filing Alleges

Judge Rejects Meta Attempt to Overturn Flo Privacy Verdict

Labour Politician Charged Over ‘Honey Trap’ WhatsApp Messages Sent to MPs
Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts

Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims

ShinyHunters Claims 1.5 Billion Salesforce Records Stolen in Drift Hacks

VC Firm Insight Partners Says Thousands of Staff and Limited Partners Had Personal Data Stolen in a Ransomware Attack

TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks

Shai-Hulud Worm Prowls npm to Steal Hundreds of Secrets

SonicWall Warns Customers to Reset Credentials After Breach

9/16/2025

A DHS Data Hub Exposed Sensitive Intel to Thousands of Unauthorized Users

Krebs: Self-Replicating Worm Hits 180+ Software Packages

Microsoft Seizes 340 Websites Linked to Growing Phishing Subscription Service

We Set Out to Craft the Perfect Phishing Scam. Major AI Chatbots Were Happy to Help.

OpenAI to Predict Ages in Bid to Stop ChatGPT From Discussing Self Harm With Kids

Want to Foil an AI Deepfake? Tell It to Draw a Smiley Face

How to Set Up and Use a Burner Phone

CrowdStrike to Buy AI Security Company Pangea

Israeli Cybersecurity Startup Vega Raises $65 Million, Valued at $400 Million

Cybersecurity Provider Netskope Boosts IPO Range as It Tests Tech Hot Streak
Jaguar Land Rover (JLR) Stuck in Neutral as Losses Skyrocket Amid Cyberattack Cleanup

Fifteen Ransomware Gangs, including Scattered Spider, ShinyHunters and Lapsus$, “Retire,” Future Unclear

New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site

UK: Tax Refund-Themed Phishing Slows in 2025

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids

Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover

Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack

BreachForums Hacking Forum Admin Resentenced to Three Years in Prison

TikTok’s Journey From Global Sensation to Trump Target

9/15/2025

Ukraine Claims Cyberattacks on Russian Election Systems; Moscow Confirms Disruptions

New Zealand Sanctions Russian Military Hackers Over Cyberattacks on Ukraine

Russia Tests Hypersonic Missile at NATO’s Doorstep—And Shares the Video

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

AI-Forged Military IDs Used in North Korean Phishing Attack

Google Confirms Hackers Gained Access to Law Enforcement Portal

France Threatens to Block Crypto Licence ‘Passporting’ in EU Regulatory Fight

U.S. National Charged in Finnish Psychotherapy Center Extortion

Europol Adds Spanish Academic Suspected of Aiding Pro-Russian Hackers to Most Wanted List
Gucci, Balenciaga and Alexander McQueen Private Data Ransomed by Hackers

Union County (NC) Town Government Hacked in Recent Cyber Attack

FinWise Insider Breach Impacts 689K American First Finance Customers

SEO Poisoning Targets Chinese Users with Fake Software Sites

Phishing Campaigns Drop RMM Tools for Remote Access

New Phoenix Attack Bypasses Rowhammer Defenses in DDR5 Memory

AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns

Microsoft: Exchange 2016 and 2019 Reach End of Support in 30 Days

Building Highly Resilient IT Infrastructure Throughout the Enterprise From the Start

9/12-14/2025

France Warns Apple Users of New Spyware Campaign

Philippine Military Company Spied Upon With New China-Linked Malware

Charlie Kirk Shooting Suspect Tyler Robinson Had ‘Leftist Ideology’ but Motive Unclear, Utah Gov. Says

‘Not Co-Operating’

Alleged Transgender Partner Is Cooperating and Not Believed to be Involved

Inside Our Investigation of Jeffrey Epstein’s Personal Yahoo Account

Data Destruction Done Wrong Could Cost Your Company Millions

Companies Are Competing for Employees With AI Skills. So Are Hackers.

Man Gets Over 4 Years in Prison for Selling Unreleased Movies

Hacker Convicted of Extorting 20,000 Psychotherapy Victims Walks Free During Appeal

DHS IG: CISA Mismanaged Multimillion-Dollar Employee Incentives Program
Vietnam Investigates Cyberattack on Creditors Data

Ransomware Attack Cancels School for Several Days at  Uvalde Consolidated Independent School District (TX)

Attackers Adopting Novel LOTL Techniques to Evade Detection

New VoidProxy Phishing Service Targets Microsoft 365, Google Accounts

‘WhiteCobra’ Floods VSCode Market with Crypto-Stealing Extensions

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks

Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues Warning

New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit

Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks

CISA Official Calls on Lawmakers to Immediately Extend Cyber Info-Sharing Law

9/11/2025

Chinese APT Actor Compromises Military Firm with Novel Fileless Malware Toolset

How China’s Propaganda and Surveillance Systems Really Operate

Didi Global’s $740 Million IPO Settlement Likely Ready Next Month, Plaintiffs’ Lawyer Says

Krebs: Bulletproof Host Stark Industries Evades EU Sanctions

Four Years After Kaseya’s Nightmare Hack, a Cyber Turnaround Is Underway

Swiss Government Looks to Undercut Privacy Tech, Stoking Fears of Mass Surveillance

FTC Opens Inquiry Into How AI Chatbots Impact Child Safety, Privacy

Cyberattacks Against Schools Driven by a Rise in Student Hackers, ICO Warns

California Legislature Passes Bill Forcing Web Browsers to Let Consumers Automatically Opt Out of Data Sharing
France: Three Regional Healthcare Agencies Targeted by Cyber-Attacks

Panama Ministry of Economy Discloses Breach Claimed by INC Ransomware

DDoS Defender Targeted in 1.5 Bpps Denial-of-Service Attack

Fileless Malware Deploys Advanced RAT AsyncRAT via Legitimate Tools

Fake Madgicx Plus and SocialMetrics Extensions Are Hijacking Meta Business Accounts

New VMScape Attack Breaks Guest-Host Isolation on AMD, Intel CPUs

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers

CISA Launches Roadmap for the CVE Program

Apple Warns Customers Targeted in Recent Spyware Attacks

Microsoft Adds Malicious Link Warnings to Teams Private Chats

9/10/2025

China-Linked APT41 Hackers Target U.S. Trade Officials Amid 2025 Negotiations

Poland Downs Drones in Its Airspace, Becoming First NATO Member to Fire During War in Ukraine

U.S. Warns Hidden Radios May Be Embedded in Solar-Powered Highway Infrastructure

U.S. Investment in Spyware Is Skyrocketing

Apple Says the iPhone 17 Comes With a Massive Security Upgrade

U.S. Senator Wyden Pushes FTC to Investigate Microsoft for ‘Gross Cybersecurity Negligence’

Ransomware Payments Plummet in Education Amid Enhanced Resiliency

Chinese Companies and Bosses to Face Major Fines Over Cybersecurity Incidents

Nepal Lifts Social Media Ban After Deadly Youth Protests

Ukraine’s Ousted Cyber Chief Posts Bail in Corruption Case

Oracle, OpenAI Sign Massive $300 Billion Cloud Computing Deal
KillSec Ransomware Hits Brazilian Healthcare IT Vendor

Jaguar Land Rover Admits Hackers May Have Taken Data

Flu Jab Email Mishap Exposes Hundreds of Students’ Personal Data

Researchers Find Spyware on Phones Belonging to Kenyan Filmmakers

European Crypto Platform Swissborg to Reimburse Users After $41 Million Theft

Hackers Left Empty-Handed After Massive NPM Supply-Chain Attack

CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems

Cursor Autorun Flaw Lets Repositories Execute Code Without Consent

Krebs: Microsoft Patch Tuesday, September 2025 Edition

EoP Flaws Again Lead Microsoft Patch Tuesday

Microsoft Waives Fees for Windows Devs Publishing to Microsoft Store

Pixel 10 Fights AI Fakes With New Android Photo Verification Tech

9/9/2025

House Lawmakers to Make Official Visit to China for the First Time Since 2019

Massive Leak Shows How a Chinese Company Is Exporting the Great Firewall to the World

New Cybersecurity Rules Land for Defense Department Contractors

Defense Dept Didn’t Protect Social Media Accounts, Left Stream Keys Out in Public

Cyber Command, NSA to Remain Under Single Leader as Officials Shelve Plan to End ‘Dual Hat’

New Cyber Director Cairncross Calls on Industry to Help Put ‘America First’ in Cyberspace

Krebs: 18 Popular Code Packages Hacked, Rigged to Steal Crypto

Claude’s New AI File Creation Feature Ships With Deep Security Risks Built In

A New Platform Offers Privacy Tools to Millions of Public Servants

Former WhatsApp Security Boss in Lawsuit Likens Meta’s Culture to a “Cult”

Mitsubishi Electric to Buy Nozomi Networks in $1 Billion Deal

U.S. Charges Admin of LockerGoga, MegaCortex, Nefilim Ransomware

Kosovo Hacker Pleads Guilty to Running BlackDB Cybercrime Marketplace
Plex Tells Users to Reset Passwords After New Data Breach

New York Blood Center Says Thousands Had Data Leaked in January Ransomware Attack

No Gains, Just Pains as 1.6m HelloGym Fitness Phone Call Recordings Exposed Online

Brazil Lesbian Dating App Sapphos Shuts Down After Security Flaw Exposes Sensitive User Data

Salty2FA Phishing Kit Unveils New Level of Sophistication

Threat Actor Accidentally Exposes AI-Powered Operations

TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs

RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities

Adobe Patches Critical SessionReaper Flaw in Magento eCommerce Platform

SAP Fixes Maximum Severity NetWeaver Command Execution Flaw

Microsoft September 2025 Patch Tuesday Fixes 81 Flaws, Two Zero-Days

Windows 10 KB5065429 Update Includes 14 Changes and Fixes

Microsoft: Anti-Spam Bug Blocks Links in Exchange Online, Teams

9/8/2025

Salt Typhoon Used Dozens of Domains, Going Back Five Years. Did You Visit One?

Update: Noisy Bear Campaign Targeting Kazakhstan Energy Sector Outed as a Planned Phishing Test

Remote Access Abuse Biggest Pre-Ransomware Indicator

Silicon Valley’s Graying Workforce: Gen Z Staff Cut in Half at Tech Companies as the Average Age Goes up by 5 Years

SoFi Launches New AI-Themed ETF as Skepticism Grows

Cyberattack on Jaguar Land Rover Threatens to Hit British Economic Growth

The U.S. Government Has No Idea How Many Cybersecurity Pros It Employs

Sports Streaming Piracy Service With 123M Yearly Visits Shut Down

U.S. Sanctions Companies Behind Cyber Scam Centers in Cambodia, Myanmar

Nepal Social Media Ban Sparks Protests, Dozens Injured
Qualys, Tenable Latest Victims of Salesloft Drift Hack

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

GhostAction Supply Chain Attack Compromises 3000+ Secrets

Wealthsimple Confirms Data Breach After Supply Chain Attack

Lovesac Confirms Data Breach After Ransomware Attack Claims

VC Giant Insight Partners Notifies Staff and Limited Partners After Data Breach

MostereRAT Targets Windows Users With Stealth Tactics

Hackers Hijack npm Packages With 2 Billion Weekly Downloads in Supply Chain Attack

Surge in Networks Scans Targeting Cisco ASA Devices Raise Concerns

The Critical Failure in Vulnerability Management

Signal Adds Secure Cloud Backups to Save and Restore Chats

9/5-7/2025

Chinese Hackers Pretended to Be a Top U.S. Lawmaker During Trade Talks

U.S. Says It Is Restricting Visas of Some Central American Nationals Over China Ties

U.S. Is Increasingly Exposed to Chinese Election Threats, Lawmakers Say

Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

Ukraine’s Cyber Chief on Russian Hackers’ Shifting Tactics, U.S. Cyber Aid

Krebs: GOP Cries Censorship Over Spam Filters That Work

Qantas Penalizes Executives for July Cyberattack

Roblox to Verify Ages of All Gamers Who Use Chat and Text Features

Embracing the Next Generation of Cybersecurity Talent

Why Threat Hunting Should Be Part of Every Security Program

CISA Orders Federal Agencies to Patch Sitecore Zero-Day Following Hacking Reports
School District Five of Lexington & Richland Counties (SC) Data Breach Affects 31,000 People

Navy Federal Credit Union Data Breach Exposes Backup Files on Credit Union Serving Military Members

Data Breach at American Credit Union Exposes Financial Data

‘SEO Fraud-As-A-Service’ Scheme Hijacks Windows Servers to Promote Gambling Websites

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages

iCloud Calendar Abused to Send Phishing Emails from Apple’s Servers

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Security

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

SAP S/4HANA Critical Vulnerability CVE-2025-42957 Exploited in the Wild

9/4/2025

How North Korean Hackers Are Using Fake Job Offers to Steal Cryptocurrency

‘Unrestrained’ Chinese Cyberattackers May Have Stolen Data From Almost Every American

Czech Cyber Agency Warns Against Using Services and Products That Send Data to China

GhostRedirector Emerges as New China-Aligned Threat Actor

U.S. Says It Is Restricting Visas of Some Central American Nationals Over China Ties

U.S. and 14 Allies Release Joint Guidance on Software Bill of Materials

Britain Rules Out Backing for Global Defence Bank

Google Fined $379 Million by French Regulator for Cookie Consent Violations

Texas Sues PowerSchool Over Breach Exposing 62M Students, 880K Texans
Ukraine’s Cyber Chief on Russian Hackers’ Shifting Tactics, U.S. Cyber Aid

Blast Radius of Salesloft Drift Attacks Remains Uncertain

Chess.com Discloses Recent Data Breach via File Transfer App

Tire Giant Bridgestone Confirms Cyberattack Impacts Manufacturing

Delivery Giant OnTrac Data Breach Exposes 40,000 Personal Records

Attackers Snooping Around Sitecore, Dropping Malware via Public Sample Keys

CMS Provider Sitecore Patches Exploited Critical Zero Day

CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited

Microsoft Says Recent Windows Updates Cause App Install Issues

European Court Rejects Challenge to EU-U.S. Data Transfer Agreement

9/3/2025

Russian APT28 Expands Arsenal with ‘NotDoor’ Outlook Backdoor

U.S. Offers $10 Million Bounty for Info on Russian FSB Hackers

Venezuela’s President Thinks American Spies Can’t Hack Huawei Phones

Iranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Targeting Diplomats

Automated Sextortion Spyware Takes Webcam Pics of Victims Watching Porn

It Looks Like You’re Ransoming Data. Would You Like Some Help?

How Passkeys Work—And How to Use Them

Finland’s IQM Quantum Computers Raises $320 Million in New Funding Round

Israel’s Cato Networks Buys Aim Security, Raises Another $50 Million

More Personal Injury Lawyers Are Chasing Data-Breach Settlements

Police Disrupts Streameast, Largest Pirated Sports Streaming Network

U.S. Sues Robot Toy Maker Apitor Technology for Exposing Children’s Data to Chinese Devs
Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

SaaS Giant Workiva Discloses Data Breach After Salesforce Attack

M&S Hackers ‘Scattered Lapsus$ Hunters’ Claim to Be Behind Jaguar Land Rover Cyber Attack

Matrix.org Homeserver Grinds to a Halt After Raid Meltdown

Hackers Breach Fintech Firm Sinqia S.A. in Attempted $130M Bank Heist

Threat Actors Abuse X’s Grok AI to Spread Malicious Links

Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers

Major IPTV Piracy Network Uncovered Spanning 1100 Domains

Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure

Android Security Alert: Google Patches 120 Flaws, Including Two Zero-Days Under Attack

With Less Than a Month to Go, House Panel Votes to Extend Popular Cyber Programs

Corruption Case Against Ousted Cyber Chief Is ‘Revenge,’ Ukraine’s Security Service Says

9/2/2025

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

Moscow Reportedly Hires Hackers Who Breached City’s School System

Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices

ICE Reinstates Contract with Spyware Vendor Paragon

Who Watches the Watchmen? Surveillanceware Firms Make Bank, Avoid Oversight

Disney Agrees to $10 Million Settlement for Collecting Data From Children

That Supposed ‘Gmail Hack’: Google Says It’s False, but Watch Out for Phishing Anyway

FBI, Cybersecurity Experts Warn of 3-Phase Scam That Is Draining Bank Accounts

AI Chatbot Users Beware – Hackers Are Now Hiding Malware in the Images Served up by LLMs
Krebs: The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft

Stolen OAuth Tokens Expose Palo Alto Customer Data

Cloudflare Hit by Data Breach in Salesloft Drift Supply Chain Attack

Cloudflare Blocks Largest Recorded DDoS Attack Peaking at 11.5 Tbps

Britain’s Jaguar Land Rover Hit by Cyber Incident That Disrupts Production, Sales

Pennsylvania AG Says Recovery Continues After Office Refused to Pay Ransomware Gang

Azure AD Credentials Exposed in Public App Settings File

Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets

Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control

Hackers Are Sophisticated & Impatient — That Can Be Good

9/1/2025

Silver Fox APT Exploits Signed Drivers to Deploy ValleyRAT Backdoor

China Is About to Show Off Its New High-Tech Weapons to the World

North Korea’s Kim Inspects New Missile Production Line, KCNA Says

Google: Gmail’s Protections Are Strong and Effective, and Claims of a Major Gmail Security Warning Are False

Spanish Government Cancels €10M Contract Using Huawei Equipment

LegalPwn: Tricking LLMs by Burying Badness in Lawyerly Fine Print
Zscaler Data Breach Exposes Customer Info After Salesloft Drift Compromise

Ransomware Attack on Pennsylvania’s AG Office Disrupts Court Cases

Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans

High-Risk SQLi Flaw Exposes WordPress Memberships Plugin Users

DDoS Is the Neglected Cybercrime That’s Getting Bigger. Let’s Kill It Off

Proof-of-Concept in 15 Minutes? AI Turbocharges Exploitation

8/29-31/2025

Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign

North Korean APT37 Hackers Weaponize Seoul Intelligence Files to Target South Koreans

Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication

State-Sponsored Hackers Behind Majority of Vulnerability Exploits

Akira, Cl0p Top List of 5 Most Active Ransomware-as-a-Service Groups

Ransomware Gang Takedowns Causing Explosion of New, Smaller Groups

SSA Whistleblower’s Resignation Email Mysteriously Disappeared From Inboxes

A Troubled Man, His Chatbot and a Murder-Suicide in Old Greenwich

OpenAI is Testing “Thinking Effort” for ChatGPT

There’s Something Bizarre About When GPT-5 Writes in a Literary Style
Scammer Steals $1.5 Million From Baltimore by Spoofing City Vendor

TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies

Brokewell Android Malware Delivered Through Fake TradingView Ads

Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling

Npm Package Hijacked to Steal Data and Crypto via AI-Powered Malware

FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available

WhatsApp Patches Zero-Click Exploit Targeting iOS and macOS Devices

Researcher Who Found McDonald’s Free-Food Hack Turns Her Attention to Chinese Restaurant Robots

Microsoft to Enforce MFA for Azure Resource Management in October

Noem Fires Two Dozen FEMA Employees Over Alleged Cybersecurity Gaps

8/28/2025

Netherlands Confirms China’s Salt Typhoon Targeted Small Dutch Telcos

Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide

FBI Cyber Cop: Salt Typhoon Pwned ‘Nearly Every American’

Germany Charges Man Over Cyberattack on Rosneft Subsidiary

Lawmakers Press UnitedHealth on Hack Loan Repayments

Police Seize VerifTools Fake ID Marketplace Servers, Domains

Crypto Companies Freeze $47m in Romance Baiting Funds

Krebs: Affiliates Flock to ‘Soulless’ Scam Gambling Machine

Malware Devs Abuse Anthropic’s Claude AI to Build Ransomware

SentinelOne Raises Annual Revenue Forecast on Strong Cybersecurity Demand
TransUnion Suffers Data Breach Impacting Over 4.4 Million People

MATLAB Dev Says Ransomware Gang Stole Data of 10,000 People

Cyber-Attack on UK Contractor Affects Islanders

CISA Steps in to Help Nevada State Government Recover From Cyberattack

Google Warns Salesloft Breach Impacted Some Workspace Accounts

Fake IT Support Attacks Hit Microsoft Teams

Microsoft Warns of Ransomware Gang Shifting to Steal Cloud Data, Lock Companies Out of Systems

Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials

Malicious VS Code Extensions Exploit Name Reuse Loophole

Passwordstate Dev Urges Users to Patch Auth Bypass Vulnerability