1/22/2026

From a Whisper to a Scream: Europe Frets About Overreliance on U.S. Tech

Risky Chinese Electric Buses Spark Aussie Gov’t Review

Spanish Judge Closes NSO Group Spyware Probe Due to Lack of Cooperation From Israel

Claude’s New AI File-Creation Feature Ships With Security Risks Built In

Crims Compromised Energy Firms’ Microsoft Accounts, Sent 600 Phishing Emails

Microsoft Teams to Add Brand Impersonation Warnings to Calls

1Password Is Introducing a New Phishing Prevention Feature

House of Lords Backs Legislation to Ban Social Media for Children Under 16

Bank of England: Financial Sector Failing to Implement Basic Cybersecurity Controls

Over 160,000 Companies Notify Regulators of GDPR Breaches

Europe’s GDPR Cops Dished Out €1.2B in Fines Last Year as Data Breaches Piled Up

INC Ransomware Opsec Fail Allowed Data Recovery for 12 U.S. Orgs
Hackers Breach Fortinet FortiGate Devices, Steal Firewall Configs

Fortinet Firewalls Hit With Malicious Configuration Changes

Jordan Used Cellebrite Phone-Hacking Tools Against Activists Critical of Gaza War, Report Finds

Okta SSO Accounts Targeted in Vishing-Based Data Theft Attacks

New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access

Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts

SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release

RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites

Critical Appsmith Flaw Enables Account Takeovers

Hackers Exploit 29 Zero-Days on Second Day of Pwn2Own Automotive

Curl Ending Bug Bounty Program After Flood of AI Slop Reports

1/21/2026

North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

Phishing and Spoofed Sites Remain Primary Entry Points For Olympics

Hackers Exploit Security Testing Apps to Breach Fortune 500 Firms

Fortinet Admins Report Patched FortiGate Firewalls Getting Hacked

New Android Malware Uses AI to Click on Hidden Browser Ads

Greek Police Arrest Scammers Using Fake Cell Tower Hidden in Car Trunk

Ireland Wants to Give Its Cops Spyware, Ability to Crack Encrypted Messages

EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act

UK’s NCC Group to Sell Escode for $369.4 Million
Everest Ransomware Gang Said to Be Sitting on Mountain of Under Armour Data

Online Retailer PcComponentes Says Data Breach Claims are Fake

Peruvian Loan Scam Harvests Cards and PINs via Fake Applications

LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Cisco Fixes Unified Communications RCE Zero Day Exploited in Attacks

Tesla Hacked, 37 Zero-Days Demoed at Pwn2Own Automotive 2026

Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch

1/20/2026

North Korea-Linked Hackers Target Developers via Malicious VS Code Projects

EU Plan to Phase-Out High-Risk Tech Draws Fire From China’s Huawei

Greece, Israel to Cooperate on Anti-Drone Systems, Cybersecurity, Greek Minister Says

Krebs: Kimwolf Botnet Lurking in Corporate, Gov’t Networks

UK Launches Landmark ‘Report Fraud’ Service to Tackle Cybercrime and Fraud

Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

Cyber Risks Among CEOs’ Top Worries Amid Weak Short Term Growth Outlook

AI Supercharges Attacks in Cybercrime’s New ‘Fifth Wave’

VoidLink Cloud Malware Shows Clear Signs of Being AI-Generated

True Agentic AI Is Years Away – Here’s Why and How We Get There

Supreme Court to Consider Whether Geofence Warrants Are Constitutional

UK Says It Will Consider Banning Social Media for Children
Hackers Target Afghan Government Workers With Fake Correspondence From Senior Officials

Linkedin Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs

Numerous Mass Spam Attacks Leverage Zendesk Instances

UStrive Security Lapse Exposed Personal Data of Its Users, Including Children

Minnesota Department of Human Services Data Breach Affects Over 300K Individuals

Everest Ransomware Claims McDonalds India Breach Involving Customer Data

Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto

ACF Plugin Bug Gives Hackers Admin on 50,000 WordPress Sites

Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers

Chainlit Security Flaws Highlight Infrastructure Risks in AI Apps

Prompt Injection Bugs Found in Official Anthropic Git MCP Server

Lawmakers Move to Extend Two Cyber Programs (Again) in Funding Proposal

1/19/2026

Iran to Consider Lifting Internet Ban; State TV Hacked to Air Anti-Regime Messages

Russian Hacktivists Intensify Disruptive Cyber Pressure on UK Orgs

Read the Texts Between Trump and Norway’s Prime Minister

How Crypto Criminals Stole $700 Million From People – Often Using Age-Old Tricks
Ingram Micro Admits Summer Ransomware Raid Exposed Thousands of Staff Records

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Researchers Uncover PDFSIDER Malware Built for Long-Term, Covert System Access

Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites

1/16-18/2026

China-Linked Hackers Exploited Sitecore Zero-Day for Initial Access

Trump Says Iran Has Told Him ‘Killing Has Stopped’ as He Pulls Back From Strike Threats

Donald Trump Calls off Iran Strikes After Steve Witkoff, Araghchi Texts

By Asking Trump to Delay Iran Attacks, Netanyahu Exposes Israel’s Air Defense Holes

Anti-Regime Activists Hack Iran’s National Broadcaster, Transmit Pahlavi’s Calls to Protest

Canada Will Regret Allowing Chinese EVs Into Their Market, U.S. Says

EU Moves to Force the Phase-Out of Chinese Suppliers From Key Infrastructure

A Faceless Hacker Stole My Therapy Notes – Now My Deepest Secrets Are Online Forever

Jordanian Initial Access Broker Pleads Guilty to Helping Target 50 Companies

Police Raid Homes of Alleged Black Basta Hackers, Hunt Suspected Russian Ringleader

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
Canadian Investment Regulatory Organization (CIRO) Confirms Data Breach Exposed Info on 750,000 Canadian Investors

Tens of Millions of French Citizen Records Exposed

TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals

RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation Wave

Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection

Malicious GhostPoster Browser Extensions Found with 840,000 Installs

Hackers Now Exploiting Critical Fortinet FortiSIEM Flaw in Attacks

StealC Hackers Hacked as Researchers Hijack Malware Control Panels

Cisco Finally Fixes AsyncOS Zero-Day Exploited Since November

I’m Sorry Dave, I’m Afraid I Can’t Do That! PCs Refuse to Shut Down After Microsoft Patch

1/15/2026

Chinese-Linked Hackers Target U.S. Entities With Venezuelan-Themed Malware

ICE Agent Doxxing Site DDoS-ed Via Russian Servers

Hackers Increasingly Shun Encryption in Favour of Pure Data Theft and Extortion

Former CISA Director Jen Easterly Will Lead RSAC Conference

FTC Bans GM From Selling Drivers’ Location Data for Five Years

Google to Pay $8.25 Million to Settle Lawsuit Alleging Children’s Privacy Violations

Elon Musk’s X Says It Will Block Grok From Making Sexual Images

Data Privacy Teams Face Staffing Shortages and Budget Constraints, ISACA Warns

Cloudflare Acquires AI Data Marketplace Human Native

Former U.S. Special Forces Officer Is Now a Startup CEO—His Cybersecurity Company Has Raised $22 Million
Verizon’s Hourslong Wireless Outage Tied to Software Update

Grubhub Confirms Hackers Stole Data in Recent Security Breach

Anchorage Police Department Takes Servers Offline After Cyberattack on Service Provider

Contagious Claude Code Bug Anthropic Ignored Promptly Spreads to Cowork

WhisperPair: Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking

Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access

Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login

Trio of Critical Bugs Spotted in Delta Industrial PLCs

CodeBuild Flaw Put AWS Console Supply Chain At Risk

Germany Turns to Israel for a ‘Cyber Dome’ Amid Rising Threats

1/14/2026

PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces

Ukraine Appoints Digital Chief as Defense Minister to Drive Military Reform

Western Cyber Agencies Warn About Threats to Industrial Operational Technology

Beijing Tells Chinese Firms to Stop Using U.S. and Israeli Cybersecurity Software, Sources Say

Lawmakers to Restart Efforts to Revive Lapsed Cyber Intel Bill

Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers

Criminal Subscription Service Behind AI-Powered Cyber-Attacks Taken Out By Microsoft

Verizon Outage Knocks Out U.S. Mobile Service, Including Some 911 Calls

France Fines Telcos €42M for Sub-Par Security Prior to 24M Customer Breach

Palantir Is Trying to ‘Destroy’ Percepta Through Legal Action, Startup’s Execs Say in Filing

Google’s Personal Intelligence links Gmail, Photos and Search to Gemini

California AG to Probe Musk’s Grok for Nonconsensual Deepfakes

Ugandan Officials Turn Off Internet on Eve of National Elections
Victorian Department of Education Says Hackers Stole Students’ Data

Monroe University Says 2024 Data Breach Affects 320,000 People

South Korean Giant Kyowon Confirms Data Theft in Ransomware Attack

Cloud Marketplace Pax8 Accidentally Exposes Data on 1,800 MSP Partners

Reprompt Attack Hijacked Microsoft Copilot Sessions for Data Theft

Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs

DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation

Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution

Krebs: Patch Tuesday, January 2026 Edition

Federal Agencies Ordered to Patch Microsoft Desktop Windows Manager Bug

Microsoft Updates Windows DLL That Triggered Security Alerts

1/13/2026

Massive Cyberattack on Polish Power System in December Failed, Minister Says

Hill Warning: Don’t Put Cyber Offense Before Defense

Trump Renominates Sean Plankey for CISA Director

Ukraine Parliament Approves Resignation of Security Service Chief in Major Reshuffle

Kremlin-Linked Hackers Pose as Charities to Spy on Ukraine’s Military

Senior Military Cyber Operator Removed From Russia Task Force

More Than 40 Countries Impacted by North Korea IT Worker Scams, Crypto Thefts

Oracle Hack Still Generating Ransom Demands

India’s Smartphone Security Proposal Faces Backlash Over Privacy Concerns

Quantum Software Company Haiqu Raises $11 Million

AI and Automation Could Erase 10.4 Million U.S. Roles by 2030

What’s the Deal With Physical AI? Why the Next Frontier of Tech Is Already All Around You

Teen Hackers Recruited Through Fake Job Ads

Tennessee Man to Plead Guilty to Hacking Supreme Court’s Electronic Case Filing System

Dutch Cops Cuff Alleged AVCheck Malware Kingpin in Amsterdam
Target Employees Confirm Leaked Source Code Is Authentic

Suspected Ransomware Attack Threatens One of South Korea’s Largest Companies, Kyowon Group

Everest Ransomware Group Claims Nissan Breach, Demands Response

Central Maine Healthcare Breach Exposed Data of Over 145,000 People

Belgian Hospital AZ Monica Shuts Down Servers After Cyberattack

VoidLink: New Chinese-Made Malware Framework Targets Linux-Based Cloud Environments

Global Magecart Campaign Targets Six Card Networks

SHADOW#REACTOR Campaign Uses Text-Only Staging to Deploy Remcos RAT

Convincing LinkedIn Comment-Reply Tactic Used in New Phishing

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Popular Python Libraries Used in Hugging Face Models Subject to Poisoned Metadata Attack

Adobe Patches Critical Apache Tika Bug in ColdFusion

Microsoft January 2026 Patch Tuesday Fixes 3 Zero-Days, 114 Flaws

Microsoft Releases Windows 10 KB5073724 Extended Security Update

New Windows Updates Replace Expiring Secure Boot Certificates

1/12/2026

Internet Monitoring Experts Say Iran Blackout Likely to Continue

Sweden Detains Ex-Military IT Consultant Suspected of Spying for Russia

Hungary Grants Asylum to Former Polish Minister Implicated in Spyware Probe

World Economic Forum: Cyber-Fraud Overtakes Ransomware as Business Leaders’ Top Cyber-Security Concern

Illicit Crypto Activity Hits Record $158bn in 2025

Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud

Ofcom Officially Investigating X as Grok’s Nudify Button Stays Switched On

Palo Alto Networks Introduces New Vibe Coding Security Governance Framework

Hacker Gets Seven Years for Breaching Rotterdam and Antwerp Ports

‘Violence-As-A-Service’ Suspect Arrested in Iraq, Extradition Underway

Kentucky Sues Character.AI, Alleging It Harms Children and Violates Data Law

Anthropic Brings Claude to Healthcare with HIPAA-Ready Enterprise Tools
University of Hawaii Cancer Center Hit by Ransomware Attack

Spanish Energy Giant Endesa Discloses Data Breach Affecting Customers

‘Bad Actor’ Hijacks Apex Legends Characters in Live Matches

Target’s Dev Server Offline After Hackers Claim to Steal Source Code

Armenia Probes Alleged Sale of 8 Million Government Records on Hacker Forum

Fintech Firm Betterment Confirms Data Breach After Hackers Send Fake Crypto Scam Notification to Users

Instagram Denies Breach After Many Receive Emails Asking to Reset Password

Facebook Login Thieves Now Using Browser-In-Browser Trick

Hidden Telegram Proxy Links Can Reveal Your IP Address in One Click

n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens

CISA Orders Feds to Patch Gogs RCE Flaw Exploited in Zero-Day Attacks

Apple Confirms Google Gemini Will Power Siri, Says Privacy Remains a Priority

Torq Raises $140 Million for Agentic AI-Powered Cybersecurity Platform

1/9-11/2026

China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines

Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

World Economic Forum: Deepfake Face-Swapping Tools Are Creating Critical Security Risks

Krebs: Who Benefited from the Aisuru and Kimwolf Botnets?

Europol Leads Global Crackdown on Black Axe Cybercrime Gang, 34 Arrested

X Didn’t Fix Grok’s ‘Undressing’ Problem. It Just Makes People Pay for It

Lawmakers Call On App Stores to Remove Grok, X Over Sexualized Deepfakes

Illinois Man Charged With Hacking Snapchat Accounts to Steal Nude Photos

Ireland Recalls Almost 13,000 Passports Over Missing ‘IRL’ Code

California Bans Data Broker Reselling Health Data of Millions

Stellar Gains, Heavy Losses: Cybersecurity Stocks Had a Mixed Year

Here’s What Cloud Security’s Future Holds for the Year Ahead
BreachForums Hacking Forum Database Leaked, Exposing 324,000 Accounts

Ransomware Attack on Texas Gas Station Firm Gulshan Management Services Leaks 377,000 User Records

At Least $26 Million in Crypto Stolen From Truebit Platform as Crypto Crime Landscape Evolves

AI-Powered Truman Show Operation Industrializes Investment Fraud

Betterment’s Financial App Sends Customers a $10,000 Crypto Scam Message

Warning Over Scams Targeting Manx Email Accounts

Instagram Says It Fixed the Issue That Let Someone Send All Those Password Reset Emails

FBI Warns of North Korean QR Phishing Campaigns

Hackers Target Misconfigured Proxies to Access Paid LLM Services

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024

UK Government Exempting Itself From Flagship Cyber Law Inspires Little Confidence

Former NSA Insider Kosiba Brought Back as Spy Agency’s No. 2

1/8/2026

China Hacked Email Systems of U.S. Congressional Committee Staff

U.S. To Leave Global Forum on Cyber Expertise

NSA Cyber Directorate Gets New Acting Leadership

Venezuela Raid Highlights Cyber Vulnerability of Critical Infrastructure

ChatGPT Health Feature Draws Concern From Privacy Critics Over Sensitive Medical Data

Grok Is Generating Sexual Content Far More Graphic Than What’s on X

CrowdStrike Buys Identity Security Startup SGNL for $740 Million in Latest Deal Push

Cyera Valued at $9 Billion as Data Security Firm Raises $400 Million

EU Antitrust Regulators to Decide on Google’s Wiz Deal by February 10

Texas Court Blocks Samsung From Tracking TV Viewing, Then Vacates Order

Ransomware Attacks Kept Climbing in 2025 as Gangs Refused to Stay Dead

Two-Fifths of 50% of Breaches Take Two Weeks to Recover From

Russia Frees French Researcher in Prisoner Swap for Alleged Ransomware Hacker
China-Linked UAT-7290 Targets Telecom Networks in South Asia

Iran-Linked Hacker Group Claims to Have Hacked, Surveilled Senior Mossad Agent

More Than 100,000 Households Warned After Cyber Attack on Kensington and Chelsea Council

Sedgwick Breach Linked to TridentLocker Ransomware Attack

WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging

GoBruteforcer Botnet Targets Linux Servers

Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages

New Zero-Click Attack Lets ChatGPT User Steal Data

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited

Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances

Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release

Cisco Switches Hit by Reboot Loops Due to DNS Client Bug

Microsoft to Enforce MFA for Microsoft 365 Admin Center Sign-Ins

1/7/2026

Cyberattacks Likely Part of Military Operation in Venezuela

European Space Agency Calls Cops as Crims Lift Off 500 GB of Files, Say Security Black Hole Still Open

Taiwan Says China’s War Games Sought to Undermine Global Support for the Island

China Intensifies Cyber-Attacks on Taiwan as Energy Sector Sees Tenfold Spike

Grok AI Still Being Used to Digitally Undress Women and Children Despite Suspension Pledge

IBM’s AI Agent Bob Easily Duped to Run Malware, Researchers Show

Google Search AI Hallucinations Push Google to Hire “AI Answers Quality” Engineers

Personal LLM Accounts Drive Shadow AI Data Leak Risks

Cloudy Outlook for Cyber Jobs as AI Fills Security Gaps

Stalkerware Operator Pleads Guilty in Rare Prosecution

Alleged Cyber Scam Kingpin Arrested, Extradited to China
MFA Failure Enables Infostealer Breach At 50 Enterprises

Illinois Department of Human Services Reports Yearslong Data Breach

Cyberattack Under Investigation by Coles County School District (IL)

Spanish Airline Iberia Attributes Recent Data Breach Claims to November Incident

Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches

Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud

Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads

Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing

Critical jsPDF Flaw Lets Hackers Steal Secrets via Generated PDFs

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication

Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control

1/6/2026

Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government

UK Launches New Cyber Unit to Bolster Defences Against Cyber Threats

UK Government Admits Years of Cyber Policy Have Failed, Announces Reset

Ring’s Mobile Security Trailer Provides 360-Degree Coverage Anywhere

Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users

Jaguar Land Rover Wholesale Volumes Down 43% After Cyberattack

Startup Trends Shaking Up Browsers, SOC Automation, AppSec

Cybersecurity Predictions 2026: An AI Arms Race and Malware Autonomy
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat

Hospitality Sector Hit By PHALT#BLYX ClickFix Malware Campaign

Cloud File-Sharing Sites Targeted for Corporate Data Theft Attacks

High-Severity Flaw in Open WebUI Affects AI Connections

New D-Link Flaw in Legacy DSL Routers Actively Exploited in Attacks

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers

Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover

1/5/2026

Russian Hackers Target European Hospitality Industry With ‘Blue Screen of Death’ Malware

The French University Where Spies Go for Training

As Supply-Chain Cyber Risks Mount, Can AI Help?

EU Looking ‘Very Seriously’ at Taking Action Against X Over Grok

Finland Arrests Two Crew Members of Ship Suspected of Cable Break

Playing Koi: Palo Alto Isn’t Saying if It Will Buy Security Start-up

VSCode IDE Forks Expose Users to “Recommended Extension” Attacks
New Zealand Orders Review Into ManageMyHealth Cyberattack

Aurora College Working to Get Systems Back Up After Cyber Attack

Cyberattack Forces British High School to Close

Ledger Customers Impacted by Third-Party Global-E Data Breach

U.S. Broadband Provider Brightspeed Investigates Breach Claims

NordVPN Denies Breach Claims, Says Attackers Have “Dummy Data”

VVS Stealer Uses Advanced Obfuscation to Target Discord Users

1/2-4/2026

Inside the Operation: How the U.S. Moved to Capture Nicolás Maduro

Trump Suggests U.S. Used Cyberattacks to Turn Off Lights in Venezuela During Strikes

Krebs: The Kimwolf Botnet is Stalking Your Local Network

8 WhatsApp Features to Boost Your Security and Privacy

How to Protect Your iPhone or Android Device From Spyware

Trump Admin Sends Heart Emoji to Commercial Spyware Makers With Lifted Predator Sanctions

Bitfinex Crypto Thief Who Was Serving Five Years Thanks Trump for Early Release

Palo Alto Networks Security-Intel Boss Calls AI Agents 2026’s Biggest Insider Threat

Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats
Cybercrook Claims to Be Selling Infrastructure Info About Three Major U.S. Utilities

Hackers Claim to Hack Resecurity, Firm Says It Was a Honeypot

Sedgwick Confirms Cyber Incident Affecting Its Major Federal Contractor Subsidiary

Trust Wallet Links $8.5 Million Crypto Theft to Shai-Hulud NPM Attack

Covenant Health Says May Data Breach Impacted Nearly 478,000 Patients

Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign

Over 10K Fortinet Firewalls Exposed to Actively Exploited 2FA Bypass

12/30-31/2025

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

Finland Seizes Ship Suspected of Damaging Subsea Cable in Baltic Sea

Washington Wants to Get Tough on Nation-State Hackers. Are Infrastructure Operators Ready?

Fears Mount That U.S. Federal Cybersecurity Is Stagnating—Or Worse

Two Cybersecurity Employees Plead Guilty to Carrying Out Ransomware Attacks

Meta Created ‘Playbook’ to Fend Off Pressure to Crack Down on Scammers, Documents Show

Hong Kong’s Newest Anti-Scam Technology: Over-The-Counter Banking

New York’s Incoming Mayor Zohran Mamdani Bans Raspberry Pi at His Inauguration Party

And Flipper Zero

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

Disney Will Pay $10 Million to Settle Children’s Data Privacy Lawsuit

Coupang to Split $1.17 Billion Among 33.7 Million Data Breach Victims
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

European Space Agency Hit Again as Cybercrims Claim 200 GB Data up for Sale

Hackers Drain $3.9M From Unleash Protocol After Multisig Hijack

DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide

Zoom Stealer Browser Extensions Harvest Corporate Meeting Intelligence

New ERRTraffic Service Enables ClickFix Attacks via Fake Browser Glitches

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry

RondoDox Botnet Exploits React2Shell Flaw to Breach Next.js Servers

US, Australia Say ‘MongoBleed’ Bug Being Exploited

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass

12/29/2025

The Worst Hacks of 2025

Happy 16th Birthday, KrebsOnSecurity.com!

Indian Cops Cuff Ex-Coinbase Rep Over Selling Customer Info to Crims

Hacker Arrested for KMSAuto Malware Campaign with 2.8 Million Downloads

Accused Data Thief Threw MacBook Into a River to Destroy Evidence
Korean Air Data Breach Exposes Data of Thousands of Employees

Romanian Energy Provider Oltenia Energy Complex Hit by Gentlemen Ransomware Attack

Two More Banks Notifying Thousands of Victims About Marquis Software Ransomware Attack

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

12/26-28/2025

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

The U.S. Must Stop Underestimating Drone Warfare

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

Death, Torture, and Amputation: How Cybercrime Shook the World in 2025

From Video Games to Cyber Defense: If You Don’t Think Like a Hacker, You Won’t Win

Coupang Founder Kim Bom Apologises for Data Leak, Pledges Compensation

Shaping the Next Generation of Cyber Experts
Trust Wallet Users Lose $7 Million to Hacked Chrome Extension

Fake GrubHub Emails Promise Tenfold Return on Sent Cryptocurrency

Ubisoft Shuts Down ‘Rainbow Six Siege’ Servers Following Hack

Hacker Claims to Leak WIRED Database with 2.3 million Records

Everest Ransomware Group Claims Theft of Over 1TB of Chrysler Data

Exploited MongoBleed Flaw Leaks MongoDB Secrets, 87K Servers Exposed

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

12/25/2025

Why Hackers Love the Holidays, Especially Christmas and the Like

OpenAI is Reportedly Testing Multiple Claude-Like Skills For ChatGPT

Study Reveals Businesses Continue to Underinvest in Cybersecurity and are Neglect in Vulnerability Assessments

The Biggest Cybersecurity Mergers and Acquisitions of 2025
Somerset County (PA) Utilizing New 911 Alert System After Cyber Attack

Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

12/24/2025

Pro-Russian Hackers Noname057 Claim Cyberattack on French Postal Service

NIST, MITRE Partner on $20m AI Centers For Manufacturing and Cybersecurity

The Age of the All-Access AI Agent Is Here

Pen Testers Accused of ‘Blackmail’ After Reporting Eurostar Chatbot Flaws

All I Want for Christmas Is Not a Scam – Tips to Avoid Digital Threats During the Festive Season
AI Powered Cyber Attack Hits Chinese TikTok Short Video Rival Kuaishou

Coordinated Scams Target MENA Region Extensively With Fake Online Job Ads

Fake MAS Windows Activation Domain Used to Spread PowerShell Malware

MongoDB Warns Admins to Patch Severe RCE Flaw Immediately

Cyber Volunteer Effort for Small Water Utilities Announces New MSSP Effort

12/23/2025

86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush

Dozens of Flock AI Camera Feeds Were Just Out There

FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks

Chinese Crypto Scammers on Telegram Are Fueling the Biggest Darknet Markets Ever

SEC Sues Crypto Firms for Defrauding Investors Out of $14 Million

U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

NYPD Sued Over Possible Records Collected Through Muslim Spying Program

Italy Fines Apple $116 Million Over App Store Privacy Policy Issues
More Than 22 Million Aflac Customers Impacted by June Data Breach

Baker University (KS) Says 2024 Data Breach Impacts 53,000 People

Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

WebRAT Malware Spread via Fake Vulnerability Exploits on Github

Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

Microsoft Rolls Out Hardware-Accelerated BitLocker in Windows 11

A Cybersecurity Playbook for AI Adoption

ServiceNow Opens $7.7b Ticket Titled ‘Buy Security Company, Make It Armis’

12/22/2025

Cyber Spies Use Fake New Year Concert Invites to Target Russian Military

Romanian Water Authority Hit by BitLocker Ransomware Attack Over Weekend

Hacktivists Scrape 86M Spotify Tracks, Claim Their Aim Is to Preserve Culture

Microsoft Windows ‘Hack Your Own Password’ Attack Warning Issued

South Korea to Require Facial Recognition for New Mobile Numbers

Judge Rules That NSO Cannot Continue to Install Spyware via WhatsApp Pending Appeal

Interpol-Led Action Decrypts 6 Ransomware Strains, Arrests Hundreds

Nefilim Ransomware Affiliate Pleads Guilty
France’s National Post Office Hit by Suspected Cyber-Attack, Delaying Deliveries

University of Phoenix Data Breach Impacts Nearly 3.5 Million Individuals

Nissan Says Thousands of Customers Exposed in Red Hat Breach

Scripted Sparrow Sends Millions of BEC Emails Each Month

Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

New MacSync Malware Dropper Evades macOS Gatekeeper Checks

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access

12/19-21/2025

Inquiry Ongoing After UK Government Hacked, Says Minister

Firms Warned to Be On ‘High Alert’ for Scam Emails

Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence

Russian Defense Firms Targeted by Hackers Using AI, Other Tactics

Trump Signs Defense Bill Allocating Millions for Cyber Command, Mandating Pentagon Phone Security

Senate Confirms New Pentagon CIO

Krebs on Dismantling Defenses: Trump 2.0 Cyber Year in Review

Here’s What’s in the DOJ’s Epstein Files Release—And What’s Missing

U.S. Charges 54 in Massive ATM Jackpotting Conspiracy

Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

Ex-Michigan Assistant Matt Weiss Seen on Video Hacking Into Student Accounts, Security Footage Reveals
Hacks, Thefts, and Disruption: The Worst Data Breaches of 2025

Richmond Behavioral Health Authority (VA) Breach Hits Over 113K

Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware

RansomHouse Upgrades Encryption With Multi-Layered Data Processing

How RomCom Became a Multipurpose Cyberweapon

WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

Over 25,000 FortiCloud SSO Devices Exposed to Remote Attacks

New UEFI Flaw Enables Pre-Boot Attacks on Motherboards from Gigabyte, MSI, ASUS, ASRock

Docker Hardened Images Now Open Source and Available for Free

Palo Alto Networks Announces Multibillion-Dollar Deal With Google Cloud

FTC: Instacart to Refund $60M Over Deceptive Subscription Tactics

12/18/2025

Denmark Says Russia Was Behind Two ‘Destructive and Disruptive’ Cyber-Attacks

LongNosedGoblin: China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware

New BeaverTail Malware Variant Linked to Lazarus Group

Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

North Korea Steals Over $2bn in Crypto in 2025

Amazon Blocked 1,800 Suspected North Korean Scammers Seeking Jobs

Haotian: The Ultra-Realistic AI Face Swapping Platform Driving Romance Scams

France Arrests Latvian for Installing Malware on Italian Ferry

Austria’s High Court Orders Meta to Change Its Personalized Ad Practices

Pa. High Court Rules That Police Can Access Google Searches Without a Warrant
Tech Provider for NHS England DXS International Confirms Data Breach

University of Sydney Suffers Data Breach Exposing Student and Staff Info

HMRC Warns of Over 135,000 Scam Reports

OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365

Clop Ransomware Targets Gladinet Centrestack in Data Theft Attacks

Your Car’s Web Browser May Be On the Road to Cyber Ruin

New Password Spraying Attacks Target Cisco, PAN VPN Gateways

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

BlackBerry Lifts Lower End of Annual Revenue Forecast on Cybersecurity Demand

12/17/2025

Chinese Ink Dragon Group Hides in European Government Networks

APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign

New Spyware Discovered on Belarusian Journalist’s Phone After Interrogation

Former Israeli Prime Minister Bennett’s Telegram Hacked, Not Phone, Despite Iranian Group’s Claims

Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks

Border Patrol Bets on Small Drones to Expand U.S. Surveillance Reach

Trump Targets Defense Giants’ Shareholder Payouts as Cost Overruns Mount, Sources Say

Blockchain Company Nomad to Repay Users Under FTC Deal After $186M Cyberattack

FBI Takes Down Alleged Money Laundering Service for Ransomware Groups

France Arrests Suspect Tied to Cyberattack on Interior Ministry

TikTok Tracked User’s Grindr Activity in Violation of European Law, Rights Group Alleges

Privacy Advocates See Risk in New Meta Policy That Uses AI Chats to Serve Targeted Ads
U.S. Autoparts Maker LKQ Confirms Oracle EBS Breach

New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Critical React2Shell Flaw Exploited in Ransomware Attacks

Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks

Cellik Android Malware Builds Malicious Versions From Google Play Apps

WhatsApp Device Linking Abused in Account Hijacking Attacks

New “Lies-in-the-Loop” Attack Undermines AI Safety Dialogs

Motors WordPress Vulnerability Exposes Sites to Takeover

Cisco Warns of Unpatched AsyncOS Zero-Day Exploited in Attacks

SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances

Zeroday Cloud Hacking Event Awards $320,0000 for 11 Zero Days

Think Like an Attacker: Cybersecurity Tips From a CISO

Roblox in Talks With Russia to Restore Access After Platform Ban Sparks Backlash

12/16/2025

Amazon Warns Russian GRU Hackers Target Western Firms via Edge Devices

Cyberattack Disrupts Venezuelan Oil Giant PDVSA’s Operations

Venezuela State Oil Company Blames Cyberattack on U.S. After Tanker Seizure

House Homeland Security Chairman Keeps Attention on Cyber Issues

Senior Official at Indo-Pacific Command Is Set to Be Trump’s Pick to Lead Cyber Command, NSA

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

Phishing Messages and Social Scams Flood Users Ahead of Christmas

Krebs: Most Parked Domains Now Serving Malicious Content

European Authorities Dismantle Call Center Fraud Ring in Ukraine

Still Using Windows 10? You’re a Prime Target for Ransomware Now – Unless You Do This
Hacking Group ‘ShinyHunters’ Threatens to Expose Premium Users of Sex Site PornHub

Analytics Provider Mixpanel: We Didn’t Expose You to Crims

City of Westminster (SC) Missing Public Funds After Cyber Attack, Officials Say

Madison Healthcare (MN) Confirms Data Breach After Ransomware Attack

Urban VPN Proxy Accused of Harvesting AI Chat Conversations

GhostPoster Attacks Hide Malicious JavaScript in Firefox Addon Logos

Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

JumpCloud Windows Agent Flaw Enables Local Privilege Escalation

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

12/15/2025

Suspected Russian Hackers Step Up Attacks on U.S. Energy Firms, Research Shows

German Parliament Suffers Suspected Cyber Attack During Zelenskyy’s Visit

French Interior Ministry Confirms Cyberattack on Email Servers

Google Links More Chinese Hacking Groups to React2Shell Attacks

MI6 Chief Warns ‘Front Line Is Everywhere’ and Signals Intent to Pressure Putin

U.S. Government Launches Campaign to Hire Engineers for AI, Tech Roles

Starlink Claims Chinese Launch Came Within 200 Meters of Broadband Satellite

Google’s Turning off Its Dark Web Monitoring Service That Scoured Data Breaches for Your Info

Texas Sues 5 Smart TV Manufacturers Over Data Collection Practices

Third Defendant Pleads Guilty in Fantasy Sports Betting Hack Case

Vibe Coding: Innovation Demands Vigilance
700Credit Data Breach Impacts 5.8 Million Vehicle Dealership Customers

Nearly 20 Million Affected by Prosper, 700Credit Data Breaches

Askul Confirms Theft of 740K Customer Records in Ransomware Attack

PornHub Extorted After Hackers Steal Premium Member Activity Data

More Than 238K Hit by Akira-Claimed Fieldtex Product Hack

Ongoing SoundCloud Issue Blocks VPN Users With 403 Server Error

SoundCloud Confirms Breach After Member Data Stolen, VPN Access Disrupted

Russian Phishing Campaign Delivers Phantom Stealer Via ISO Files

New SantaStealer Malware Steals Data From Browsers, Crypto Wallets

Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE

12/12-14/2025

React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation

Germany Summons Russian Ambassador Over Cyberattack, Election Disinformation

Announced Pick for No. 2 at NSA Won’t Get the Job as Another Candidate Surfaces

Trump Order on AI May Not Deter State Laws

AI Toys for Kids Talk About Sex and Issue Chinese Communist Party Talking Points, Tests Show

U.S. Bill Seeks Phase-Out of Chinese Sensors in Self-Driving Cars, After Space Hack Fears

ServiceNow in Talks to Acquire Cybersecurity Startup Armis in Potential $7 Billion Deal

Uncle Sam Sues Ex-Accenture Manager Over Army Cloud Security Claims

Coupang Data Breach Traced to Ex-Employee Who Retained System Access

MKVCinemas Streaming Piracy Service With 142M Visits Shuts Down

Canada’s Privacy Regulator to Probe Billboards Equipped With Facial Scanning Tech

Streisand Effect: Businesses That Pay Ransomware Gangs Are More Likely to Hit the Headlines

CyberVolk’s Ransomware Debut Stumbles on Cryptography Weakness
More Than 340,000 Impacted by Cyberattack on Library System of Pierce County (WA)

Hamas-Affiliated APT Targeting Government Agencies in the Middle East, Morocco

Beware: PayPal Subscriptions Abused to Send Fake Purchase Emails

Fake ‘One Battle After Another’ Torrent Hides Malware in Subtitles

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads

New React RSC Vulnerabilities Enable DoS and Source Code Exposure

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks

New Windows RasMan Zero-Day Flaw Gets Free, Unofficial Patches

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

MITRE Shares 2025’s Top 25 Most Dangerous Software Weaknesses

Kali Linux 2025.4 Released With 3 New Tools, Desktop Updates

12/11/2025

Hackers Reportedly Breach Developer Involved With Russia’s Military Draft Database

OpenAI Enhances Defensive Models to Mitigate Cyber-Threats

Google Ads for Shared ChatGPT, Grok Guides Push macOS Infostealer Malware

Russian Hackers Debut Simple Ransomware Service, but Store Keys in Plain Text

Lawmaker Calls Facial Recognition on Doorbell Cameras a ‘Privacy Nightmare’

Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data

LastPass Hammered With £1.2M Fine for 2022 Breach Fiasco

Federal Agencies Now Only Have One More Day to Patch React2Shell Bug
Data Breach at 700Credit Impacts 160,000 Michiganders

WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor

New ConsentFix Attack Hijacks Microsoft Accounts via Azure CLI

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems

Malware Discovered in 19 Visual Studio Code Extensions

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw

Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks

Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution

Notepad++ Fixes Flaw That Let Attackers Push Malicious Update Files

12/10/2025

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

U.S. Says Russia-Backed Hacks Targeted Critical Infrastructure

U.S. Extradites Ukrainian Woman Accused of Hacking Meat Processing Plant for Russia

2 Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’

U.S. Halts Plans to Sanction Chinese Spy Agency

British Government Sanctions Russian and Chinese Groups Over Information Warfare

OpenAI Warns New Models Pose ‘High’ Cybersecurity Risk

Log4Shell Downloaded 40 Million Times in 2025

Nvidia Builds Location Verification Tech That Could Help Fight Chip Smuggling

Coupang CEO Resigns Over Data Breach in South Korea

Senators Return to Effort to Boost Cybersecurity for Commercial Satellite Industry

Coalition Adds Deepfake Response to Cyber Insurance Policies Globally
Petco Takes Down Vetco Website After Exposing Customers’ Personal Information

Russia’s Flagship Airline Aeroflot Hacked Through Little-Known Tech Vendor Bakka Soft, According to New Report

ClickFix Social Engineering Sparks Rise of CastleLoader Attacks

New Spiderman Phishing Service Targets Dozens of European Banks

New DroidLock Malware Locks Android Devices and Demands a Ransom

Over 10,000 Docker Hub Images Found Leaking Credentials, Auth Keys

Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups

.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling

Google Fixes Zero Click Gemini Enterprise Flaw That Exposed Corporate Data

Microsoft Teams to Warn of Suspicious Traffic With External Domains

12/9/2025

React2Shell Exploit Campaigns Tied to North Korean Cyber Intrusion Tactics

Deploy New EtherRAT Malware

Gartner Calls For Pause on AI Browser Use

Analysts Warn of Cybersecurity Risks in Humanoid Robots

How to Answer the Door When the AI Agents Come Knocking

Trump Plans Executive Order Curbing State AI Law

Cyber Startup Saviynt Raises $700 Million to Secure Identity and Access

California Man Pleads Guilty to Rico Charges as DOJ Indicts Crypto Theft Gang

Spain Arrests Teen Who Stole 64 Million Personal Data Records

Seoul Cyber Investigators Seize Data, Devices From ‘South Korea’s Amazon’ Following Data Breach

Khashoggi Widow Files Complaint in France Alleging Saudi Government Infected Devices With Spywares
Space Bears Ransomware Claims Comcast Data Breach via Contractor Quasar Inc.

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading

STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware

DeadLock Ransomware Uses BYOVD to Evade Security Measures

Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data

Fortinet Warns of Critical FortiCloud SSO Login Auth Bypass Flaws

Ivanti Warns of Critical Endpoint Manager Code Execution Flaw

SAP Fixes Three Critical Vulnerabilities Across Multiple Products

Krebs: Microsoft Patch Tuesday, December 2025 Edition

Windows PowerShell Now Warns When Running Invoke-WebRequest Scripts

12/8/2025

MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign

Three Hacking Groups, Two Vulnerabilities and All Eyes on China

U.S. to Allow Nvidia H200 Chip Shipments to China, Trump Says

Meta Proposal for Less Data Sharing Is Approved by European Commission

UK Moves to Strengthen Undersea Cable Defenses as Russian Snooping Ramps Up

Home Office Kept Police Facial Recognition Flaws to Itself, UK Data Watchdog Fumes

Poland Arrests Ukrainians Utilizing ‘Advanced’ Hacking Equipment

193 Cybercrims Arrested, Accused of Plotting ‘Violence-As-A-Service’

Russian Police Bust Bank-Account Hacking Gang That Used NFCGate-Based Malware

Russian Kids Revolt as Kremlin Bans Roblox, Other Popular Apps
Researchers Track Dozens of Organizations Affected by React2Shell Compromises Tied to China’s MSS

Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT

Malicious VSCode Extensions on Microsoft’s Registry Drop Infostealers

Ransomware Gangs Turn to Shanya EXE Packer to Hide EDR Killers

ClayRat Android Spyware Expands Capabilities

Malware Families FvncBot, and SeedSnatcher Too

Total Ransomware Payments Surpass $4.5 Billion Since 2013

Over $2.1B From 2022 To 2024

Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks

UK Intelligence Warns AI ‘Prompt Injection’ Attacks Might Never Go Away

12/5-7/2025

China-Linked Warp Panda Targets North American Firms in Espionage Campaign

Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

React2Shell Flaw Exploited to Breach 30 Orgs, 77K IP Addresses Vulnerable

Cloudflare Restores Services After Minor Dashboard Outage

Cloudflare Blames Today’s Outage on react2shell Mitigations

Krebs: SMS Phishers Pivot to Points, Taxes, Fake Retailers

Krebs: Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

Crims Using Social Media Images, Videos in ‘Virtual Kidnapping’ Scams

Louvre to Bolster Its Security, Issues €57m Public Tender

Portugal Updates Cybercrime Law to Exempt Security Researchers

Maryland Man Sentenced for N. Korea IT Worker Scheme Involving U.S. Government Contracts

EU Fines X $140 Million Over Deceptive Blue Checkmarks

SolarWinds’ Tim Brown Escaped the SEC. Future Cyber Chiefs Might Not.
Pharma Firm Inotiv Discloses Data Breach After Ransomware Attack

Barts Health NHS Discloses Data Breach After Oracle Zero-Day Hack

Huge Trove of Nude Images Leaked by AI Image Generator Startup’s Exposed Database

New Wave of VPN Login Attempts Targets Palo Alto GlobalProtect Portals

Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails

Novel Clickjacking Attack Relies on CSS and SVG

Hackers are Exploiting ArrayOS AG VPN Flaw to Plant Webshells

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch

NCSC’s ‘Proactive Notifications’ Warns Orgs of Flaws in Exposed Devices

Death to One-Time Text Codes: Passkeys Are the New Hotness in MFA

A Tale of Two CISOs: Why An Engineering-Focused CISO Can Be a Liability

12/4/2025

Amid Rising Threats, NATO Holds Its Largest-Ever Cyberdefense Exercise

Twins Who Hacked State Dept Hired to Work for Gov Again, Now Charged With Deleting Databases

UK Sanctions Russia’s GRU Agency and Cyber Spies Over Deadly Nerve Agent Attack

FBI Says DC Pipe Bomb Suspect Brian Cole Kept Buying Bomb Parts After January 6

Pentagon’s Signalgate Report Finds Pete Hegseth Violated Military Policies

Taiwan to Ban China’s Xiaohongshu App for One Year on Fraud Concerns

A New Anonymous Phone Carrier Lets You Sign Up With Nothing but a Zip Code

British Officials Seek to Expand Facial Recognition Technology Use

Cybersecurity Startup 7AI Raises $130 Million in Series A Funding

I Saw Drone Deliveries Launch in Atlanta – How They Work and Which Cities Are Next
CISA Warns of Chinese “BrickStorm” Malware Attacks on VMware Servers

Predator Spyware Uses New Infection Vector for Zero-Click Attacks

Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China

GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

New GhostFrame Phishing Framework Hits Over One Million Attacks

Critical React, Next.js Flaw Lets Hackers Execute Code on Servers

CISA and International Partners Issue Guidance for Secure AI in Infrastructure

Russia Blocks FaceTime and Snapchat for Alleged Use by Terrorists

Russian Scientist Sentenced to 21 Years on Treason, Cyber Sabotage Charges

12/3/2025

French NGO Reporters Without Borders Targeted by Star Blizzard

Disinformation and Cyber-Threats Among Top Global Business Exec Concerns

‘Exploitation Is Imminent’ as 39 Percent of Cloud Environs Have Max-Severity React Hole

UK Ransomware Payment Ban to Come with Exemptions, Security Minster Say

India Revokes Order to Preload Cybersecurity App on Smartphones After Outcry

FDA Scrutiny of WHOOP Signals Challenges for Niche Wearable Device Makers

Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

Security Startup Verkada Hits $5.8 Billion Valuation in Latest Funding Round Led by CapitalG

How Amazon Finds Its Cybersecurity Weak Spots

Russia Blocks Roblox Over Distribution of LGBT “Propaganda”

Google Expands Android Scam Protection Feature to Chase, Cash App in U.S.

DOJ Takes Down Myanmar Scam Center Website Spoofing TickMill Trading Platform

Canadian Police Department Becomes First to Trial Body Cameras Equipped With Facial Recognition Technology
French DIY Retail Giant Leroy Merlin Discloses a Data Breach

University of Phoenix Discloses Data Breach After Oracle Hack

Japan’s Askul Resumes Limited Online Sales 6 Weeks After Ransomware Attack

ASUS Listed by Everest Ransomware Group, 1 TB Data Stolen

Freedom Mobile Discloses Data Breach Exposing Customer Data

Fintech Firm Marquis Alerts Dozens of U.S. Banks and Credit Unions of a Data Breach After Ransomware Attack

Impacts Over 74 U.S. Banks, Credit Unions

Yearn Finance yETH Pool Hit by $9M Exploit

Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud

Aisuru Botnet Behind New Record-Breaking 29.7 Tbps DDoS Attack

Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

12/1-2/2025

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

ShadyPanda’s Seven-Year Campaign Infects 4.3M Chrome and Edge Users

Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks

Officials Accuse North Korea’s Lazarus of $30 Million Theft From Crypto Exchange

Most Companies Fear State-Sponsored Cyber-Attacks and Want More Government Help

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

Flock Uses Overseas Gig Workers to Build its Surveillance AI

Former Cyber Spy Raises $60 Million to Fight AI Threats

CrowdStrike Forecasts Upbeat Quarterly Revenue as AI Adoption Fuels Growth

Okta Projects Strong Quarterly Revenue on Rising Demand for Cybersecurity Tools

Axiado Raises $100 Million for Chip to Save Space, Power in AI Data Centers

Your Data Might Determine How Much You Pay for Eggs

ICO Set to Check If Mobile Games Comply with Children’s Code

FTC Settlement Requires Illuminate to Delete Unnecessary Student Data

Korea Arrests Suspects Selling Intimate Videos From Hacked IP Cameras

Europol Nukes Cryptomixer Laundering Hub, Seizing €25M in Bitcoin
India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud

Faces Backlash

ChatGPT Is Down Worldwide, Conversations Dissapeared for Users

Microsoft Defender Portal Outage Disrupts Threat Hunting Alerts

Google Deletes X Post After Getting Caught Using a ‘Stolen’ AI Recipe Infographic

University of Pennsylvania Joins List of Victims From Clop’s Oracle EBS Raid

Shai-Hulud 2.0 NPM Malware Attack Exposed Up To 400,000 Dev Secrets

Southold (NY) Police Are Reporting With Pen and Paper After Cyber Attack

Fake Calendly Invites Spoof Top Brands to Hijack Ad Manager Accounts

SmartTube YouTube App for Android TV Breached to Push Malicious Update

Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

New Android Albiriox Malware Gains Traction in Dark Web Markets

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

Critical PickleScan Vulnerabilities Expose AI Model Supply Chains

Google Releases Patches for Android Zero-Day Flaws Exploited in the Wild

11/27-30/2025

Bloody Wolf Threat Actor Expands Activity Across Central Asia

North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware

Chinese Cyberattack Campaign Likely Impacted Every American, Former FBI Official Says

Critical New FBI Warning: This Simple Hack Can Empty Your Bank Account

Poems Can Trick AI Into Helping You Make a Nuclear

Malicious LLMs Empower Inexperienced Hackers With Advanced Tools

Threat Actors Exploit Calendar Subscriptions for Phishing and Malware Delivery

FCC Warns of Hackers Hijacking Radio Equipment For False Alerts

The Wired Guide to Digital OPSEC for Teens

Three Black Friday Scams to Watch Out For This Year

TryHackMe Races to Add Women to Christmas Cyber Challenge Roster After Backlash

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

GrapheneOS Bails on OVHcloud Over France’s Privacy Stance

Man Behind In-Flight Evil Twin WiFi Attacks Gets 7 Years in Prison

Poland Arrested Suspected Russian Citizen for Hacking Local Organizations’ Computer Networks

GreyNoise Launches Free Scanner to Check if You’re Part of a Botnet
Asahi Confirms 1.5 Million Customers Affected in Major Cyber-Attack

Top South Korean E-Commerce Firm Coupang Apologises Over Massive Data Breach

Korean Web Giant Naver Acquired Crypto Exchange Upbit, Which Reported a $30M Heist a Day Later

French Football Federation Suffers Data Breach

Brit Telco Brsk Confirms Breach as Bidding Begins for 230K+ Customer Records

Data Copied in Kensington and Chelsea Cyber Attack

At Least 35,000 Impacted by Dartmouth College Breach Through Oracle EBS Campaign

Computer Services Impacted After Ransomware Attack Hits Golf Manor (OH)

OpenAI Warns of Mixpanel Data Breach Impacting API Users

Public GitLab Repositories Exposed More Than 17,000 Secrets

PostHog Admits Shai-Hulud 2.0 Was Its Biggest Ever Security Bungle

Scattered Lapsus$ Hunters Take Aim At Zendesk Users

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

California Law Regulating Web Browsers Could Have National Data Privacy Impact, Experts Say

11/26/2025

Bug in Jury Systems Used by Several U.S. States Exposed Sensitive Personal Data

New ShadowV2 Botnet Malware Used AWS Outage as a Test Opportunity

Gainsight CEO Downplays Breach, Says Only a ‘Handful’ of Customers Had Data Stolen

Krebs: Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’

The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been ‘Performative’

House Energy and Commerce Committee Unveils New Draft Children’s Online Safety Bill
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps

Popular Forge Library Gets Fix for Signature Verification Bypass Flaw

ASUS Warns of New Critical Auth Bypass Flaw in AiCloud Routers

11/25/2025

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

FBI: Cybercriminals Stole $262M by Impersonating Bank Support Teams

Scammers Hacked Her Phone and Stole Thousands – So How Did They Get Her Details?

Crime Rings Enlist Hackers to Hijack Trucks

ICE Offers up to $280 Million to Immigrant-Tracking ‘Bounty Hunter’ Firms

HashJack Attack Shows AI browsers Can Be Fooled With a Simple ‘#’

Tor Switches to New Counter Galois Onion Relay Encryption Algorithm

The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals

Russia Arrests Young Cybersecurity Entrepreneur on Treason Charges
Multiple London Councils ‘Hit by Cyber-Attacks’

Georgia Court Filing Organization Warns of Outages After Ransomware Allegations

Clop’s Oracle EBS Rampage Reaches Dartmouth College

OnSolve CodeRED Cyberattack Disrupts Emergency Alert Systems Nationwide

Smishing Triad Impersonation Campaigns Expand Globally

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers

11/24/2025

Russian-Linked Malware Campaign Hides in Blender 3D Files

Hackers Knock Out Systems at Moscow-Run Postal Operator in Occupied Ukraine

Krebs: Is Your Android TV Streaming Box Part of a Botnet?

Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs

UK Privacy Regulator Has Seen ‘Collapse in Enforcement Activity,’ Rights Coalition Says

Software Companies Must Be Held Liable for British Economic Security, Say MPs

Comcast to Pay $1.5 Million U.S. Fine After Vendor Data Breach

This Hacker Conference Installed a Literal Antivirus Monitoring System

With AI Reshaping Entry-Level Cyber, What Happens to the Security Talent Pipeline?
Harvard University Discloses Data Breach Affecting Alumni, Donors

AI Nude Photo Link Appears on Kansas AG’s Website After Apparent Hack

Fresh ClickFix Attacks Use Windows Update Trick-Pics to Steal Credentials

Malicious Blender Model Files Deliver StealC Infostealing Malware

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Flaws Expose Risks in Fluent Bit Logging Agent

Amazon Is Using Specialized AI Agents for Deep Bug Hunting

Microsoft to Remove WINS Support after Windows Server 2025

11/21-23/2025

China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services

More Companies Are Shifting Workers to Passwordless Authentication

Google Enables Pixel-to-iPhone File Sharing via Quick Share, AirDrop

Press a Button and This SSD Will Self-Destruct With All Your Data

Russia-Linked Crooks Bought a Bank for Christmas to Launder Cyber Loot

Four Charged Over Alleged Plot to Smuggle Nvidia AI Chips Into China

‘Scattered Spider’ Teens Plead Not Guilty to UK Transport Hack

CrowdStrike Catches Insider Feeding Information to Hackers

Flock Safety Cameras Used to Monitor Protesters, Rights Group Finds

Google Begins Showing Ads in AI Mode (AI Answers)
A Swath of Bank Customer Data Was Hacked at Real Estate Technology Vendor SitusAMC. The FBI. Is Investigating

Wall Street Banks Scramble to Assess Fallout From Hack of Real-Estate Data Firm

Cox Enterprises Discloses Oracle E-Business Suite Data Breach

Iberia Discloses Customer Data Leak After Vendor Security Breach

Local Law Enforcement Agencies in Oklahoma, Massachusetts Responding to Cyber Incidents

ShinyHunters ‘Does Not Like Salesforce at All,’ Claims the Crew Accessed Gainsight 3 Months Ago

Matrix Push C2: Cybercriminals Exploit Browser Push Notifications to Deliver Malware

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability

11/20/2025

Google Exposes BadAudio Malware Used in APT24 Espionage Campaigns

Russia Blacklists S.T.A.L.K.E.R. Game Developer, Accusing It of Aiding Ukraine’s War Effort

With the Rise of AI, Cisco Sounds an Urgent Alarm About the Risks of Aging Tech

LLM-Generated Malware Is Improving, but Don’t Expect Autonomous Attacks Tomorrow

CISA Issues New Guidance on Bulletproof Hosting Threat

Krebs: Mozilla Says It’s Finally Done With Two-Faced Onerep

The FCC Is Rolling Back Steps Meant to Stop a Repeat of a Massive Telecom Hack

U.S. SEC Dismisses Case Against SolarWinds, Top Security Officer

NSO Seeks to Overturn Whatsapp Case, Saying It Is ‘Catastrophic’ for the Spyware Maker

Fired Techie Admits Sabotaging Ex-Employer, Causing $862K in Damage

Samourai Crypto Mixer Founders Sent to Prison for Laundering Over $237 Million

TV Streaming Piracy Service Photocall With 26M Yearly Visits Shut Down
Salesforce Investigates Customer Data Theft via Gainsight Breach

Salesforce-Linked Data Breach Claims 200+ Victims, Has ShinyHunters’ Fingerprints All Over It

Hacker Claims to Steal 2.3TB Data From Italian Rail Group, Almavia

GlobalProtect VPN Portals Probed with 2.3 Million Scan Sessions

UNC2891 Money Mule Network Reveals Full Scope of ATM Fraud Operation

TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows

New SonicWall SonicOS Flaw Allows Hackers to Crash Firewalls

D-Link Warns of New RCE Flaws in End-of-Life DIR-878 Routers

Lawmakers Reintroduce Bill to Bolster Cybersecurity at Securities and Exchange Commission

Privacy Oversight Board Finds FBI Does Not Buy Real-Time Location Data

11/19/2025

China-Linked Operation “WrtHug” Hijacks Thousands of ASUS Routers

Cloudflare Shows Internet Outages Aren’t a Matter of If — but When

Krebs: The Cloudflare Outage May Be a Security Roadmap

Airline Data Broker Airlines Reporting Corporation to Stop Selling Individuals’ Travel Records to Government Agencies

Vaping Is ‘Everywhere’ in Schools—Sparking a Bathroom Surveillance Boom

Half of Ransomware Access Due to Hijacked VPN Credentials

Russian Bulletproof Hosting Provider Sanctioned Over Ransomware Ties

California Man Admits to Laundering Crypto Stolen in $230M Heist

Coordinated Europol Operation Disrupts $55m in Cryptocurrency For Piracy

Palo Alto Tops Earnings Expectations, Announces Chronosphere Acquisition

What AI Bubble? Nvidia’s Strong Earnings Signal There’s More Room to Grow

Canadian Privacy Regulators Say Schools Share Blame for PowerSchool Hack
Major Russian Insurer VSK Facing Widespread Outages After Cyberattack

Email Breach at St. Anthony Hospital (IL) May Have Exposed the Information of More Than 6,600 People

Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime

PlushDaemon Hackers Unleash New Malware in China-Aligned Spy Campaigns

Meet ShinySp1d3r: New Ransomware-as-a-Service Created by ShinyHunters

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

W3 Total Cache WordPress Plugin Vulnerable to PHP Command Injection

CISA Gives Gov’t Agencies 7 Days to Patch New Fortinet Flaw

Google Search Is Now Using AI to Create Interactive UI to Answer Your Questions

The AI Attack Surface: How Agents Raise the Cyber Stakes

Lawmakers Reintroduce Bill to Bolster Cybersecurity at Securities and Exchange Commission

11/18/2025

White House Goes on Cyber Offensive

CISA 2015 Receives Extension, Offering Brief Relief for Cyber Information Sharing

FCC Looks to Torch Biden-Era Cyber Rules Sparked by Salt Typhoon Mess

CBO Director Testifies That Hackers Have Been Expelled From Email Systems

MI5 Warns of Chinese Spies Using LinkedIn to Gain Intel on Lawmakers

Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks

A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

GenAI and Deepfakes Drive Digital Forgeries and Biometric Fraud

Microsoft Teams to Let Users Report Messages Wrongly Flagged as Threats

Microsoft Is Turning Windows Into an ‘Agentic OS,’ Starting With the Taskbar

Microsoft to Integrate Sysmon Directly Into Windows 11, Server 2025

Windows 11 Gets New Cloud Rebuild, Point-In-Time Restore Tools

Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This Year

Amazon, Google Named by EU Among ‘Critical’ Tech Providers for Finance Industry

Zoomers Are Officially Worse at Passwords Than 80-Year-Olds

Russian Suspect Detained in Thailand Is Allegedly Tied to Void Blizzard Group
Cloudflare Outage Disrupts X, ChatGPT and Other Parts of the Internet

Cloudflare Says Outage That Hit X, ChatGPT and Other Sites Is Resolved

Pro-Russian Group Claims Hits on Danish Party Websites as Voters Head to Polls

French Agency Pajemploi Reports Data Breach Affecting 1.2m People

LG Battery Subsidiary Says Ransomware Attack Targeted Overseas Facility

Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach

Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet

Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar

New ShadowRay Attacks Convert Ray Clusters Into Crypto Miners

Researchers Detail Tuoni C2’s Role in an Attempted 2025 Real-Estate Cyber Intrusion

New npm Malware Campaign Redirects Victims to Crypto Sites

RondoDox Botnet Malware Now Hacks Servers Using XWiki Flaw

Fortinet Warns of New FortiWeb Zero-Day Exploited in Attacks

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

Microsoft: Windows 10 KB5072653 OOB Update Fixes ESU Install Errors

Bug Bounty Programs Rise as Key Strategic Security Solutions

11/17/2025

Pentagon and Soldiers Let Too Many Secrets Slip on Social Networks, Watchdog Says

Hackers Steal Maternity Ward CCTV Videos in India Cybercrime Racket

Google Is Collecting Troves of Data From Downgraded Nest Thermostats

X Launches Chat, Its New Encrypted DMs

UK Twitter Hacker Who Breached Obama’s Account Ordered to Repay $5.4 Million in Bitcoin

Govini Founder Eric Gillespie’s Lawyer Calls Child Sex Chat ‘Internet Fantasy,’ Not a Crime

Dutch Police Seizes 250 Servers Used by “Bulletproof Hosting” Service

Kamel Ghali on What’s ‘Theoretically Possible’ in Car Hacking
Kenyan Gov’t Websites Back Online After Hackers Deface Pages With White Supremacist Messages

Princeton University Discloses Data Breach Affecting Donors, Alumni

Pennsylvania AG Confirms Data Breach After INC Ransom Attack

Eurofiber France Warns of Breach After Hacker Tries to Sell Customer Data

DoorDash Email Spoofing Vulnerability Sparks Messy Disclosure Dispute

‘Largest-Ever’ Cloud DDoS Attack Pummels Azure With 3.64b Packets per Second

New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

11/14-16/2025

U.S. Announces New Strike Force Targeting Chinese Crypto Scammers

Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

Anthropic Claims of Claude AI-Automated Cyberattacks Met With Doubt

Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns

Google to Flag Android Apps With Excessive Battery Use on the Play Store

Google Backpedals on New Android Developer Registration Rules

Civil Society Decries Digital Rights ‘Rollback’ as European Commission Pushes Data Protection Changes

DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound

Suspected Russian Hacker Reportedly Detained in Thailand, Faces Possible U.S. Extradition

Five Plead Guilty to Helping North Koreans Infiltrate U.S. Firms

Uncertain Economy Takes Toll on Cybersecurity Teams

CISO Pay Increases 7% As Budget Growth Slows
FBI Flags Scam Targeting Chinese Speakers With Bogus Surgery Bills

Cyberattack on Russian Port Operator Aimed to Disrupt Coal, Fertilizer Shipments

DoorDash Hit by New Data Breach in October Exposing User Information

Checkout.com Snubs Hackers After Data Breach, to Donate Ransom Instead

Logitech Leaks Data After Zero-Day Attack

Decades-Old ‘Finger’ Protocol Abused in ClickFix Malware Attacks

Kraken Ransomware Benchmarks Systems for Optimal Encryption Choice

CISA Warns of Akira Ransomware Linux Encryptor Targeting Nutanix VMs

Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts

ASUS Warns of Critical Auth Bypass Flaw in DSL Series Routers

Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

Krebs: Microsoft Patch Tuesday, November 2025 Edition

Microsoft: Windows 10 KB5068781 ESU Update May Fail With 0x800f0922 Errors

11/13/2025

Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks

U.S. Dismisses Chinese Accusation of Extensive LuBian Mining Pool Hack

Two Key Cyber Laws Are Back as President Trump Signs Bill to End Shutdown

Microsoft Rolls Out Screen Capture Prevention for Teams Users

Google Will Let ‘Experienced Users’ Keep Sideloading Android Apps

Krebs: Google Sues to Disrupt Chinese SMS Phishing Triad

Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown

FBI: Akira Gang Has Received Nearly $250 Million in Ransoms

NHS Supplier Ends Probe Into Ransomware Attack That Contributed to Patient Death

Kazakhstan Becomes Latest Country to Ban ‘LGBT Propaganda’ Online

Kenya Kicks Off ‘Code Nation’ With a Nod to Cybersecurity

Orgs Move to SSO, Passkeys to Solve Bad Password Habits
Washington Post Data Breach Impacts Nearly 10K Employees, Contractors

Popular Android-Based Photo Frames Download Malware on Boot

Phishing Campaign Targets Customers of Major Italian Web Hosting Provider

Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data

Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain

“IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages

Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack

RCE Flaw in ImunifyAV Puts Millions of Linux-Hosted Sites at Risk

CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks

CISA Warns Feds to Fully Patch Actively Exploited Cisco Flaws

Ubuntu 25.10’s Rusty Sudo Holes Quickly Welded Shut

11/12/2025

Australia at Risk of ‘High-Impact Sabotage’ From China, Says Spy Chief

UK Plans Tougher Laws to Protect Public Services From Cyberattacks

British Government Unveils Long-Awaited Landmark Cybersecurity Bill

Army Officer With Indo-Pacific Experience Emerges as Potential Cyber Command, NSA Pick

U.S. Announces ‘Strike Force’ to Counter Southeast Asian Cyber Scams, Sanctions Myanmar Armed Group

Lighthouse: This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

German Extremist Arrested Over Operating Alleged Darknet Assassination Marketplace

DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules
Synnovis Notifies of Data Breach After 2024 Ransomware Attack

DanaBot Malware Is Back to Infecting Windows After 6-Month Break

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Windows 11 Now Supports 3rd-Party Apps for Native Passkey Management

Cybersecurity Firm Deepwatch Lays off Dozens, Citing Move to ‘Accelerate’ AI Investment

Bridging the Skills Gap: How Military Veterans Are Strengthening Cybersecurity

Russia Imposes 24-Hour Mobile Internet Blackout for Travelers Returning Home

Rhadamanthys Infostealer Disrupted as Cybercriminals Lose Server Access

11/10-11/2025

China-Aligned UTA0388 Uses AI Tools in Global Phishing Campaigns

Android Devices Targeted By KONNI APT in Find Hub Exploitation

CISA Orders Feds to Patch Samsung Zero-Day Used in Spyware Attacks

UK Asks Cyberspies to Probe Whether Chinese Buses Can Be Switched off Remotely

China Accuses U.S. of Orchestrating $13 Billion Bitcoin Hack

America’s Cybersecurity Defenses Are Cracking

Shutdown Deal Would Revive Cyber Intelligence-Sharing Bill

EU’s Reforms of GDPR, AI Slated by Privacy Activists for ‘Playing Into Big Tech’s Hands’

Yanluowang Initial Access Broker Pleaded Guilty to Ransomware Attacks

“Bitcoin Queen” Gets 11 Years in Prison for $7.3 Billion Bitcoin Scam

Mozilla Firefox Gets New Anti-Fingerprinting Defenses

Data Privacy Whistleblowers Would Get Expanded Protections Under California Proposal

Former Trump Official Named NSO Group Executive Chairman

Microsoft Releases KB5068781 — The first Windows 10 Extended Security Update
Hitachi-Owned GlobalLogic Admits Data Stolen on 10K Current and Former Staff

Wakefield & Associates (TN) Announces Breach of Client Data

Qilin Ransomware Activity Surges as Attacks Target Small Businesses

Quantum Route Redirect PhaaS Targets Microsoft 365 Users Worldwide

WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks

Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware

Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers

Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories

Hackers Exploit Critical Flaw in Gladinet’s Triofox File Sharing Product

Popular JavaScript Library Expr-Eval Vulnerable to RCE Flaw

SAP Fixes Hardcoded Credentials Flaw in SQL Anywhere Monitor

Synology Fixes BeeStation Zero-Days Demoed at Pwn2Own Ireland

Microsoft November 2025 Patch Tuesday Fixes 1 Zero-Day, 63 Flaws