12/30-31/2025

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

Finland Seizes Ship Suspected of Damaging Subsea Cable in Baltic Sea

Washington Wants to Get Tough on Nation-State Hackers. Are Infrastructure Operators Ready?

Fears Mount That U.S. Federal Cybersecurity Is Stagnating—Or Worse

Two Cybersecurity Employees Plead Guilty to Carrying Out Ransomware Attacks

Meta Created ‘Playbook’ to Fend Off Pressure to Crack Down on Scammers, Documents Show

Hong Kong’s Newest Anti-Scam Technology: Over-The-Counter Banking

New York’s Incoming Mayor Zohran Mamdani Bans Raspberry Pi at His Inauguration Party

And Flipper Zero

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

Disney Will Pay $10 Million to Settle Children’s Data Privacy Lawsuit

Coupang to Split $1.17 Billion Among 33.7 Million Data Breach Victims
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

European Space Agency Hit Again as Cybercrims Claim 200 GB Data up for Sale

Hackers Drain $3.9M From Unleash Protocol After Multisig Hijack

DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide

Zoom Stealer Browser Extensions Harvest Corporate Meeting Intelligence

New ERRTraffic Service Enables ClickFix Attacks via Fake Browser Glitches

Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry

RondoDox Botnet Exploits React2Shell Flaw to Breach Next.js Servers

US, Australia Say ‘MongoBleed’ Bug Being Exploited

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass

12/29/2025

The Worst Hacks of 2025

Happy 16th Birthday, KrebsOnSecurity.com!

Indian Cops Cuff Ex-Coinbase Rep Over Selling Customer Info to Crims

Hacker Arrested for KMSAuto Malware Campaign with 2.8 Million Downloads

Accused Data Thief Threw MacBook Into a River to Destroy Evidence
Korean Air Data Breach Exposes Data of Thousands of Employees

Romanian Energy Provider Oltenia Energy Complex Hit by Gentlemen Ransomware Attack

Two More Banks Notifying Thousands of Victims About Marquis Software Ransomware Attack

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

12/26-28/2025

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

The U.S. Must Stop Underestimating Drone Warfare

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

Death, Torture, and Amputation: How Cybercrime Shook the World in 2025

From Video Games to Cyber Defense: If You Don’t Think Like a Hacker, You Won’t Win

Coupang Founder Kim Bom Apologises for Data Leak, Pledges Compensation

Shaping the Next Generation of Cyber Experts
Trust Wallet Users Lose $7 Million to Hacked Chrome Extension

Fake GrubHub Emails Promise Tenfold Return on Sent Cryptocurrency

Ubisoft Shuts Down ‘Rainbow Six Siege’ Servers Following Hack

Hacker Claims to Leak WIRED Database with 2.3 million Records

Everest Ransomware Group Claims Theft of Over 1TB of Chrysler Data

Exploited MongoBleed Flaw Leaks MongoDB Secrets, 87K Servers Exposed

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

12/25/2025

Why Hackers Love the Holidays, Especially Christmas and the Like

OpenAI is Reportedly Testing Multiple Claude-Like Skills For ChatGPT

Study Reveals Businesses Continue to Underinvest in Cybersecurity and are Neglect in Vulnerability Assessments

The Biggest Cybersecurity Mergers and Acquisitions of 2025
Somerset County (PA) Utilizing New 911 Alert System After Cyber Attack

Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

12/24/2025

Pro-Russian Hackers Noname057 Claim Cyberattack on French Postal Service

NIST, MITRE Partner on $20m AI Centers For Manufacturing and Cybersecurity

The Age of the All-Access AI Agent Is Here

Pen Testers Accused of ‘Blackmail’ After Reporting Eurostar Chatbot Flaws

All I Want for Christmas Is Not a Scam – Tips to Avoid Digital Threats During the Festive Season
AI Powered Cyber Attack Hits Chinese TikTok Short Video Rival Kuaishou

Coordinated Scams Target MENA Region Extensively With Fake Online Job Ads

Fake MAS Windows Activation Domain Used to Spread PowerShell Malware

MongoDB Warns Admins to Patch Severe RCE Flaw Immediately

Cyber Volunteer Effort for Small Water Utilities Announces New MSSP Effort

12/23/2025

86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush

Dozens of Flock AI Camera Feeds Were Just Out There

FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks

Chinese Crypto Scammers on Telegram Are Fueling the Biggest Darknet Markets Ever

SEC Sues Crypto Firms for Defrauding Investors Out of $14 Million

U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

NYPD Sued Over Possible Records Collected Through Muslim Spying Program

Italy Fines Apple $116 Million Over App Store Privacy Policy Issues
More Than 22 Million Aflac Customers Impacted by June Data Breach

Baker University (KS) Says 2024 Data Breach Impacts 53,000 People

Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

WebRAT Malware Spread via Fake Vulnerability Exploits on Github

Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

Microsoft Rolls Out Hardware-Accelerated BitLocker in Windows 11

A Cybersecurity Playbook for AI Adoption

ServiceNow Opens $7.7b Ticket Titled ‘Buy Security Company, Make It Armis’

12/22/2025

Cyber Spies Use Fake New Year Concert Invites to Target Russian Military

Romanian Water Authority Hit by BitLocker Ransomware Attack Over Weekend

Hacktivists Scrape 86M Spotify Tracks, Claim Their Aim Is to Preserve Culture

Microsoft Windows ‘Hack Your Own Password’ Attack Warning Issued

South Korea to Require Facial Recognition for New Mobile Numbers

Judge Rules That NSO Cannot Continue to Install Spyware via WhatsApp Pending Appeal

Interpol-Led Action Decrypts 6 Ransomware Strains, Arrests Hundreds

Nefilim Ransomware Affiliate Pleads Guilty
France’s National Post Office Hit by Suspected Cyber-Attack, Delaying Deliveries

University of Phoenix Data Breach Impacts Nearly 3.5 Million Individuals

Nissan Says Thousands of Customers Exposed in Red Hat Breach

Scripted Sparrow Sends Millions of BEC Emails Each Month

Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

New MacSync Malware Dropper Evades macOS Gatekeeper Checks

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access

12/19-21/2025

Inquiry Ongoing After UK Government Hacked, Says Minister

Firms Warned to Be On ‘High Alert’ for Scam Emails

Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence

Russian Defense Firms Targeted by Hackers Using AI, Other Tactics

Trump Signs Defense Bill Allocating Millions for Cyber Command, Mandating Pentagon Phone Security

Senate Confirms New Pentagon CIO

Krebs on Dismantling Defenses: Trump 2.0 Cyber Year in Review

Here’s What’s in the DOJ’s Epstein Files Release—And What’s Missing

U.S. Charges 54 in Massive ATM Jackpotting Conspiracy

Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

Ex-Michigan Assistant Matt Weiss Seen on Video Hacking Into Student Accounts, Security Footage Reveals
Hacks, Thefts, and Disruption: The Worst Data Breaches of 2025

Richmond Behavioral Health Authority (VA) Breach Hits Over 113K

Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware

RansomHouse Upgrades Encryption With Multi-Layered Data Processing

How RomCom Became a Multipurpose Cyberweapon

WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

Over 25,000 FortiCloud SSO Devices Exposed to Remote Attacks

New UEFI Flaw Enables Pre-Boot Attacks on Motherboards from Gigabyte, MSI, ASUS, ASRock

Docker Hardened Images Now Open Source and Available for Free

Palo Alto Networks Announces Multibillion-Dollar Deal With Google Cloud

FTC: Instacart to Refund $60M Over Deceptive Subscription Tactics

12/18/2025

Denmark Says Russia Was Behind Two ‘Destructive and Disruptive’ Cyber-Attacks

LongNosedGoblin: China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware

New BeaverTail Malware Variant Linked to Lazarus Group

Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

North Korea Steals Over $2bn in Crypto in 2025

Amazon Blocked 1,800 Suspected North Korean Scammers Seeking Jobs

Haotian: The Ultra-Realistic AI Face Swapping Platform Driving Romance Scams

France Arrests Latvian for Installing Malware on Italian Ferry

Austria’s High Court Orders Meta to Change Its Personalized Ad Practices

Pa. High Court Rules That Police Can Access Google Searches Without a Warrant
Tech Provider for NHS England DXS International Confirms Data Breach

University of Sydney Suffers Data Breach Exposing Student and Staff Info

HMRC Warns of Over 135,000 Scam Reports

OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365

Clop Ransomware Targets Gladinet Centrestack in Data Theft Attacks

Your Car’s Web Browser May Be On the Road to Cyber Ruin

New Password Spraying Attacks Target Cisco, PAN VPN Gateways

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

BlackBerry Lifts Lower End of Annual Revenue Forecast on Cybersecurity Demand

12/17/2025

Chinese Ink Dragon Group Hides in European Government Networks

APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign

New Spyware Discovered on Belarusian Journalist’s Phone After Interrogation

Former Israeli Prime Minister Bennett’s Telegram Hacked, Not Phone, Despite Iranian Group’s Claims

Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks

Border Patrol Bets on Small Drones to Expand U.S. Surveillance Reach

Trump Targets Defense Giants’ Shareholder Payouts as Cost Overruns Mount, Sources Say

Blockchain Company Nomad to Repay Users Under FTC Deal After $186M Cyberattack

FBI Takes Down Alleged Money Laundering Service for Ransomware Groups

France Arrests Suspect Tied to Cyberattack on Interior Ministry

TikTok Tracked User’s Grindr Activity in Violation of European Law, Rights Group Alleges

Privacy Advocates See Risk in New Meta Policy That Uses AI Chats to Serve Targeted Ads
U.S. Autoparts Maker LKQ Confirms Oracle EBS Breach

New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Critical React2Shell Flaw Exploited in Ransomware Attacks

Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks

Cellik Android Malware Builds Malicious Versions From Google Play Apps

WhatsApp Device Linking Abused in Account Hijacking Attacks

New “Lies-in-the-Loop” Attack Undermines AI Safety Dialogs

Motors WordPress Vulnerability Exposes Sites to Takeover

Cisco Warns of Unpatched AsyncOS Zero-Day Exploited in Attacks

SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances

Zeroday Cloud Hacking Event Awards $320,0000 for 11 Zero Days

Think Like an Attacker: Cybersecurity Tips From a CISO

Roblox in Talks With Russia to Restore Access After Platform Ban Sparks Backlash

12/16/2025

Amazon Warns Russian GRU Hackers Target Western Firms via Edge Devices

Cyberattack Disrupts Venezuelan Oil Giant PDVSA’s Operations

Venezuela State Oil Company Blames Cyberattack on U.S. After Tanker Seizure

House Homeland Security Chairman Keeps Attention on Cyber Issues

Senior Official at Indo-Pacific Command Is Set to Be Trump’s Pick to Lead Cyber Command, NSA

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

Phishing Messages and Social Scams Flood Users Ahead of Christmas

Krebs: Most Parked Domains Now Serving Malicious Content

European Authorities Dismantle Call Center Fraud Ring in Ukraine

Still Using Windows 10? You’re a Prime Target for Ransomware Now – Unless You Do This
Hacking Group ‘ShinyHunters’ Threatens to Expose Premium Users of Sex Site PornHub

Analytics Provider Mixpanel: We Didn’t Expose You to Crims

City of Westminster (SC) Missing Public Funds After Cyber Attack, Officials Say

Madison Healthcare (MN) Confirms Data Breach After Ransomware Attack

Urban VPN Proxy Accused of Harvesting AI Chat Conversations

GhostPoster Attacks Hide Malicious JavaScript in Firefox Addon Logos

Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

JumpCloud Windows Agent Flaw Enables Local Privilege Escalation

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

12/15/2025

Suspected Russian Hackers Step Up Attacks on U.S. Energy Firms, Research Shows

German Parliament Suffers Suspected Cyber Attack During Zelenskyy’s Visit

French Interior Ministry Confirms Cyberattack on Email Servers

Google Links More Chinese Hacking Groups to React2Shell Attacks

MI6 Chief Warns ‘Front Line Is Everywhere’ and Signals Intent to Pressure Putin

U.S. Government Launches Campaign to Hire Engineers for AI, Tech Roles

Starlink Claims Chinese Launch Came Within 200 Meters of Broadband Satellite

Google’s Turning off Its Dark Web Monitoring Service That Scoured Data Breaches for Your Info

Texas Sues 5 Smart TV Manufacturers Over Data Collection Practices

Third Defendant Pleads Guilty in Fantasy Sports Betting Hack Case

Vibe Coding: Innovation Demands Vigilance
700Credit Data Breach Impacts 5.8 Million Vehicle Dealership Customers

Nearly 20 Million Affected by Prosper, 700Credit Data Breaches

Askul Confirms Theft of 740K Customer Records in Ransomware Attack

PornHub Extorted After Hackers Steal Premium Member Activity Data

More Than 238K Hit by Akira-Claimed Fieldtex Product Hack

Ongoing SoundCloud Issue Blocks VPN Users With 403 Server Error

SoundCloud Confirms Breach After Member Data Stolen, VPN Access Disrupted

Russian Phishing Campaign Delivers Phantom Stealer Via ISO Files

New SantaStealer Malware Steals Data From Browsers, Crypto Wallets

Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE

12/12-14/2025

React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation

Germany Summons Russian Ambassador Over Cyberattack, Election Disinformation

Announced Pick for No. 2 at NSA Won’t Get the Job as Another Candidate Surfaces

Trump Order on AI May Not Deter State Laws

AI Toys for Kids Talk About Sex and Issue Chinese Communist Party Talking Points, Tests Show

U.S. Bill Seeks Phase-Out of Chinese Sensors in Self-Driving Cars, After Space Hack Fears

ServiceNow in Talks to Acquire Cybersecurity Startup Armis in Potential $7 Billion Deal

Uncle Sam Sues Ex-Accenture Manager Over Army Cloud Security Claims

Coupang Data Breach Traced to Ex-Employee Who Retained System Access

MKVCinemas Streaming Piracy Service With 142M Visits Shuts Down

Canada’s Privacy Regulator to Probe Billboards Equipped With Facial Scanning Tech

Streisand Effect: Businesses That Pay Ransomware Gangs Are More Likely to Hit the Headlines

CyberVolk’s Ransomware Debut Stumbles on Cryptography Weakness
More Than 340,000 Impacted by Cyberattack on Library System of Pierce County (WA)

Hamas-Affiliated APT Targeting Government Agencies in the Middle East, Morocco

Beware: PayPal Subscriptions Abused to Send Fake Purchase Emails

Fake ‘One Battle After Another’ Torrent Hides Malware in Subtitles

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads

New React RSC Vulnerabilities Enable DoS and Source Code Exposure

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks

New Windows RasMan Zero-Day Flaw Gets Free, Unofficial Patches

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

MITRE Shares 2025’s Top 25 Most Dangerous Software Weaknesses

Kali Linux 2025.4 Released With 3 New Tools, Desktop Updates

12/11/2025

Hackers Reportedly Breach Developer Involved With Russia’s Military Draft Database

OpenAI Enhances Defensive Models to Mitigate Cyber-Threats

Google Ads for Shared ChatGPT, Grok Guides Push macOS Infostealer Malware

Russian Hackers Debut Simple Ransomware Service, but Store Keys in Plain Text

Lawmaker Calls Facial Recognition on Doorbell Cameras a ‘Privacy Nightmare’

Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data

LastPass Hammered With £1.2M Fine for 2022 Breach Fiasco

Federal Agencies Now Only Have One More Day to Patch React2Shell Bug
Data Breach at 700Credit Impacts 160,000 Michiganders

WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor

New ConsentFix Attack Hijacks Microsoft Accounts via Azure CLI

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems

Malware Discovered in 19 Visual Studio Code Extensions

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw

Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks

Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution

Notepad++ Fixes Flaw That Let Attackers Push Malicious Update Files

12/10/2025

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

U.S. Says Russia-Backed Hacks Targeted Critical Infrastructure

U.S. Extradites Ukrainian Woman Accused of Hacking Meat Processing Plant for Russia

2 Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’

U.S. Halts Plans to Sanction Chinese Spy Agency

British Government Sanctions Russian and Chinese Groups Over Information Warfare

OpenAI Warns New Models Pose ‘High’ Cybersecurity Risk

Log4Shell Downloaded 40 Million Times in 2025

Nvidia Builds Location Verification Tech That Could Help Fight Chip Smuggling

Coupang CEO Resigns Over Data Breach in South Korea

Senators Return to Effort to Boost Cybersecurity for Commercial Satellite Industry

Coalition Adds Deepfake Response to Cyber Insurance Policies Globally
Petco Takes Down Vetco Website After Exposing Customers’ Personal Information

Russia’s Flagship Airline Aeroflot Hacked Through Little-Known Tech Vendor Bakka Soft, According to New Report

ClickFix Social Engineering Sparks Rise of CastleLoader Attacks

New Spiderman Phishing Service Targets Dozens of European Banks

New DroidLock Malware Locks Android Devices and Demands a Ransom

Over 10,000 Docker Hub Images Found Leaking Credentials, Auth Keys

Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups

.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling

Google Fixes Zero Click Gemini Enterprise Flaw That Exposed Corporate Data

Microsoft Teams to Warn of Suspicious Traffic With External Domains

12/9/2025

React2Shell Exploit Campaigns Tied to North Korean Cyber Intrusion Tactics

Deploy New EtherRAT Malware

Gartner Calls For Pause on AI Browser Use

Analysts Warn of Cybersecurity Risks in Humanoid Robots

How to Answer the Door When the AI Agents Come Knocking

Trump Plans Executive Order Curbing State AI Law

Cyber Startup Saviynt Raises $700 Million to Secure Identity and Access

California Man Pleads Guilty to Rico Charges as DOJ Indicts Crypto Theft Gang

Spain Arrests Teen Who Stole 64 Million Personal Data Records

Seoul Cyber Investigators Seize Data, Devices From ‘South Korea’s Amazon’ Following Data Breach

Khashoggi Widow Files Complaint in France Alleging Saudi Government Infected Devices With Spywares
Space Bears Ransomware Claims Comcast Data Breach via Contractor Quasar Inc.

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading

STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware

DeadLock Ransomware Uses BYOVD to Evade Security Measures

Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data

Fortinet Warns of Critical FortiCloud SSO Login Auth Bypass Flaws

Ivanti Warns of Critical Endpoint Manager Code Execution Flaw

SAP Fixes Three Critical Vulnerabilities Across Multiple Products

Krebs: Microsoft Patch Tuesday, December 2025 Edition

Windows PowerShell Now Warns When Running Invoke-WebRequest Scripts

12/8/2025

MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign

Three Hacking Groups, Two Vulnerabilities and All Eyes on China

U.S. to Allow Nvidia H200 Chip Shipments to China, Trump Says

Meta Proposal for Less Data Sharing Is Approved by European Commission

UK Moves to Strengthen Undersea Cable Defenses as Russian Snooping Ramps Up

Home Office Kept Police Facial Recognition Flaws to Itself, UK Data Watchdog Fumes

Poland Arrests Ukrainians Utilizing ‘Advanced’ Hacking Equipment

193 Cybercrims Arrested, Accused of Plotting ‘Violence-As-A-Service’

Russian Police Bust Bank-Account Hacking Gang That Used NFCGate-Based Malware

Russian Kids Revolt as Kremlin Bans Roblox, Other Popular Apps
Researchers Track Dozens of Organizations Affected by React2Shell Compromises Tied to China’s MSS

Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT

Malicious VSCode Extensions on Microsoft’s Registry Drop Infostealers

Ransomware Gangs Turn to Shanya EXE Packer to Hide EDR Killers

ClayRat Android Spyware Expands Capabilities

Malware Families FvncBot, and SeedSnatcher Too

Total Ransomware Payments Surpass $4.5 Billion Since 2013

Over $2.1B From 2022 To 2024

Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks

UK Intelligence Warns AI ‘Prompt Injection’ Attacks Might Never Go Away

12/5-7/2025

China-Linked Warp Panda Targets North American Firms in Espionage Campaign

Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

React2Shell Flaw Exploited to Breach 30 Orgs, 77K IP Addresses Vulnerable

Cloudflare Restores Services After Minor Dashboard Outage

Cloudflare Blames Today’s Outage on react2shell Mitigations

Krebs: SMS Phishers Pivot to Points, Taxes, Fake Retailers

Krebs: Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

Crims Using Social Media Images, Videos in ‘Virtual Kidnapping’ Scams

Louvre to Bolster Its Security, Issues €57m Public Tender

Portugal Updates Cybercrime Law to Exempt Security Researchers

Maryland Man Sentenced for N. Korea IT Worker Scheme Involving U.S. Government Contracts

EU Fines X $140 Million Over Deceptive Blue Checkmarks

SolarWinds’ Tim Brown Escaped the SEC. Future Cyber Chiefs Might Not.
Pharma Firm Inotiv Discloses Data Breach After Ransomware Attack

Barts Health NHS Discloses Data Breach After Oracle Zero-Day Hack

Huge Trove of Nude Images Leaked by AI Image Generator Startup’s Exposed Database

New Wave of VPN Login Attempts Targets Palo Alto GlobalProtect Portals

Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails

Novel Clickjacking Attack Relies on CSS and SVG

Hackers are Exploiting ArrayOS AG VPN Flaw to Plant Webshells

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch

NCSC’s ‘Proactive Notifications’ Warns Orgs of Flaws in Exposed Devices

Death to One-Time Text Codes: Passkeys Are the New Hotness in MFA

A Tale of Two CISOs: Why An Engineering-Focused CISO Can Be a Liability

12/4/2025

Amid Rising Threats, NATO Holds Its Largest-Ever Cyberdefense Exercise

Twins Who Hacked State Dept Hired to Work for Gov Again, Now Charged With Deleting Databases

UK Sanctions Russia’s GRU Agency and Cyber Spies Over Deadly Nerve Agent Attack

FBI Says DC Pipe Bomb Suspect Brian Cole Kept Buying Bomb Parts After January 6

Pentagon’s Signalgate Report Finds Pete Hegseth Violated Military Policies

Taiwan to Ban China’s Xiaohongshu App for One Year on Fraud Concerns

A New Anonymous Phone Carrier Lets You Sign Up With Nothing but a Zip Code

British Officials Seek to Expand Facial Recognition Technology Use

Cybersecurity Startup 7AI Raises $130 Million in Series A Funding

I Saw Drone Deliveries Launch in Atlanta – How They Work and Which Cities Are Next
CISA Warns of Chinese “BrickStorm” Malware Attacks on VMware Servers

Predator Spyware Uses New Infection Vector for Zero-Click Attacks

Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China

GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

New GhostFrame Phishing Framework Hits Over One Million Attacks

Critical React, Next.js Flaw Lets Hackers Execute Code on Servers

CISA and International Partners Issue Guidance for Secure AI in Infrastructure

Russia Blocks FaceTime and Snapchat for Alleged Use by Terrorists

Russian Scientist Sentenced to 21 Years on Treason, Cyber Sabotage Charges

12/3/2025

French NGO Reporters Without Borders Targeted by Star Blizzard

Disinformation and Cyber-Threats Among Top Global Business Exec Concerns

‘Exploitation Is Imminent’ as 39 Percent of Cloud Environs Have Max-Severity React Hole

UK Ransomware Payment Ban to Come with Exemptions, Security Minster Say

India Revokes Order to Preload Cybersecurity App on Smartphones After Outcry

FDA Scrutiny of WHOOP Signals Challenges for Niche Wearable Device Makers

Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

Security Startup Verkada Hits $5.8 Billion Valuation in Latest Funding Round Led by CapitalG

How Amazon Finds Its Cybersecurity Weak Spots

Russia Blocks Roblox Over Distribution of LGBT “Propaganda”

Google Expands Android Scam Protection Feature to Chase, Cash App in U.S.

DOJ Takes Down Myanmar Scam Center Website Spoofing TickMill Trading Platform

Canadian Police Department Becomes First to Trial Body Cameras Equipped With Facial Recognition Technology
French DIY Retail Giant Leroy Merlin Discloses a Data Breach

University of Phoenix Discloses Data Breach After Oracle Hack

Japan’s Askul Resumes Limited Online Sales 6 Weeks After Ransomware Attack

ASUS Listed by Everest Ransomware Group, 1 TB Data Stolen

Freedom Mobile Discloses Data Breach Exposing Customer Data

Fintech Firm Marquis Alerts Dozens of U.S. Banks and Credit Unions of a Data Breach After Ransomware Attack

Impacts Over 74 U.S. Banks, Credit Unions

Yearn Finance yETH Pool Hit by $9M Exploit

Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud

Aisuru Botnet Behind New Record-Breaking 29.7 Tbps DDoS Attack

Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

12/1-2/2025

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

ShadyPanda’s Seven-Year Campaign Infects 4.3M Chrome and Edge Users

Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks

Officials Accuse North Korea’s Lazarus of $30 Million Theft From Crypto Exchange

Most Companies Fear State-Sponsored Cyber-Attacks and Want More Government Help

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

Flock Uses Overseas Gig Workers to Build its Surveillance AI

Former Cyber Spy Raises $60 Million to Fight AI Threats

CrowdStrike Forecasts Upbeat Quarterly Revenue as AI Adoption Fuels Growth

Okta Projects Strong Quarterly Revenue on Rising Demand for Cybersecurity Tools

Axiado Raises $100 Million for Chip to Save Space, Power in AI Data Centers

Your Data Might Determine How Much You Pay for Eggs

ICO Set to Check If Mobile Games Comply with Children’s Code

FTC Settlement Requires Illuminate to Delete Unnecessary Student Data

Korea Arrests Suspects Selling Intimate Videos From Hacked IP Cameras

Europol Nukes Cryptomixer Laundering Hub, Seizing €25M in Bitcoin
India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud

Faces Backlash

ChatGPT Is Down Worldwide, Conversations Dissapeared for Users

Microsoft Defender Portal Outage Disrupts Threat Hunting Alerts

Google Deletes X Post After Getting Caught Using a ‘Stolen’ AI Recipe Infographic

University of Pennsylvania Joins List of Victims From Clop’s Oracle EBS Raid

Shai-Hulud 2.0 NPM Malware Attack Exposed Up To 400,000 Dev Secrets

Southold (NY) Police Are Reporting With Pen and Paper After Cyber Attack

Fake Calendly Invites Spoof Top Brands to Hijack Ad Manager Accounts

SmartTube YouTube App for Android TV Breached to Push Malicious Update

Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

New Android Albiriox Malware Gains Traction in Dark Web Markets

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

Critical PickleScan Vulnerabilities Expose AI Model Supply Chains

Google Releases Patches for Android Zero-Day Flaws Exploited in the Wild

11/27-30/2025

Bloody Wolf Threat Actor Expands Activity Across Central Asia

North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware

Chinese Cyberattack Campaign Likely Impacted Every American, Former FBI Official Says

Critical New FBI Warning: This Simple Hack Can Empty Your Bank Account

Poems Can Trick AI Into Helping You Make a Nuclear

Malicious LLMs Empower Inexperienced Hackers With Advanced Tools

Threat Actors Exploit Calendar Subscriptions for Phishing and Malware Delivery

FCC Warns of Hackers Hijacking Radio Equipment For False Alerts

The Wired Guide to Digital OPSEC for Teens

Three Black Friday Scams to Watch Out For This Year

TryHackMe Races to Add Women to Christmas Cyber Challenge Roster After Backlash

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

GrapheneOS Bails on OVHcloud Over France’s Privacy Stance

Man Behind In-Flight Evil Twin WiFi Attacks Gets 7 Years in Prison

Poland Arrested Suspected Russian Citizen for Hacking Local Organizations’ Computer Networks

GreyNoise Launches Free Scanner to Check if You’re Part of a Botnet
Asahi Confirms 1.5 Million Customers Affected in Major Cyber-Attack

Top South Korean E-Commerce Firm Coupang Apologises Over Massive Data Breach

Korean Web Giant Naver Acquired Crypto Exchange Upbit, Which Reported a $30M Heist a Day Later

French Football Federation Suffers Data Breach

Brit Telco Brsk Confirms Breach as Bidding Begins for 230K+ Customer Records

Data Copied in Kensington and Chelsea Cyber Attack

At Least 35,000 Impacted by Dartmouth College Breach Through Oracle EBS Campaign

Computer Services Impacted After Ransomware Attack Hits Golf Manor (OH)

OpenAI Warns of Mixpanel Data Breach Impacting API Users

Public GitLab Repositories Exposed More Than 17,000 Secrets

PostHog Admits Shai-Hulud 2.0 Was Its Biggest Ever Security Bungle

Scattered Lapsus$ Hunters Take Aim At Zendesk Users

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

California Law Regulating Web Browsers Could Have National Data Privacy Impact, Experts Say

11/26/2025

Bug in Jury Systems Used by Several U.S. States Exposed Sensitive Personal Data

New ShadowV2 Botnet Malware Used AWS Outage as a Test Opportunity

Gainsight CEO Downplays Breach, Says Only a ‘Handful’ of Customers Had Data Stolen

Krebs: Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’

The Destruction of a Notorious Myanmar Scam Compound Appears to Have Been ‘Performative’

House Energy and Commerce Committee Unveils New Draft Children’s Online Safety Bill
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware

Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps

Popular Forge Library Gets Fix for Signature Verification Bypass Flaw

ASUS Warns of New Critical Auth Bypass Flaw in AiCloud Routers

11/25/2025

CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users

FBI: Cybercriminals Stole $262M by Impersonating Bank Support Teams

Scammers Hacked Her Phone and Stole Thousands – So How Did They Get Her Details?

Crime Rings Enlist Hackers to Hijack Trucks

ICE Offers up to $280 Million to Immigrant-Tracking ‘Bounty Hunter’ Firms

HashJack Attack Shows AI browsers Can Be Fooled With a Simple ‘#’

Tor Switches to New Counter Galois Onion Relay Encryption Algorithm

The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals

Russia Arrests Young Cybersecurity Entrepreneur on Treason Charges
Multiple London Councils ‘Hit by Cyber-Attacks’

Georgia Court Filing Organization Warns of Outages After Ransomware Allegations

Clop’s Oracle EBS Rampage Reaches Dartmouth College

OnSolve CodeRED Cyberattack Disrupts Emergency Alert Systems Nationwide

Smishing Triad Impersonation Campaigns Expand Globally

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers

11/24/2025

Russian-Linked Malware Campaign Hides in Blender 3D Files

Hackers Knock Out Systems at Moscow-Run Postal Operator in Occupied Ukraine

Krebs: Is Your Android TV Streaming Box Part of a Botnet?

Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs

UK Privacy Regulator Has Seen ‘Collapse in Enforcement Activity,’ Rights Coalition Says

Software Companies Must Be Held Liable for British Economic Security, Say MPs

Comcast to Pay $1.5 Million U.S. Fine After Vendor Data Breach

This Hacker Conference Installed a Literal Antivirus Monitoring System

With AI Reshaping Entry-Level Cyber, What Happens to the Security Talent Pipeline?
Harvard University Discloses Data Breach Affecting Alumni, Donors

AI Nude Photo Link Appears on Kansas AG’s Website After Apparent Hack

Fresh ClickFix Attacks Use Windows Update Trick-Pics to Steal Credentials

Malicious Blender Model Files Deliver StealC Infostealing Malware

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access

Flaws Expose Risks in Fluent Bit Logging Agent

Amazon Is Using Specialized AI Agents for Deep Bug Hunting

Microsoft to Remove WINS Support after Windows Server 2025

11/21-23/2025

China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services

More Companies Are Shifting Workers to Passwordless Authentication

Google Enables Pixel-to-iPhone File Sharing via Quick Share, AirDrop

Press a Button and This SSD Will Self-Destruct With All Your Data

Russia-Linked Crooks Bought a Bank for Christmas to Launder Cyber Loot

Four Charged Over Alleged Plot to Smuggle Nvidia AI Chips Into China

‘Scattered Spider’ Teens Plead Not Guilty to UK Transport Hack

CrowdStrike Catches Insider Feeding Information to Hackers

Flock Safety Cameras Used to Monitor Protesters, Rights Group Finds

Google Begins Showing Ads in AI Mode (AI Answers)
A Swath of Bank Customer Data Was Hacked at Real Estate Technology Vendor SitusAMC. The FBI. Is Investigating

Wall Street Banks Scramble to Assess Fallout From Hack of Real-Estate Data Firm

Cox Enterprises Discloses Oracle E-Business Suite Data Breach

Iberia Discloses Customer Data Leak After Vendor Security Breach

Local Law Enforcement Agencies in Oklahoma, Massachusetts Responding to Cyber Incidents

ShinyHunters ‘Does Not Like Salesforce at All,’ Claims the Crew Accessed Gainsight 3 Months Ago

Matrix Push C2: Cybercriminals Exploit Browser Push Notifications to Deliver Malware

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability

11/20/2025

Google Exposes BadAudio Malware Used in APT24 Espionage Campaigns

Russia Blacklists S.T.A.L.K.E.R. Game Developer, Accusing It of Aiding Ukraine’s War Effort

With the Rise of AI, Cisco Sounds an Urgent Alarm About the Risks of Aging Tech

LLM-Generated Malware Is Improving, but Don’t Expect Autonomous Attacks Tomorrow

CISA Issues New Guidance on Bulletproof Hosting Threat

Krebs: Mozilla Says It’s Finally Done With Two-Faced Onerep

The FCC Is Rolling Back Steps Meant to Stop a Repeat of a Massive Telecom Hack

U.S. SEC Dismisses Case Against SolarWinds, Top Security Officer

NSO Seeks to Overturn Whatsapp Case, Saying It Is ‘Catastrophic’ for the Spyware Maker

Fired Techie Admits Sabotaging Ex-Employer, Causing $862K in Damage

Samourai Crypto Mixer Founders Sent to Prison for Laundering Over $237 Million

TV Streaming Piracy Service Photocall With 26M Yearly Visits Shut Down
Salesforce Investigates Customer Data Theft via Gainsight Breach

Salesforce-Linked Data Breach Claims 200+ Victims, Has ShinyHunters’ Fingerprints All Over It

Hacker Claims to Steal 2.3TB Data From Italian Rail Group, Almavia

GlobalProtect VPN Portals Probed with 2.3 Million Scan Sessions

UNC2891 Money Mule Network Reveals Full Scope of ATM Fraud Operation

TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows

New SonicWall SonicOS Flaw Allows Hackers to Crash Firewalls

D-Link Warns of New RCE Flaws in End-of-Life DIR-878 Routers

Lawmakers Reintroduce Bill to Bolster Cybersecurity at Securities and Exchange Commission

Privacy Oversight Board Finds FBI Does Not Buy Real-Time Location Data

11/19/2025

China-Linked Operation “WrtHug” Hijacks Thousands of ASUS Routers

Cloudflare Shows Internet Outages Aren’t a Matter of If — but When

Krebs: The Cloudflare Outage May Be a Security Roadmap

Airline Data Broker Airlines Reporting Corporation to Stop Selling Individuals’ Travel Records to Government Agencies

Vaping Is ‘Everywhere’ in Schools—Sparking a Bathroom Surveillance Boom

Half of Ransomware Access Due to Hijacked VPN Credentials

Russian Bulletproof Hosting Provider Sanctioned Over Ransomware Ties

California Man Admits to Laundering Crypto Stolen in $230M Heist

Coordinated Europol Operation Disrupts $55m in Cryptocurrency For Piracy

Palo Alto Tops Earnings Expectations, Announces Chronosphere Acquisition

What AI Bubble? Nvidia’s Strong Earnings Signal There’s More Room to Grow

Canadian Privacy Regulators Say Schools Share Blame for PowerSchool Hack
Major Russian Insurer VSK Facing Widespread Outages After Cyberattack

Email Breach at St. Anthony Hospital (IL) May Have Exposed the Information of More Than 6,600 People

Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime

PlushDaemon Hackers Unleash New Malware in China-Aligned Spy Campaigns

Meet ShinySp1d3r: New Ransomware-as-a-Service Created by ShinyHunters

EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

W3 Total Cache WordPress Plugin Vulnerable to PHP Command Injection

CISA Gives Gov’t Agencies 7 Days to Patch New Fortinet Flaw

Google Search Is Now Using AI to Create Interactive UI to Answer Your Questions

The AI Attack Surface: How Agents Raise the Cyber Stakes

Lawmakers Reintroduce Bill to Bolster Cybersecurity at Securities and Exchange Commission

11/18/2025

White House Goes on Cyber Offensive

CISA 2015 Receives Extension, Offering Brief Relief for Cyber Information Sharing

FCC Looks to Torch Biden-Era Cyber Rules Sparked by Salt Typhoon Mess

CBO Director Testifies That Hackers Have Been Expelled From Email Systems

MI5 Warns of Chinese Spies Using LinkedIn to Gain Intel on Lawmakers

Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks

A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

GenAI and Deepfakes Drive Digital Forgeries and Biometric Fraud

Microsoft Teams to Let Users Report Messages Wrongly Flagged as Threats

Microsoft Is Turning Windows Into an ‘Agentic OS,’ Starting With the Taskbar

Microsoft to Integrate Sysmon Directly Into Windows 11, Server 2025

Windows 11 Gets New Cloud Rebuild, Point-In-Time Restore Tools

Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This Year

Amazon, Google Named by EU Among ‘Critical’ Tech Providers for Finance Industry

Zoomers Are Officially Worse at Passwords Than 80-Year-Olds

Russian Suspect Detained in Thailand Is Allegedly Tied to Void Blizzard Group
Cloudflare Outage Disrupts X, ChatGPT and Other Parts of the Internet

Cloudflare Says Outage That Hit X, ChatGPT and Other Sites Is Resolved

Pro-Russian Group Claims Hits on Danish Party Websites as Voters Head to Polls

French Agency Pajemploi Reports Data Breach Affecting 1.2m People

LG Battery Subsidiary Says Ransomware Attack Targeted Overseas Facility

Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach

Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet

Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar

New ShadowRay Attacks Convert Ray Clusters Into Crypto Miners

Researchers Detail Tuoni C2’s Role in an Attempted 2025 Real-Estate Cyber Intrusion

New npm Malware Campaign Redirects Victims to Crypto Sites

RondoDox Botnet Malware Now Hacks Servers Using XWiki Flaw

Fortinet Warns of New FortiWeb Zero-Day Exploited in Attacks

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

Microsoft: Windows 10 KB5072653 OOB Update Fixes ESU Install Errors

Bug Bounty Programs Rise as Key Strategic Security Solutions

11/17/2025

Pentagon and Soldiers Let Too Many Secrets Slip on Social Networks, Watchdog Says

Hackers Steal Maternity Ward CCTV Videos in India Cybercrime Racket

Google Is Collecting Troves of Data From Downgraded Nest Thermostats

X Launches Chat, Its New Encrypted DMs

UK Twitter Hacker Who Breached Obama’s Account Ordered to Repay $5.4 Million in Bitcoin

Govini Founder Eric Gillespie’s Lawyer Calls Child Sex Chat ‘Internet Fantasy,’ Not a Crime

Dutch Police Seizes 250 Servers Used by “Bulletproof Hosting” Service

Kamel Ghali on What’s ‘Theoretically Possible’ in Car Hacking
Kenyan Gov’t Websites Back Online After Hackers Deface Pages With White Supremacist Messages

Princeton University Discloses Data Breach Affecting Donors, Alumni

Pennsylvania AG Confirms Data Breach After INC Ransom Attack

Eurofiber France Warns of Breach After Hacker Tries to Sell Customer Data

DoorDash Email Spoofing Vulnerability Sparks Messy Disclosure Dispute

‘Largest-Ever’ Cloud DDoS Attack Pummels Azure With 3.64b Packets per Second

New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

11/14-16/2025

U.S. Announces New Strike Force Targeting Chinese Crypto Scammers

Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

Anthropic Claims of Claude AI-Automated Cyberattacks Met With Doubt

Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns

Google to Flag Android Apps With Excessive Battery Use on the Play Store

Google Backpedals on New Android Developer Registration Rules

Civil Society Decries Digital Rights ‘Rollback’ as European Commission Pushes Data Protection Changes

DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound

Suspected Russian Hacker Reportedly Detained in Thailand, Faces Possible U.S. Extradition

Five Plead Guilty to Helping North Koreans Infiltrate U.S. Firms

Uncertain Economy Takes Toll on Cybersecurity Teams

CISO Pay Increases 7% As Budget Growth Slows
FBI Flags Scam Targeting Chinese Speakers With Bogus Surgery Bills

Cyberattack on Russian Port Operator Aimed to Disrupt Coal, Fertilizer Shipments

DoorDash Hit by New Data Breach in October Exposing User Information

Checkout.com Snubs Hackers After Data Breach, to Donate Ransom Instead

Logitech Leaks Data After Zero-Day Attack

Decades-Old ‘Finger’ Protocol Abused in ClickFix Malware Attacks

Kraken Ransomware Benchmarks Systems for Optimal Encryption Choice

CISA Warns of Akira Ransomware Linux Encryptor Targeting Nutanix VMs

Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts

ASUS Warns of Critical Auth Bypass Flaw in DSL Series Routers

Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

Krebs: Microsoft Patch Tuesday, November 2025 Edition

Microsoft: Windows 10 KB5068781 ESU Update May Fail With 0x800f0922 Errors

11/13/2025

Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks

U.S. Dismisses Chinese Accusation of Extensive LuBian Mining Pool Hack

Two Key Cyber Laws Are Back as President Trump Signs Bill to End Shutdown

Microsoft Rolls Out Screen Capture Prevention for Teams Users

Google Will Let ‘Experienced Users’ Keep Sideloading Android Apps

Krebs: Google Sues to Disrupt Chinese SMS Phishing Triad

Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown

FBI: Akira Gang Has Received Nearly $250 Million in Ransoms

NHS Supplier Ends Probe Into Ransomware Attack That Contributed to Patient Death

Kazakhstan Becomes Latest Country to Ban ‘LGBT Propaganda’ Online

Kenya Kicks Off ‘Code Nation’ With a Nod to Cybersecurity

Orgs Move to SSO, Passkeys to Solve Bad Password Habits
Washington Post Data Breach Impacts Nearly 10K Employees, Contractors

Popular Android-Based Photo Frames Download Malware on Boot

Phishing Campaign Targets Customers of Major Italian Web Hosting Provider

Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data

Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain

“IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages

Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack

RCE Flaw in ImunifyAV Puts Millions of Linux-Hosted Sites at Risk

CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks

CISA Warns Feds to Fully Patch Actively Exploited Cisco Flaws

Ubuntu 25.10’s Rusty Sudo Holes Quickly Welded Shut

11/12/2025

Australia at Risk of ‘High-Impact Sabotage’ From China, Says Spy Chief

UK Plans Tougher Laws to Protect Public Services From Cyberattacks

British Government Unveils Long-Awaited Landmark Cybersecurity Bill

Army Officer With Indo-Pacific Experience Emerges as Potential Cyber Command, NSA Pick

U.S. Announces ‘Strike Force’ to Counter Southeast Asian Cyber Scams, Sanctions Myanmar Armed Group

Lighthouse: This Is the Platform Google Claims Is Behind a ‘Staggering’ Scam Text Operation

German Extremist Arrested Over Operating Alleged Darknet Assassination Marketplace

DHS Kept Chicago Police Records for Months in Violation of Domestic Espionage Rules
Synnovis Notifies of Data Breach After 2024 Ransomware Attack

DanaBot Malware Is Back to Infecting Windows After 6-Month Break

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Windows 11 Now Supports 3rd-Party Apps for Native Passkey Management

Cybersecurity Firm Deepwatch Lays off Dozens, Citing Move to ‘Accelerate’ AI Investment

Bridging the Skills Gap: How Military Veterans Are Strengthening Cybersecurity

Russia Imposes 24-Hour Mobile Internet Blackout for Travelers Returning Home

Rhadamanthys Infostealer Disrupted as Cybercriminals Lose Server Access

11/10-11/2025

China-Aligned UTA0388 Uses AI Tools in Global Phishing Campaigns

Android Devices Targeted By KONNI APT in Find Hub Exploitation

CISA Orders Feds to Patch Samsung Zero-Day Used in Spyware Attacks

UK Asks Cyberspies to Probe Whether Chinese Buses Can Be Switched off Remotely

China Accuses U.S. of Orchestrating $13 Billion Bitcoin Hack

America’s Cybersecurity Defenses Are Cracking

Shutdown Deal Would Revive Cyber Intelligence-Sharing Bill

EU’s Reforms of GDPR, AI Slated by Privacy Activists for ‘Playing Into Big Tech’s Hands’

Yanluowang Initial Access Broker Pleaded Guilty to Ransomware Attacks

“Bitcoin Queen” Gets 11 Years in Prison for $7.3 Billion Bitcoin Scam

Mozilla Firefox Gets New Anti-Fingerprinting Defenses

Data Privacy Whistleblowers Would Get Expanded Protections Under California Proposal

Former Trump Official Named NSO Group Executive Chairman

Microsoft Releases KB5068781 — The first Windows 10 Extended Security Update
Hitachi-Owned GlobalLogic Admits Data Stolen on 10K Current and Former Staff

Wakefield & Associates (TN) Announces Breach of Client Data

Qilin Ransomware Activity Surges as Attacks Target Small Businesses

Quantum Route Redirect PhaaS Targets Microsoft 365 Users Worldwide

WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks

Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware

Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers

Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories

Hackers Exploit Critical Flaw in Gladinet’s Triofox File Sharing Product

Popular JavaScript Library Expr-Eval Vulnerable to RCE Flaw

SAP Fixes Hardcoded Credentials Flaw in SQL Anywhere Monitor

Synology Fixes BeeStation Zero-Days Demoed at Pwn2Own Ireland

Microsoft November 2025 Patch Tuesday Fixes 1 Zero-Day, 63 Flaws

11/6-9/2025

U.S. Congressional Budget Office (CBO) Hit by Cybersecurity Incident

Congressional Budget Office Implementing New Security Controls Following Cyberattack

Data Breach at Chinese Infosec Firm Reveals Cyber-Weapons and Target List

Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine

Previously Unknown Landfall Spyware Used in 0-Day Attacks on Samsung Phones

Scam Ads Are Flooding Social Media. These Former Meta Staffers Have a Plan

Krebs: Cloudflare Scrubs Aisuru Botnet from Top Domains List

Krebs: Drilling Down on Uncle Sam’s Proposed TP-Link Ban

The Government Shutdown Is a Ticking Cybersecurity Time Bomb

Japan Plans to Revise Foreign Investment Law to Sharpen Security Screening

Mexico City Is the Most Video-Surveilled Metropolis in the Americas

Lost iPhone? Don’t Fall for Phishing Texts Saying It Was Found

Italian Communications Executive Reveals He Was Targeted With Paragon Spyware

Edtech Company Fined $5.1 Million for Poor Data Security Practices Leading to Hack

Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts
“I Paid Twice” Phishing Campaign Targets Booking.com

How a Ransomware Gang Encrypted Nevada Government’s Systems

Washington Post Confirms Data Breach Linked to Oracle Hacks

Louvre’s Pathetic Passwords Belong in a Museum, Just Not That One

Cybersecurity Investigation Closes Manassas City Public Schools (VA) Monday

Cybercrims Plant Destructive Time Bomb Malware in Industrial .Net Extensions

Curly COMrades Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection

GlassWorm Malware Returns on OpenVSX with 3 New VSCode Extensions

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities

ClickFix Malware Attacks Evolve with Multi-OS Support, Video Tutorials

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic

Multi-Turn Attacks Expose Weaknesses in Open-Weight LLM Models

Critical Cisco UCCX Flaw Lets Attackers Run Commands as Root

Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362

Dangerous runC Flaws Could Allow Hackers to Escape Docker Containers

QNAP Fixes Seven NAS Zero-Day Flaws Exploited at Pwn2Own

11/5/2025

SonicWall Says State-Sponsored Hackers Behind September Security Breach

Russia-Linked ‘Curly COMrades’ Turn to Malicious Virtual Machines for Digital Spy Campaigns

Zohran Mamdani Just Inherited the NYPD Surveillance State

China Sentences 5 Myanmar Scam Kingpins to Death

Operation Chargeback Uncovers €300m Fraud Scheme in 193 Countries

UK Carriers to Block Spoofed Phone Numbers in Fraud Crackdown

Telecoms Cyber Chiefs Adopt Financial Sector’s Model of Collective Defense

Google Gets the U.S. Government’s Green Light to Acquire Wiz for $32B

Armis Raises $435 Million, Valuing Cybersecurity Startup at $6.1 Billion

Cyberattack Ate up Profits for First Half of Year, Retailer M&S Says
UNK_SmudgedSerpent Targets Academics With Political Lures

Hyundai AutoEver America Data Breach Exposes SSNs, Drivers Licenses

Central New Jersey Medical Center Suffers Ransomware Attack

University of Pennsylvania Confirms Hacker Stole Data During Cyberattack

Gootloader Malware Is Back With a Bang With New Tricks After 7-Month Break

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

AMD Red-Faced Over Random-Number Bug That Kills Cryptographic Security

CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence

11/4/2025

Russian Spies Pack Custom Malware Into Hidden VMs on Windows Machines

Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense Sectors

Data Brokers Selling Location Info That Can Be Used to Track EU Officials, Report Finds

Europe Sees Increase in Ransomware, Extortion Attacks

A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces

DragonForce Cartel Emerges as Conti-Derived Ransomware Threat

Lawmakers Say Stolen Police Logins Are Exposing Flock Surveillance Cameras to Hackers

FBI Warns of Criminals Posing as ICE, Urges Agents to ID Themselves

Treasury Sanctions 8 for Laundering North Korea Earnings From Cybercrime, IT Worker Scheme

Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep

French Police Seize €1.6m Amid Crypto Scam Network Crackdown

Health Privacy Bill Seeks Protections for Data Collected by Apps, Smartwatches
Data Breach at Major Swedish Software Supplier Impacts 1.5 Million

Media Giant Nikkei Reports Data Breach Impacting 17,000 People

Polish Loan Platform Hacked; Mobile Payment System and Other Businesses Disrupted

Hundreds of South Gloucestershire Residents’ Details Shared in Data Breach

Penn Data Breach Involves Decades of Student and Alumni Information

Apache OpenOffice Disputes Data Breach Claims by Akira Ransomware Gang

Malicious Android Apps on Google Play Downloaded 42 Million Times

Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed

Hackers Exploit WordPress Plugin Post SMTP to Hijack Admin Accounts

Hackers Exploit Critical Auth Bypass Flaw in JobMonster WordPress Theme

Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit

Microsoft Removing Defender Application Guard From Office

11/3/2025

New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea

Homeland Security Biometric Policy for Foreign Travelers Poses Data-Theft Risks

Hack Exposes Kansas City’s Secret Police Misconduct List

Cybercrooks Team Up With Organized Crime to Steal Pricey Cargo

Ransomware Negotiator, Pay Thyself!

U.S. Cybersecurity Experts Indicted for BlackCat Ransomware Attacks

MIT Sloan Quietly Shelves AI Ransomware Study After Researcher Calls BS

AWS, Nvidia, CrowdStrike Seek Security Startups to Enter the Arena

Data Breach Costs Lead to 90% Drop In Operating Profit at South Korean Telecom Giant
Hackers Are Attacking Britain’s Drinking Water Suppliers

Hacker Steals Over $120 Million From Balancer DeFi Crypto Protocol

Japanese Retailer Askul Confirms Data Leak After Cyberattack Claimed by Russia-Linked Group

Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive

Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data

Microsoft: SesameOp Malware Abuses OpenAI Assistants API in Attacks

New GDI Flaws Could Enable Remote Code Execution in Windows

Microsoft: Patch for WSUS Flaw Disabled Windows Server Hotpatching

CISA and NSA Outline Best Practices to Secure Exchange Servers

10/31-11/2/2025

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack

How to Hack a Poker Game Revealed

Security Concerns Persist Over System at Heart of Digital ID

Krebs: Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody

Alleged Conti Ransomware Gang Affiliate Appears in Tennessee Court After Ireland Extradition

Russia Finally Bites the Cybercrooks It Raised, Arresting Suspected Meduza Infostealer Devs

FCC Plans Vote to Remove Cyber Regulations Installed After Theft of Trump Info From Telecoms

Sling TV Settles With California for Allegedly Violating State Consumer Privacy Law
Hackers Threaten to Leak ‘Woke’ University of Pennsylvania Student Data

Attackers Dig Up $11M in Garden Finance Crypto Exploit

Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery

Rhysida Oysterloader Malvertising Campaign Leverages 40+ Code-Signing Certificates

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability

CISA: High-Severity Linux Flaw Now Exploited by Ransomware Gangs

Chinese Hackers Scanning, Exploiting Cisco ASA Firewalls Used by Governments Worldwide

Microsoft Edge Gets Scareware Sensor for Faster Scam Detection

Cybersecurity Earnings Rise as AI Dominates Strategies

10/30/2025

Diplomatic Entities in Belgium and Hungary Hacked in China-Linked Spy Campaign

Leaker Reveals Which Pixels Are Vulnerable to Cellebrite Phone Hacking

Shadow AI: One In Four Employees Use Unapproved AI Tools, Research Finds

LinkedIn Phishing Targets Finance Execs With Fake Board Invites

Proton Trains New Service to Expose Corporate Infosec Cover-Ups

NASA’s Quiet Supersonic Jet Takes Flight

Coalition Calls on FTC to Block Meta From Using Chatbot Interactions to Target Ads, Personalize Content
Threat Actors Utilize AdaptixC2 for Malicious Payload Delivery

Critical Flaws Found in Elementor King Addons Affect 10,000 Sites

Massive Surge of NFC Relay Malware Steals Europeans’ Credit Cards

Malicious NPM Packages Fetch Infostealer for Windows, Linux, macOS

CISA Orders Feds to Patch VMware Tools Flaw Exploited by Chinese Hackers

Cyber Info Sharing ‘Holding Steady’ Despite Lapse in CISA 2015, Official Says

The AI Trust Paradox: Why Security Teams Fear Automated Remediation

10/29/2025

U.S. Company Ribbon Communications With Access to Biggest Telecom Firms Uncovers Breach by Unnamed Nation-State Hackers

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

New Names Surface for NSA Director, Other Top Jobs at Spy Agency

The Microsoft Azure Outage Shows the Harsh Reality of Cloud Failures

Krebs: Aisuru Botnet Shifts from DDoS to Residential Proxies

New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts

Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm

CISOs Finally Get a Seat at the Board’s Table — But There’s a Big Catch
Canada Says Hacktivists Breached Water and Energy Facilities

Cloud Atlas Hackers Target Russian Agriculture Sector Ahead of Industry Forum

EY Exposes 4TB+ SQL Database to Open Internet for Who Knows How Long

Tata Motors Confirms It Fixed Security Flaws, Which Exposed Company and Customer Data

More Than 10 Million Impacted by Breach of Government Contractor Conduent

Investment Scams Spread Across Asia With International Reach

PhantomRaven: Npm Malware Uses Invisible Dependencies to Infect Dozens of Packages

WordPress Security Plugin Exposes Private Data to Site Subscribers

Windows 11 KB5067036 Update Rolls out Administrator Protection Feature

10/28/2025

SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats

Researchers Expose GhostCall and GhostHire: BlueNoroff’s New Malware Chains

Nation-State Cyber Ecosystems Weakened by Sanctions, Report Reveals

Clearview AI Faces Criminal Heat for Ignoring EU Data Fines

AI Browsers Face a Security Flaw as Inevitable as Death and Taxes

Palo Alto Networks Debuts Automated AI Agents to Fight Cyberattacks

Sublime Raises $150 Million for AI-Powered Email Security

A Quarter of Scam Victims Have Considered Self-Harm
Advertising Giant Dentsu Reports Data Breach at Subsidiary Merkle

New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human

New Atroposia Malware Comes With a Local Vulnerability Scanner

New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves

CISA Warns of Two More Actively Exploited Dassault Vulnerabilities

Google Chrome to Warn Users by Default Before Opening Insecure HTTP Sites

FCC Adopts New Rule Targeting Robocalls

F5 Expects Big Revenue Hit From Recent Cyber Attack Compromising Many

10/27/2025

Chatbots Are Pushing Sanctioned Russian Propaganda

Iran’s School for Cyberspies Could’ve Used a Few More Lessons in Preventing Breaches

Italian Spyware Vendor Linked to Chrome Zero-Day Attacks

Europol Warns of Rising Threat From Caller ID Spoofing Attacks

‘There Isn’t Really Another Choice:’ Signal Chief Explains Why the Encrypted Messenger Relies on AWS

X: Re-Enroll 2FA Security Keys by November 10 or Get Locked Out

You Have One Week to Opt Out or Become Fodder for LinkedIn AI Training

Shaquille O’Neal’s Custom Range Rover Stolen During Transport in Suspected Hack
Hundreds of People With ‘Top Secret’ Clearance Exposed by House Democrats’ Website

Google Disputes False Claims of Massive Gmail Data Breach

Sweden’s Power Grid Operator Confirms Data Breach Claimed by Everest Ransomware Gang

Qilin Ransomware Group Publishes Over 40 Cases Monthly

Ransomware Profits Drop as Victims Stop Paying Hackers

QNAP Warns of Critical ASP.NET Flaw in its Windows Backup Software

CISA Releases Warning About Windows Server Update Service Bug, Orders Agencies to Patch

Google Says Everyone Will Be Able to Vibe Code Video Games

10/24-26/2025

Blitz Spear Phishing Campaign Targets NGOs Supporting Ukraine

UN Cybercrime Treaty to Be Signed in Hanoi to Tackle Global Offences

Fake LastPass Death Claims Used to Breach Password Vaults

MPs Urge Government to Stop Britain’s Phone Theft Wave Through Tech

How Hacked Card Shufflers Allegedly Enabled a Mob-Fueled Poker Scam That Rocked the NBA

Hackers Earn $1,024,750 for 73 Zero-Days at Pwn2Own Ireland
Everest Ransomware Says It Stole 1.5m Dublin Airport Passenger Records

New LockBit Ransomware Victims Identified by Security Researchers

Hackers Steal Discord Accounts With RedTiger-Based Infostealer

Hackers Launch Mass Attacks Exploiting Outdated WordPress Plugins

Windows Server Emergency Patches Fix WSUS Bug with PoC Exploit

Critical WSUS Flaw in Windows Server Now Exploited in Attacks

10/23/2025

Lazarus Group’s Operation DreamJob Targets European Defense Firms

Pakistani-Linked Hacker Group Targets Indian Government with DeskRAT

Hackers Posing as Kyrgyz Officials Target Russian Agencies in Cyber Espionage Campaign

Europe’s Offshore Wind Sector Faces Dilemma Over China’s Grip on Sector

UK Cyber Law Delays ‘Deeply Concerning,’ Say MPs

The ‘Universal Browser’ Privacy Browser Has Dangerous Hidden Features

23andMe’s Data-Theft Victims Offered ‘Genetic Monitoring’ to Ward Off Hackers

Former Polish Official Indicted Over Spyware Purchase
Playtime’s Over: Crooks Swipe Toys R Us Canada Customer Data and Dump It Online

“Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards

Spoofed AI Sidebars Can Trick Atlas, Comet Users Into Dangerous Actions

Tired of Unpaid Toll Texts? Blame the ‘Smishing Triad’

CISA Warns of Lanscope Endpoint Manager Flaw Exploited in Attacks

Microsoft Disables File Explorer Preview for Downloads to Block Attacks

Google Nukes 3,000 YouTube Videos That Sowed Malware Disguised as Cracked Software

Trump Pardons Former Binance CEO After Guilty Plea in Letting Cybercrime Proceeds Flow Through Platform

10/22/2025

PhantomCaptcha Campaign Targets Ukraine Relief Organizations

MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign

The Long Tail of the AWS Outage

Scattered Lapsus$ Hunters Signal Shift in Tactics

UN Cybercrime Pact to Be Signed in Hanoi Raises Hopes, Concerns

Krebs: Canada Fines Cybercrime Friendly Cryptomus $176M

JLR Hack UK’s Costliest Ever, Hitting Economy with £1.9bn Loss

No, ICE (Probably) Didn’t Buy Guided Missile Warheads

SpaceX Disables More Than 2,000 Starlink Devices Used in Myanmar Scam Compounds

It Takes Only 250 Documents to Poison Any AI Model
Cyber Incidents in Texas, Tennessee and Indiana Impacting Critical Government Services

Ransomware Gang Steals Meeting Videos, Financial Secrets From Fence Wholesaler

Summit Golf Brands Allegedly Subjected to Massive INC Ransom Breach

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys

TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution

Hackers Exploiting Critical “SessionReaper” Flaw in Adobe Magento

Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft’s July Patch

Pwn2Own Day 2: Hackers Exploit 56 Zero-Days for $790,000

10/21/2025

Russian Coldriver Hackers Deploy New ‘NoRobot’, ‘YesRobot’, and ‘MaybeRobot’ Malware

‘PassiveNeuron’ Cyber Spies Target Orgs With Custom Malware

Lumma Stealer Developers Doxxed in Underground Rival Cybercrime Campaign

Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams

How Malware Vaccines Could Stop Ransomware’s Rampage

Medical Specialist Group Fined £100K After Hack Exposed Patient Data

Cloud Data Firm Veeam to Buy Securiti AI for $1.73 Billion

Russia Pressures Apple to Make Russian Search Engines Default on Locally-Sold iPhones
Amazon Says AWS Cloud Service Back to Normal After Outage Disrupts Businesses Worldwide

Singapore Officials Impersonated in Sophisticated Investment Scam

Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network

Vidar Stealer 2.0 Adds Multi-Threaded Data Theft, Better Evasion

PolarEdge Targets Cisco, ASUS, QNAP, Synology Routers in Expanding Botnet Campaign

Cursor, Windsurf IDEs Riddled with 94+ N-Day Chromium Vulnerabilities

TP-Link Warns of Critical Command Injection Flaw in Omada Gateways

Hackers Exploit 34 Zero-Days on the First Day of Pwn2Own Ireland 2025

10/20/2025

Amazon’s AWS Struggles to Recover After Major Outage Disrupts Apps, Services Worldwide

What the Huge AWS Outage Reveals About the Internet

Salt Typhoon Uses Citrix Flaw in Global Cyber-Attack

Flawed Vendor Guidance Exposes Enterprises to Avoidable Risk

Cyberattacks Cripple Small Businesses, Even When They Aren’t Hacked

DNS0.EU Private DNS Service Shuts Down Over Sustainability Issues

Evilginx’s Creator Reckons With the Dark Side of Red-Team Tools

Judge Bars NSO From Targeting WhatsApp Users With Spyware, Reduces Damages in Landmark Case

What to Know About the Shocking Louvre Jewelry Heist

The Fraudster Behind Steve Ballmer’s NBA Nightmare
Retail Giant Muji Halts Online Sales After Ransomware Attack on Supplier

Home Security Firm Verisure Reports Data Breach at Swedish Subsidiary

Japanese Retailer Askul Halts Online Orders, Shipments After Ransomware Attack

131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign

Self-Spreading GlassWorm Malware Hits OpenVSX, VS Code Registries

Cyber Defenders From All Around Sound the Alarm as F5 Hack Exposes Broad Risks

CISA: High-Severity Windows SMB Flaw Now Exploited in Attacks

Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets

Microsoft Warns of Windows Smart Card Auth Issues After October Updates

10/17-19/2025

Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials

North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware

Teen Tied to Russian Hackers in Dutch Cyber Espionage Probe

Over 266,000 F5 BIG-IP Instances Exposed to Remote Attacks

China Accuses U.S. of Cyberattack on National Time Center

Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide

Experian Fined $3.2 Million for Mass-Collecting Personal Data

Labor Unions Sue Trump Administration Over Social Media Surveillance
American Airlines Subsidiary Envoy Air Confirms Oracle Data Theft Attack

AI Girlfriend Apps Leak Millions of Private Chats

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

Krebs: Email Bombs Exploit Lax Authentication in Zendesk

Google Ads for Fake Homebrew, LogMeIn Sites Push Infostealers

TikTok Videos Continue to Push Infostealers, Including Aura Stealer, in ClickFix Attacks

Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices

ConnectWise Fixes Automate Bug Allowing AiTM Update Attacks

Microsoft Fixes Highest-Severity ASP.NET Core Flaw Ever

10/16/2025

Why the F5 Hack Created an ‘Imminent Threat’ for Thousands of Networks

Breach at U.S.-Based Cybersecurity Provider F5 Blamed on China, Say Sources

Cybersecurity Firm F5′S Stock Sinks 10%

‘Categorically Untrue’ That China Hacked UK Intelligence Systems, Say Officials

Hacked Airport P.A. Systems Broadcast Anti-Trump and Pro-Hamas Messages

North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts

Microsoft Disrupts Ransomware Attacks Targeting Teams Users

Microsoft Debuts Copilot Actions for Agentic AI-Driven Windows Tasks

Ring to Partner With Flock, Giving Law Enforcement Easier Access to Home Security Camera Footage

Cambodia to Repatriate South Koreans Ensnared by Scam Industry Amid Diplomatic Pressure

Ex-Trump National Security Adviser Bolton Charged With Storing and Sharing Classified Information

Vulnerability Scores, Huh, What Are They Good For? Almost Nothing
Nintendo Denies Data Leak After Online Reports

Auction Giant Sotheby’s Says Data Breach Exposed Customer Information

Have I Been Pwned: Prosper Data Breach Impacts 17.6 Million Accounts

List of Major Companies Hit by Massive Salesforce Data Breach Continues to Grow

Dairy Farmers of America Confirms June Cyberattack Leaked Personal Data

Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites

Microsoft Warns of a 32% Surge in Identity Hacks, Mainly Driven by Stolen Passwords

LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets

New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence

Gladinet Fixes Actively Exploited Zero-Day CVE-2025-11371 in File-Sharing Software

CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack