loader image
Russia SpyPress Malware Hacks Webmail to Track Ukraine

A newly identified malware strain linked to Russian threat actors is exploiting webmail platforms to conduct surveillance operations targeting Ukraine, according to cybersecurity researchers. Dubbed “SpyPress,” the malware enables attackers to intercept communications, exfiltrate sensitive data, and monitor victims’ online activity through compromised email accounts. The campaign underscores the continued use of sophisticated cyber-espionage tactics […]

Nova Scotia Power Hit by Ransomware, Data Exposed

Nova Scotia Power has confirmed that a recent cybersecurity incident was the result of a ransomware attack, acknowledging the breach after weeks of investigation. The utility company, which provides electricity across the Canadian province, stated that while its systems were compromised, it has not paid any ransom to the attackers. As part of the fallout […]

Ivanti RCE Attacks Spread to Cloud as Hacks Surge

Ivanti is facing continued scrutiny as remote code execution (RCE) attacks targeting its software remain active, with recent exploitation efforts extending into cloud environments. The vulnerabilities appear to stem from insecure code within Ivanti’s security suite, raising concerns over the reliability of tools designed to protect enterprise systems. The ongoing nature of the attacks suggests […]

Russian State Services Crippled in Cyberattack Wave

Several major Russian government services experienced widespread disruptions, with indications pointing to a cyberattack as the potential cause. Internet monitoring platforms detected outages affecting the country’s tax service and Saby, a platform used for managing secure digital keys and official documents. The disruptions, which began earlier this week, appear to be ongoing, according to technical […]

Vietnam Hackers Bait AI Tool Fans With Stealth Malware

A threat group based in Vietnam is deploying deceptive online campaigns that exploit the growing interest in artificial intelligence video-generation tools, according to cybersecurity firm Mandiant. The group has launched thousands of ads, fake websites and social media posts that falsely promise access to popular prompt-to-video AI services. Instead of delivering the advertised tools, the […]

NSO Group Fined $168 Million for WhatsApp Spy Attack

A U.S. federal jury has ordered Israeli cyber-intelligence firm NSO Group to pay approximately $168 million in damages to WhatsApp, owned by Meta Platforms Inc., over the unauthorized use of its servers to deploy the Pegasus spyware tool. The decision follows a federal judge’s earlier finding that NSO Group violated U.S. law by targeting more […]

Qilin Tops Ransomware Charts With 74 Attacks in April

The Qilin ransomware group emerged as the most active cybercriminal collective in April 2025, launching 74 attacks globally, according to a new threat intelligence report. The group’s rise follows the abrupt decline of RansomHub, which had led activity earlier in the year but posted only three attacks last month before its leak site went offline. […]

California Fines Retailer Over Flawed Privacy Portal

The California Privacy Protection Agency on Tuesday levied a six-figure fine against a national clothing retailer for allegedly mismanaging a consumer privacy portal, marking one of the agency’s first enforcement actions under the state’s privacy law. The retailer, whose name was not disclosed, was cited for operating a flawed system that may have hindered consumers […]

Russian Firm Controls Key Easyjson Code Used Globally

A widely used open-source Go library, Easyjson, is under the exclusive control of developers based in Moscow who are affiliated with VK Group, a major Russian tech conglomerate, according to researchers at Hunted Labs. The JSON serialization tool is deeply embedded in critical infrastructure, including Kubernetes, Helm and Istio, raising concerns over software supply chain […]

CISA Warns Hackers Target Oil and Gas Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a brief advisory warning that “unsophisticated cyber actor(s)” are attempting to target and disrupt industrial technology systems used in the oil and gas sector. The alert, though limited in detail, highlights ongoing threats to critical infrastructure, particularly within the energy industry. CISA noted that the actors […]

Amazon, Rakuten Lures Used in Japan CoGUI Phishing Blitz

Organizations and individuals across Japan are being targeted by a wave of phishing attacks leveraging a sophisticated toolkit known as CoGUI. The phishing campaign, currently circulating widely, impersonates well-known Japanese e-commerce brands such as Amazon and Rakuten in an effort to deceive recipients and harvest sensitive information. Cybercriminals deploying the CoGUI phishing kit are taking […]

LockBit Ransomware Site Hacked, Database Dump Leaked

The LockBit ransomware gang’s dark web leak site was breached, with attackers defacing the portal and leaking a MySQL database tied to its affiliate backend infrastructure. A message reading “Don’t do crime — CRIME IS BAD xoxo from Prague” replaced the homepage, alongside a link to the database dump. LockBit’s operator, known as LockBitSupp, confirmed […]