loader image
Npm Package Hack Plants Trojan in 45,000 Downloads

A widely used npm package, *rand-user-agent*, has been compromised in a supply chain attack, injecting obfuscated code designed to deploy a remote access trojan (RAT) on users’ systems. The malicious package, which sees approximately 45,000 downloads per week, was altered to include code that covertly grants attackers backdoor access to affected machines. The tampered component […]

Insight Partners Fears Hack Exposed Financial Secrets

Private equity firm Insight Partners suspects that highly sensitive financial data may have been compromised in a recent cyber intrusion, raising concerns over potential fraud risks. The breach, described as involving “weapons-grade” information, could include confidential financial records, placing investors and partners at heightened exposure to identity theft and financial manipulation. While the extent and […]

Germany Seizes eXch Crypto Site in $1.9 Billion Probe

German authorities dismantled the eXch crypto exchange on April 30, 2025, in a coordinated international operation targeting money laundering and illegal trading activities. The Federal Criminal Police Office (BKA), in collaboration with the Central Office for Combating Cybercrime (ZIT) and Dutch financial intelligence agency FIOD, seized the platform’s infrastructure, €34 million in cryptocurrency, and 8 […]

Hackers Target Linux With New ClickFix Attack Tests

A new cyberattack campaign employing ClickFix techniques is now targeting Linux systems in addition to Windows, signaling a broader scope for the emerging threat. The attackers are using platform-agnostic instructions that allow the malware to infect both operating systems, expanding the potential victim pool and demonstrating increased sophistication. ClickFix attacks typically exploit user interaction by […]

APT28 Hacks Gov’t Email via MDaemon Zero-Day Bug

A Russian state-linked hacking group has exploited a zero-day vulnerability in MDaemon webmail software as part of a broader cyber espionage campaign targeting government email servers, according to new research from cybersecurity firm ESET. Dubbed Operation RoundPress, the activity began in 2023 and focused on exploiting cross-site scripting (XSS) flaws in multiple webmail platforms, including […]

Russia Disinformation Hits Poland, Romania Elections

Russian disinformation campaigns are intensifying in Poland and Romania as voters head to the polls for presidential elections, according to local authorities. Officials from both countries report a surge in activity linked to the Kremlin-backed influence network known as Doppelgänger. The disinformation effort appears designed to sway public opinion and disrupt the electoral process, with […]

LockBit Hacked, Internal Chats and Wallets Leaked

LockBit, one of the world’s most active ransomware groups, has suffered a major breach after attackers defaced its dark web infrastructure and leaked a trove of sensitive internal data. The breach, disclosed on May 7, exposed a MySQL database containing operational details, including 60,000 Bitcoin wallet addresses and over 4,400 negotiation messages between LockBit operators […]

Poland Arrests Four in Global DDoS-for-Hire Crackdown

Polish authorities have arrested four individuals accused of operating six-for-hire cybercrime platforms that offered distributed denial-of-service (DDoS) attacks, marking a significant step in a global crackdown on digital threat services. The suspects allegedly provided access to tools capable of disrupting targeted websites and online infrastructure for as little as 10 euros, according to officials. The […]

PowerSchool Hack Spurs Extortion Threats to Clients

PowerSchool, a major provider of education technology, is facing downstream extortion threats following a cyberattack that occurred in December. The company reportedly paid a ransom after the intrusion. Now, a threat actor is leveraging stolen data obtained during the breach to target PowerSchool’s customers, attempting to extort them directly. The attack underscores the growing risks […]

Poland Blames Russia for Election Interference Threat

Poland has accused Russia of engaging in “unprecedented” interference ahead of the country’s upcoming presidential election, citing escalating hybrid threats and disinformation campaigns. The warning comes amid rising concerns over cybersecurity and foreign influence operations across Europe. Poland’s digital affairs minister said that no other European Union nation faces the same level of threats from […]

Samsung Display Flaw Hit by Mirai Botnet Exploit

A Mirai-based botnet has begun targeting a vulnerability in Samsung’s MagicINFO system after patches addressing the flaw were found to be ineffective, according to researchers. MagicINFO is a content management solution used to control digital signage across a variety of enterprise environments. The exploited flaw remains active despite Samsung issuing fixes, raising concerns over the […]

Fake AI Video Sites Spread New Noodlophile Malware

Cybercriminals are exploiting the surging interest in artificial intelligence by using fake image-to-video AI websites to distribute a new information-stealing malware dubbed “Noodlophile,” according to cybersecurity researchers. The malicious platforms claim to generate AI-powered videos from static images but instead deliver executable files that initiate a stealthy attack chain. Once downloaded, these files deploy the […]