loader image
FBI Seizes 145 Domains Tied to BidenCash Fraud Hub

U.S. federal authorities have seized 145 internet domains linked to BidenCash, a cybercrime platform accused of trafficking stolen financial data, according to the Justice Department. The illicit marketplace, active since at least March 2022, reportedly served over 117,000 customers and facilitated the sale of more than 15 million compromised credit card numbers. The domain seizure […]

Anubis RaaS Adds Wiper Tool to Permanently Erase Data

A newly emerged ransomware-as-a-service offering known as Anubis RaaS adds wiper functionality, making attacks more destructive by permanently deleting victim data. Active since December 2024, the ransomware encrypts files and—if its “wipe mode” is enabled—erases contents irreversibly, leaving behind empty 0 KB files. The malware campaign has targeted organizations across sectors such as healthcare and […]

DuckDuckGo Expands Scam Blocker as Fraud Hits $12.5B

DuckDuckGo has expanded its Scam Blocker to shield users from an increasing range of online threats such as fake e-commerce sites, phishing hubs, and scareware. The move comes as the Federal Trade Commission reported $12.5 billion in consumer fraud losses in 2024, underscoring the urgency for stronger digital defenses. DuckDuckGo expands Scam Blocker to detect […]

AI Agents Gain Identity, Forcing New Security Rules

Artificial intelligence continues to reshape cybersecurity, and identity protection now faces a new frontier. As AI agents gain identity, organizations must adapt their security frameworks to address the growing autonomy and access these systems possess. These agents no longer act as passive tools; they operate, decide, and interact in ways that demand recognition as distinct […]

Cyberattack Cripples Russian Dairy Supply Chain

A cyberattack cripples Russian dairy operations, triggering widespread supply chain disruptions across the nation’s major retailers. Lenta, Miratorg, and Yandex Lavka reported significant delays after hackers targeted Mercury, the national platform responsible for certifying animal-based products. The platform’s shutdown began earlier last week, halting the issuance of digital veterinary certificates essential for dairy distribution. Retailers […]

vBulletin Flaws Let Hackers Seize Forums via API, RCE

Two critical vulnerabilities in the vBulletin forum software are under active exploitation, security researchers warned. Tracked as CVE-2025-48827 and CVE-2025-48828, the flaws affect vBulletin versions 5.0.0 to 5.7.5 and 6.0.0 to 6.0.3 when running on PHP 8.1 or newer. CVE-2025-48827, rated with a maximum CVSS score of 10, allows unauthenticated users to invoke protected API […]

TikTok Users Hit by AI Malware in Video Scam

Hackers are exploiting TikTok’s popularity to distribute information-stealing malware using AI-generated tutorial videos, according to researchers at Censys. The campaign targets users searching for pirated software by presenting convincing how-to videos that guide viewers through fake activation processes. Instead of legitimate instructions, the videos prompt users to run PowerShell commands that install malware such as […]

Coinbase Breach Tied to Bribed TaskUs Agents in India

Coinbase, one of the largest cryptocurrency exchanges in the U.S., has confirmed a data breach linked to bribed customer support agents at TaskUs, a third-party service provider based in India. Threat actors reportedly targeted support personnel employed by TaskUs, offering bribes in exchange for internal access that was then used to extract sensitive user data […]

Gluestack NPM Hack Hits 960,000 Weekly Downloads

A major supply chain attack has compromised 15 widely used Gluestack packages on the NPM registry, affecting libraries that collectively draw over 950,000 downloads each week. The affected packages were altered to include malicious code functioning as a remote access trojan (RAT), enabling attackers to potentially gain unauthorized control over systems running the compromised software. […]

ClickFix Hack Fakes Cloudflare to Spread Malware

Cybersecurity researchers have uncovered a ClickFix malware campaign that leverages a counterfeit Cloudflare Turnstile—a system typically used to verify human users—to trick victims into downloading malicious software. The attack mimics Cloudflare’s “humanness” verification process to deceive users into believing they are interacting with a legitimate security check. Once engaged, the fraudulent interface initiates the installation […]

Ukraine Hacks Tupolev in Escalating Cyber Strike

Ukraine has launched a second cyberattack targeting Russian military assets, this time focusing on Tupolev, a prominent aircraft manufacturer. The move signals an escalation in Ukraine’s digital offensive, suggesting that drones alone may no longer suffice in its strategic operations. The attack, described as a hack, is part of an ongoing campaign to disrupt Russia’s […]

Paragon Spyware Found on iPhones of EU Journalists

Researchers have confirmed that spyware developed by Paragon was found on an Apple device, marking a significant development in a growing surveillance controversy in Italy. The discovery, revealed Wednesday, adds to mounting concerns over the use of advanced surveillance tools targeting journalists across Europe. The spyware’s presence was detected during an investigation into potential abuses […]