loader image
Scattered Spider Hacks IT Desks, Bypasses MFA Systems

A cybercriminal group known as SCATTERED SPIDER is intensifying attacks on IT support teams to bypass multi-factor authentication (MFA), according to researchers at SOSIntelligence. Active since at least 2022, the group employs native English speakers to impersonate employees and exploit help desk personnel through voice phishing and MFA reset requests. SCATTERED SPIDER operates primarily as […]

Forescout Warns Europe Leads in Solar Gear Exposure

Europe has emerged as the leading region with the highest number of exposed solar power systems, according to new research from cybersecurity firm Forescout. The findings raise fresh concerns about the security of critical infrastructure amid growing reliance on renewable energy sources. Forescout’s analysis highlights vulnerabilities in solar energy equipment that is accessible through the […]

Salesforce Users Hit in Google-Uncovered Attack Spree

A cybercrime group tracked as UNC6040 has targeted approximately 20 organizations through a series of social-engineering attacks exploiting Salesforce customer accounts, according to Google’s Threat Intelligence Group. The campaign involves tricking individuals into providing sensitive information, enabling attackers to gain unauthorized access to enterprise systems. The attacks represent a growing trend in threat actors leveraging […]

Episource Hack Exposes Data of 5.4 Million Patients

Hackers breached healthcare services firm Episource, compromising personal and health data of approximately 5.4 million individuals. The Episource Hack Exposes Data tied to customers of healthcare organizations that rely on the company for critical services. The attackers accessed sensitive information, including personal identifiers and medical details, raising concerns about patient privacy and data security across […]

23andMe Fined $3.1 Million by UK Over Data Breach

The UK’s data protection authority has fined DNA testing company 23andMe £2.31 million ($3.12 million) for what it described as “serious security failings” that led to a major data breach in 2023. The regulator said the incident exposed sensitive genetic information, causing what it called “profoundly damaging” consequences. The penalty has drawn international scrutiny, with […]

APT28 Hits Ukraine With Malware in Signal Chat Attack

Russia-linked hacking group APT28 hits Ukraine with new malware by exploiting Signal, a secure messaging platform, according to recent cybersecurity findings. The attackers targeted Ukrainian government entities using malicious documents delivered through Signal chats, raising concerns over the platform’s misuse in cyber operations. Security researchers identified the malware as a fresh tool in APT28’s arsenal, […]

NetBird Malware Hits CFOs in Global Phishing Blitz

Chief financial officers and senior finance executives across global investment, banking, energy, and insurance sectors are being targeted in a sophisticated spear-phishing campaign deploying the NetBird malware, according to a report from GBHackers News. The operation appears designed to infiltrate high-value corporate environments by compromising executive-level email accounts through deceptive, tailored phishing messages. Once delivered […]

Microsoft Edge Adds Bio Lock for Android Private Tabs

Microsoft has introduced a new privacy feature in its Edge browser for Android that allows users to lock InPrivate browsing tabs using a PIN or biometric authentication. The update, currently available in the Canary version, enhances session security by requiring user authentication when returning to private tabs after leaving the app. The feature mirrors similar […]

China Data Leak Exposes 4 Billion User Records

Cybersecurity researchers have uncovered what may be the largest known leak of Chinese personal data from a single source, exposing more than 4 billion records online. The 631-gigabyte trove was found on an unsecured server and included sensitive details such as WeChat and Alipay activity, residential addresses, financial data, and national identification information. The leak, […]

Fortinet 0-Day Exploit Released as Attacks Surge

A publicly available proof-of-concept (PoC) exploit for a critical zero-day vulnerability in multiple Fortinet products has heightened concerns over enterprise network security. The flaw, identified as CVE-2025-32756 with a CVSS score of 9.8, enables unauthenticated remote code execution via a stack-based buffer overflow in the `/remote/hostcheck_validate` endpoint. It originates from improper bounds checking of the […]

DOJ Seizes $7.7M in Crypto Tied to North Korea Plot

The U.S. Department of Justice has seized approximately $7.7 million in cryptocurrency tied to an alleged scheme involving North Korean information technology workers, authorities said. The funds were frozen and confiscated after North Korean nationals reportedly attempted to launder the assets, which were linked to a long-running conspiracy. Officials stated the funds were illicitly obtained […]

Honeywell Finds 1,000 Threats in OT Log Review

Honeywell’s Advanced Monitoring and Incident Response (AMIR) service identified more than 1,000 cybersecurity incidents after analyzing 90 billion logs, reflecting a growing wave of threats targeting operational technology (OT) systems. The findings highlight the increasing complexity and frequency of cyber risks confronting industrial environments. The AMIR service, which specializes in monitoring and investigating cybersecurity events […]