loader image
n8n Nodes Compromised by Malicious npm Package

Hackers have compromised n8n nodes by exploiting a weaponized npm package posing as a legitimate Google Ads integration. The malicious package mimicked authentic functionality, tricking developers into entering their OAuth credentials. Once input, the data was exfiltrated to an attacker-controlled server during routine workflow execution. Researchers at EndorLabs uncovered eight malicious packages targeting the automation […]

Endesa Says Hackers Accessed Customer Contracts

Spanish utility provider Endesa says hackers accessed data from its systems in a recent security breach impacting both the main company and its regulated retailer, Energía XXI. The attack exposed contract-related information that includes customers’ personal details, according to notices the company is now sending to affected individuals. Endesa has not disclosed how many customers […]

Europol, Spain Police Arrest 34 in Black Axe Raid

Europol announced the arrest of 34 individuals in Spain tied to the Black Axe criminal group after a joint crackdown with Spanish police and Bavarian authorities. The operation focused heavily on Seville, with additional arrests in Madrid, Málaga and Barcelona. Black Axe, a highly organized syndicate rooted in Nigeria, engages in cyber fraud, trafficking and […]

React Router Flaw Exposes Server Files

Security researchers have discovered a critical React Router flaw that enables attackers to perform directory traversal, gaining unauthorized access to server filesystem locations. The vulnerability, tracked as CVE-2025-61686, affects several packages within the React Router ecosystem. Exploiting the flaw allows malicious users to read, write or even overwrite sensitive server files outside of expected application […]

Sweden Detains IT Consultant Over Russia Spy Claim

Sweden detains an IT consultant who formerly worked with the Swedish Armed Forces, as authorities suspect him of spying for Russian intelligence. The 33-year-old man was taken into custody earlier this week, prosecutors announced. Officials believe he accessed sensitive information during his time working as a consultant and may have passed it to a foreign […]

Amsterdam Court Jails Hacker in Port Cocaine Plot

The Amsterdam Court of Appeal on Friday ruled that a hacker who manipulated European port systems to enable cocaine smuggling played a key technical role in a criminal trafficking operation. In a decision that underscores the growing intersection of cybercrime and organized drug trade, the Amsterdam court jailed the hacker for seven years, linking him […]

Ofcom Probes X Over Nonconsensual Deepfakes

British communications regulator Ofcom has launched an inquiry into social media platform X, formerly known as Twitter, over alleged failures to curb the spread of nonconsensual deepfake pornography involving both adults and minors. The move comes as Ofcom probes X under its new online safety powers, marking one of the first high-profile cases to test […]

Nissan Says 900GB Stolen in Everest Hack

The hacker group Everest Ransomware has claimed responsibility for a cybersecurity breach at Nissan, alleging that it stole 900GB of sensitive corporate data. The cybercriminals posted evidence of the intrusion on their leak site, showcasing documents they say belong to the Tokyo-headquartered automaker. Among the files are marketing materials, vehicle client data, legal documents and […]

Gmail Adds AI Inbox; Google Won’t Train on Emails

Google is introducing a major update to its email platform as Gmail adds a new AI inbox powered by its Gemini large language model. The feature automatically summarizes email threads, helping users quickly understand the content without opening each message individually. Despite the increased integration of artificial intelligence, the company emphasized that it will not […]

China-Linked Hackers Breach Telco Edge Devices

A threat group believed to operate from China has expanded its cyber operations, now targeting telecom firms in Southeastern Europe using edge device vulnerabilities. Security researchers say the china-linked hackers breach telco infrastructure by deploying custom Linux-based malware designed to exploit poorly secured internet-facing systems. This group reportedly shifted tactics, focusing on edge devices to […]

ValleyRAT_S2 Hijacks Firms to Steal Financial Data

A new malware campaign using a variant of the ValleyRAT family is raising alarms across cybersecurity circles as ValleyRAT_S2 hijacks firms through deceptive productivity tools and trojanized installers disguised as AI spreadsheet software. Delivered via spearphishing, modified software updaters, and DLL side-loading, ValleyRAT_S2 functions as a powerful C++-based remote access trojan. Once installed, it provides […]