loader image
Hackers Hijack Paychecks via Fake Payroll Portals

Hackers are leveraging search engine optimization (SEO) poisoning to launch a new wave of payroll fraud attacks, security researchers at ReliaQuest report. By targeting employees on mobile devices, attackers create fake login pages that closely mimic legitimate corporate payroll portals. These spoofed sites appear prominently in search results when users look for company payroll platforms, […]

Lumma Infostealer Hit 10 Million Devices: FBI Says

A widespread malware campaign using the Lumma infostealer compromised approximately 10 million systems globally before being disrupted, according to the FBI. The malicious software targeted a broad range of victims, including individuals, businesses, and major corporations such as those in the Fortune 500. Cybercriminals deployed the malware to extract sensitive data from infected machines, enabling […]

VMware Fixes NATO-Flagged Flaw Exposing User Data

VMware has released a new batch of security patches addressing multiple software vulnerabilities that could expose users to serious cyber threats, including data leakage, unauthorized command execution, and denial-of-service (DoS) attacks. The most critical flaw among them has been flagged by NATO, underscoring its potential impact on security-sensitive environments. The company did not provide any […]

Everest Ransomware Leaks Coca-Cola Staff Data

The Everest ransomware group has reportedly leaked sensitive employee data belonging to Coca-Cola, exposing internal records on the dark web. According to cybersecurity sources, the compromised information includes personal and professional details of the company’s staff. The leak was disclosed via the hackers’ data leak site, where samples of the stolen files were made publicly […]

Iranian Hacker Pleads Guilty in $19 Million Robbinhood Hit

An Iranian national has pleaded guilty to two criminal counts tied to the deployment of the RobbinHood ransomware, which inflicted at least $19 million in damages, most notably targeting the city of Baltimore. The cyberattack disrupted municipal operations, crippling services and systems across the city. The defendant, identified as Sina Gholinejad, admitted to participating in […]

China Says Taiwan Hackers Hit 1,000 Mainland Networks

Chinese authorities have accused a group allegedly connected to Taiwan’s ruling Democratic Progressive Party (DPP) of carrying out cyberattacks on a local technology company, according to police in Guangzhou. The group is suspected of targeting more than 1,000 critical networks across over 10 provinces in mainland China, officials said. The announcement comes amid heightened tensions […]

Pure Crypter Malware Outsmarts Windows 11 24H2 Defenses

A sophisticated malware crypter known as Pure Crypter has been observed bypassing new security features introduced in Windows 11 version 24H2, according to researchers at eSentire. Designed as a modular malware delivery platform, Pure Crypter deploys multiple evasion techniques, including AMSI bypassing, DLL unhooking, and execution delays, to avoid detection by modern security tools. The […]

MainStreet Bank Data Breach Hits 5% of Customers

MainStreet Bancshares, a Virginia-based community bank, disclosed that nearly 5% of its customer data was compromised following a cybersecurity breach involving a third-party vendor. The incident occurred in March and was reported by The Record, a cybersecurity news outlet operated by Recorded Future. The breach did not originate within MainStreet Bank’s internal systems but stemmed […]

Apple Denies China Tied to Mysterious iPhone Crashes

A wave of unexplained iPhone crashes has raised alarms in the cybersecurity community, with some observers suspecting links to Chinese hacking operations—allegations Apple firmly denies. The crashes have prompted scrutiny amid rising geopolitical tensions and increasing cyberespionage activity. Though no official attribution has been made, the incidents coincide with broader concerns about state-backed cyber intrusions […]

Google Uncovers Vishing Ring Targeting Salesforce Data

Google has revealed a financially motivated threat group, dubbed UNC6040, that is targeting organizations using Salesforce through voice phishing, or “vishing,” schemes. According to the company’s threat intelligence team, the group employs deceptive techniques to trick victims into downloading a counterfeit version of a legitimate Salesforce tool called Data Loader. The fraudulent application is designed […]

Cilium Taps eBPF to Boost Container Security Insights

Cilium taps eBPF to deliver deeper visibility into container environments by monitoring activities directly at the Linux kernel level. This approach enables enhanced security by capturing detailed system behavior, including system calls, network traffic, and process execution. Tools such as Tetragon leverage this capability to provide real-time insights into container operations without disrupting performance. By […]

Scattered Spider Hacks M&S, Co-op in $592M Cyber Hit

U.K. retailers Marks & Spencer and Co-op suffered coordinated cyberattacks in April 2025, resulting in damages estimated up to $592 million. The Cyber Monitoring Centre (CMC), an independent body backed by the insurance industry, confirmed that the incidents are now classified as a “single combined cyber event.” Investigators linked the breaches to the Scattered Spider […]