loader image
OneClik Malware Hits Energy Sector With Golang Tool

Cybersecurity analysts have uncovered a sophisticated campaign called OneClik Malware Hits Energy that targets companies in the energy, oil, and gas industries. The operation exploits Microsoft’s ClickOnce technology, a legitimate software deployment tool, to distribute malicious payloads. Attackers then deploy customized backdoors written in Golang, enabling long-term access to compromised systems. Researchers at Trellix noted […]

NSO Group Fined $168 Million for WhatsApp Spy Attack

A U.S. federal jury has ordered Israeli cyber-intelligence firm NSO Group to pay approximately $168 million in damages to WhatsApp, owned by Meta Platforms Inc., over the unauthorized use of its servers to deploy the Pegasus spyware tool. The decision follows a federal judge’s earlier finding that NSO Group violated U.S. law by targeting more […]

Qilin Tops Ransomware Charts With 74 Attacks in April

The Qilin ransomware group emerged as the most active cybercriminal collective in April 2025, launching 74 attacks globally, according to a new threat intelligence report. The group’s rise follows the abrupt decline of RansomHub, which had led activity earlier in the year but posted only three attacks last month before its leak site went offline. […]

California Fines Retailer Over Flawed Privacy Portal

The California Privacy Protection Agency on Tuesday levied a six-figure fine against a national clothing retailer for allegedly mismanaging a consumer privacy portal, marking one of the agency’s first enforcement actions under the state’s privacy law. The retailer, whose name was not disclosed, was cited for operating a flawed system that may have hindered consumers […]

Russian Firm Controls Key Easyjson Code Used Globally

A widely used open-source Go library, Easyjson, is under the exclusive control of developers based in Moscow who are affiliated with VK Group, a major Russian tech conglomerate, according to researchers at Hunted Labs. The JSON serialization tool is deeply embedded in critical infrastructure, including Kubernetes, Helm and Istio, raising concerns over software supply chain […]

CISA Warns Hackers Target Oil and Gas Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a brief advisory warning that “unsophisticated cyber actor(s)” are attempting to target and disrupt industrial technology systems used in the oil and gas sector. The alert, though limited in detail, highlights ongoing threats to critical infrastructure, particularly within the energy industry. CISA noted that the actors […]

LockBit Ransomware Site Hacked, Database Dump Leaked

The LockBit ransomware gang’s dark web leak site was breached, with attackers defacing the portal and leaking a MySQL database tied to its affiliate backend infrastructure. A message reading “Don’t do crime — CRIME IS BAD xoxo from Prague” replaced the homepage, alongside a link to the database dump. LockBit’s operator, known as LockBitSupp, confirmed […]

Amazon, Rakuten Lures Used in Japan CoGUI Phishing Blitz

Organizations and individuals across Japan are being targeted by a wave of phishing attacks leveraging a sophisticated toolkit known as CoGUI. The phishing campaign, currently circulating widely, impersonates well-known Japanese e-commerce brands such as Amazon and Rakuten in an effort to deceive recipients and harvest sensitive information. Cybercriminals deploying the CoGUI phishing kit are taking […]

Npm Package Hack Plants Trojan in 45,000 Downloads

A widely used npm package, *rand-user-agent*, has been compromised in a supply chain attack, injecting obfuscated code designed to deploy a remote access trojan (RAT) on users’ systems. The malicious package, which sees approximately 45,000 downloads per week, was altered to include code that covertly grants attackers backdoor access to affected machines. The tampered component […]

Insight Partners Fears Hack Exposed Financial Secrets

Private equity firm Insight Partners suspects that highly sensitive financial data may have been compromised in a recent cyber intrusion, raising concerns over potential fraud risks. The breach, described as involving “weapons-grade” information, could include confidential financial records, placing investors and partners at heightened exposure to identity theft and financial manipulation. While the extent and […]

Germany Seizes eXch Crypto Site in $1.9 Billion Probe

German authorities dismantled the eXch crypto exchange on April 30, 2025, in a coordinated international operation targeting money laundering and illegal trading activities. The Federal Criminal Police Office (BKA), in collaboration with the Central Office for Combating Cybercrime (ZIT) and Dutch financial intelligence agency FIOD, seized the platform’s infrastructure, €34 million in cryptocurrency, and 8 […]

Hackers Target Linux With New ClickFix Attack Tests

A new cyberattack campaign employing ClickFix techniques is now targeting Linux systems in addition to Windows, signaling a broader scope for the emerging threat. The attackers are using platform-agnostic instructions that allow the malware to infect both operating systems, expanding the potential victim pool and demonstrating increased sophistication. ClickFix attacks typically exploit user interaction by […]