loader image
Cybersecurity ROI Climbs as Budgets Shrink: Report

Cybersecurity budgets have declined significantly over the past two years, despite evidence that security teams are generating measurable business value, according to a report cited by *Infosecurity Magazine*. The share of annual organizational spending allocated to cybersecurity has dropped from 1.1% to 0.6%, highlighting a growing disconnect between investment levels and cybersecurity’s contribution to enterprise-wide […]

Fake Job Offers Spread PureHVNC Malware in Phishing Scam

Cybercriminals last year leveraged fake job offers from well-known fashion and beauty brands—including Bershka, John Hardy, Fragrance Du Bois, and Dear Klairs—to distribute the PureHVNC remote access trojan, according to a report from GBHackers News. The phishing campaign used these fraudulent employment lures as part of a multi-stage strategy to gain unauthorized access to victims’ […]

Fake DocuSign Sites Spread RAT via PowerShell Attacks

A new cyber campaign is leveraging fake websites impersonating popular services like DocuSign and Gitcode to deploy NetSupport RAT malware through multi-stage PowerShell scripts, according to researchers from the DomainTools Investigations team. The operation uses deceptive domains to lure users into downloading malicious scripts that initiate the infection process. The attack begins when a user […]

Hackers Mask Attacks Using Residential Proxy Traffic

Cybercriminals are increasingly leveraging residential proxy services to disguise malicious web traffic as ordinary online activity, making it harder for cybersecurity systems to detect and block harmful behavior. These services reroute traffic through real users’ internet connections, effectively masking the origin of the activity and giving it the appearance of legitimate browsing. By blending in […]

Microsoft Boosts EU Cyber Defenses Amid US Tensions

Microsoft has launched a new European Security Program in what it describes as a “proactive investment” in cybersecurity across the European Union. The move comes as the tech giant faces criticism over security vulnerabilities and as tensions between the EU and the U.S. continue to shift. The initiative aims to bolster Microsoft’s collaboration with European […]

Ukrainian Hacker Mined Crypto in 5,000 Account Breach

Ukrainian authorities have arrested a 35-year-old hacker accused of breaching 5,000 accounts at an international hosting provider and using the compromised systems to mine cryptocurrency. The cyberattack caused an estimated $4.5 million in damages, according to a statement from the police. The suspect allegedly gained unauthorized access to servers belonging to the hosting company and […]

DanaBot Leak Exposes 3 Years of Stolen Data

A critical vulnerability tracked as “DanaBleed” enabled investigators to infiltrate the DanaBot botnet, exposing its internal operations over a period of three years. The flaw allowed access to sensitive data, offering rare visibility into the infrastructure and tactics of one of the more persistent cybercriminal networks in recent years. DanaBot, which was recently disrupted, had […]

WordPress Malware Mimics Cloudflare on Checkout Pages

A new cybersecurity threat is targeting e-commerce websites by embedding itself into WordPress checkout pages. This sophisticated WordPress malware mimics Cloudflare’s interface to trick users into sharing sensitive payment details. By disguising itself as a legitimate security prompt, the malware captures card data during the checkout process without raising suspicion. The malicious script activates only […]

INTERPOL Warns Africa Faces Surge in Cyber Attacks

Cybercrime now accounts for over 30% of all reported crimes in Western and Eastern Africa, according to INTERPOL’s 2025 Africa Cyberthreat Assessment Report. The report, titled “INTERPOL Warns Africa Cyber,” highlights a dramatic shift in the region’s threat landscape, with two-thirds of African nations reporting cyber-related offenses as a medium-to-high proportion of total criminal activity. […]

Iran’s APT42 Phishes Israeli Cyber Experts for Data

An Iranian state-aligned hacking group has targeted Israeli cyber and computer science professionals in a recent phishing campaign, according to Tel Aviv-based cybersecurity firm Check Point. The group, known by multiple aliases including APT42, Educated Manticore, Charming Kitten and Mint Sandstorm, reportedly used deceptive emails and messaging apps to manipulate victims. The attackers tricked individuals […]

Fake SSA Emails Lure Victims Into ScreenConnect Trap

Cybercriminals are leveraging spoofed emails purportedly from the U.S. Social Security Administration (SSA) to trick recipients into installing the ScreenConnect remote access tool (RAT), according to cybersecurity researchers. The phishing campaign uses fake SSA warnings to create a sense of urgency and prompt users to download a malicious attachment or click on a link that […]

Linux Kernel Exploit Published for Critical nftables Bug

A proof-of-concept (PoC) exploit has been released for CVE-2024-26809, a critical vulnerability affecting the Linux kernel’s nftables subsystem. The flaw, which allows local privilege escalation, stems from a double-free bug in the nft_pipapo_destroy() function of the netfilter module. Exploiting this involves manipulating overlapping elements in the nft_set_pipapo structure, corrupting the kernel heap and enabling attackers […]