loader image
Microsoft Extends M365 App Fixes on Windows 10 to 2028

Microsoft will continue delivering security updates for Microsoft 365 (M365) applications running on Windows 10 through 2028, extending support for its productivity suite even as the underlying operating system nears end-of-life. The announcement offers clarity for enterprise users relying on Windows 10 systems, though it highlights a growing divide between application and OS support. While […]

Twilio Denies Breach After Steam 2FA Leak Claim

Twilio Inc. denied reports of a security breach after a threat actor claimed to possess over 89 million Steam user records, including one-time access codes. In a statement to BleepingComputer, the communications platform said it had not been compromised, countering allegations that its systems were the source of the data leak. The claims emerged online, […]

ENISA Unveils Guide to Test Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has published a new *Handbook for Cyber Stress Testing*, designed to assist national authorities in evaluating the cybersecurity posture and operational resilience of critical sector entities. The document outlines a structured approach for conducting cyber stress tests, offering guidance on planning, execution and evaluation of results. This initiative […]

3AM Ransomware Gang Launches Email Bombing Attacks

Threat actors affiliated with the 3AM ransomware group have deployed highly targeted intrusion techniques in early 2024, including email bombing and impersonation of IT support personnel, according to a report from BleepingComputer. The attackers used email bombing — a tactic involving a flood of irrelevant emails — to obscure critical security alerts and distract potential […]

Hackers Lure With Fake VPNs to Spread Winos Malware

Hackers are leveraging counterfeit software installers disguised as popular applications, including LetsVPN and QQ Browser, to distribute the Winos 4.0 malware framework, cybersecurity researchers revealed. The campaign, uncovered by Rapid7 in February 2025, employs a sophisticated multi-stage loader known as Catena to execute the attack. Catena functions as a memory-resident loader, embedding shellcode and configuration-switching […]

ConnectWise Tool Tops List of 2025 Cyber Weapons

ConnectWise ScreenConnect has emerged as the most exploited remote access tool (RAT) in cyberattacks throughout 2025, according to a report by Hackread. The remote desktop solution, commonly used for IT support and system administration, was frequently leveraged by threat actors to gain unauthorized access to networks and systems. Its widespread abuse underscores growing security concerns […]

Telefónica Update Triggers Telecom Outage Across Spain

Telecommunications services across Spain suffered a widespread outage on Tuesday, May 20, 2025, following a scheduled network update by Telefónica that triggered a cascading failure across multiple carriers. Fixed-line and mobile services were disrupted nationwide, with Madrid, Barcelona and other urban centers reporting significant connectivity issues. Major providers including Movistar, Orange, Vodafone, Digimobil and O2 […]

Fake Chrome Extensions Steal Logins, Inject Ads

More than 100 malicious Chrome browser extensions have been discovered hijacking user sessions, stealing credentials, and injecting unwanted ads, according to recent findings. The campaign, active since at least February 2024, involves an unidentified threat actor who has developed and distributed the rogue extensions under the guise of legitimate utilities and productivity tools. The extensions […]

Russian Hackers Void Blizzard Escalate Spy Campaign

A Russian-linked hacking group known as Void Blizzard has intensified its cyber-espionage operations, focusing on infiltrating organizations by targeting their external partners and contractors, according to new findings. The group is reportedly leveraging these indirect access points to obtain login credentials and sensitive internal data, heightening concerns among cybersecurity professionals. Void Blizzard’s strategy reflects a […]

Hackers Fake OneNote Login to Steal Microsoft Emails

Hackers are deploying a highly sophisticated phishing campaign that mimics Microsoft OneNote login prompts to steal Office 365 and Outlook credentials, according to researchers at ANY.RUN. The operation primarily targets Italian and U.S. users and abuses trusted platforms such as Notion, Glitch, Google Docs and RenderForest to host fake login pages. Victims receive emails with […]

Interlock Ransomware Hits UK With New NodeSnake RAT

Interlock ransomware has launched a new wave of cyberattacks in the United Kingdom, deploying a previously unknown remote access trojan (RAT) dubbed NodeSnake. The campaign marks a shift in tactics for the cybercriminal group, integrating the Node.js-based malware to enhance stealth and persistence within compromised networks. Security researchers report that NodeSnake enables attackers to exert […]

Volkswagen Breach Claim Lacks Supporting Evidence

Volkswagen Group has been named in an unverified data breach claim by the Stormous ransomware gang, though no conclusive evidence has emerged to confirm the alleged compromise, according to a report from Cybernews. The threat group asserted responsibility for infiltrating the German automaker’s systems, but investigators have yet to identify proof substantiating the intrusion. The […]