loader image
Iranian Hackers Target U.S. Infrastructure, CISA Warns

U.S. cybersecurity and intelligence agencies are warning that Iranian hackers target U.S. critical infrastructure by exploiting outdated software, known vulnerabilities, and weak or default passwords. A joint advisory from CISA, the FBI, NSA, and DC3 urges heightened vigilance amid escalating tensions linked to the ongoing Iran-Israel conflict. While no coordinated campaign has been detected, Iranian […]

Play Ransomware Hit U.S. Using Windows Zero-Day Exploit

Hackers affiliated with the Play ransomware group exploited a now-patched Windows zero-day vulnerability to breach a U.S.-based organization, according to cybersecurity researchers. The flaw, identified as CVE-2025-29824, is a privilege escalation vulnerability in Microsoft’s Common Log File System (CLFS) driver. It had been actively exploited before Microsoft issued a security patch. The Symantec Threat Hunter […]

LockBit Ransomware Chats Exposed in Data Breach

A newly uncovered data breach has exposed internal records of the LockBit ransomware gang, shedding light on the group’s operations. Among the compromised data is a database containing a table labeled “chats,” which includes over 4,000 negotiation conversations between LockBit and its victims. The breach provides a rare glimpse into the communication tactics used by […]

.NET Malware Hides Payloads Inside Bitmap Files

A new strain of .NET malware is employing a stealth technique to evade detection by concealing its malicious payloads within bitmap image resources, according to a post shared on the cybersecurity-focused subreddit r/netsec. The method involves embedding harmful code inside what appear to be standard image files, which are then loaded and executed by the […]

SAP Patches Critical Flaw in NetWeaver Software

SAP has issued 16 new security notes as part of its May 2025 Security Patch Day, addressing several vulnerabilities across its software portfolio, including a critical flaw in its NetWeaver platform. The latest advisory highlights the company’s ongoing efforts to strengthen the security of its widely deployed enterprise systems. The critical vulnerability in NetWeaver could […]

NPM Malware Hijacks Google Calendar to Evade Detection

A newly uncovered supply chain attack targeting the Node Package Manager (NPM) ecosystem is employing Google Calendar as a covert command and control (C2) channel, security researchers at Veracode said. The malware, embedded in JavaScript packages downloaded over 35,000 times, uses obfuscated payloads to evade detection and establish persistent access. Once installed, the malware abuses […]

U.S. Dismantles DanaBot, Charges 16 in $50M Scheme

The U.S. Department of Justice said Thursday it dismantled the infrastructure behind DanaBot, a malware platform tied to a Russia-based cybercriminal group, and unsealed charges against 16 individuals allegedly involved in the scheme. According to the Justice Department, DanaBot—also known as DanaTools—was used to infect more than 300,000 computers globally, facilitating a sprawling cybercrime operation […]

U.S. Plans Data Hub to Centralize Spy Purchases

The U.S. government is developing a centralized platform designed to streamline the purchase of Americans’ personal data by intelligence and law enforcement agencies. The initiative, described as a “one-stop shop,” aims to improve access to commercially available data while raising concerns among privacy advocates about surveillance overreach and potential violations of the Fourth Amendment. In […]

US, Europol Arrest 270 in Dark Web Drug Crackdown

Global law enforcement agencies arrested 288 individuals tied to illicit drug trafficking on the dark web as part of Operation RapTor, a coordinated effort led by U.S. and European Union authorities. The operation resulted in the seizure of more than $200 million in cash and virtual currencies, signaling a major disruption of online narcotics networks. […]

Meta Wins Delay in German AI Data Consent Case

A regional court in Cologne has declined to issue an interim injunction against Meta over its use of personal data to train artificial intelligence systems, according to a statement released Thursday. The court determined that a final decision will be made during the main proceedings. The case centers on allegations that Meta is processing user […]

Europol Seizes 300 Servers in Global Ransomware Bust

European law enforcement agencies have dismantled a major ransomware infrastructure in a coordinated global crackdown, seizing 300 servers and freezing €3.5 million in assets, according to details emerging from the latest phase of Operation Endgame. The operation, which began in May 2024, targets networks that support or directly engage in ransomware attacks, including those providing […]

Facebook Data Sale Claims 1.2 Billion Records—Doubted

A threat actor is reportedly selling a data trove claiming to contain 1.2 billion Facebook user records, according to cybersecurity-focused outlet Hackread. The alleged breach was advertised on a hacking forum, where the seller claimed the data includes names, emails, phone numbers, and other personal details. However, discrepancies in the listing have raised doubts among […]