loader image
Ukraine-Linked Hack Wipes Third of Russia Court Files

A cyberattack attributed to a pro-Ukrainian hacking group has reportedly wiped out approximately one-third of the archived case files from Pravosudiye, Russia’s national electronic court filing system, according to auditors. The breach, previously disclosed, targeted the digital infrastructure that supports the country’s judiciary, disrupting access to legal documents and court records. The attackers claimed responsibility […]

ChatGPT Leak Shows AI Tapping Outside Data via MCP

OpenAI’s ChatGPT is preparing to integrate support for the Model Context Protocol (MCP), according to a newly surfaced leak. The protocol will enable the AI chatbot to connect with third-party services, allowing it to draw on external data sources as contextual input during interactions. This capability marks a significant expansion in how ChatGPT can operate, […]

Hackers Use PWAs to Target Mobile Users in China Scam

A newly uncovered malware campaign is targeting mobile users through Progressive Web Applications (PWAs), exploiting browser protections and JavaScript to evade detection. Discovered by researchers at Cside.dev, the attack originates from China and leverages compromised Chinese-language novel websites to inject malicious code that activates only on mobile devices. The attack chain begins with users visiting […]

Fake Kling AI Ads on Facebook Spread RAT Malware

Cybercriminals are exploiting Facebook’s advertising platform to lure users into downloading remote access trojan (RAT) malware via counterfeit Kling AI pages, targeting over 22 million potential victims. The campaign uses fake Facebook pages and sponsored ads that mimic the branding of Kling AI, a synthetic media tool launched in June 2024 by Kuaishou Technology. Unsuspecting […]

Google Payroll Scam Redirects Paychecks to Hackers

Hackers are leveraging search engine optimization (SEO) poisoning techniques to deceive employees into handing over payroll credentials, according to findings from threat researchers. The campaign, first identified in May 2025 by cybersecurity firm ReliaQuest, targeted an unnamed manufacturing company. Attackers created fake payroll login pages that appeared in Google search results when employees searched for […]

Malicious Code in npm, VS Code Steals Crypto, Data

More than 70 malicious packages targeting JavaScript developers have been uncovered in the npm registry and Visual Studio Code (VS Code) ecosystem, posing a significant threat to software supply chains. According to research, approximately 60 of these were found in the npm package registry, embedded with install-time scripts designed to execute automatically during installation. Once […]

Adidas Discloses Breach After Vendor Cyberattack

Adidas AG, the German sportswear company, has disclosed a data breach following a cyberattack on one of its customer service providers. The incident resulted in unauthorized access to customer data, though the company did not specify the number of affected individuals or the type of information compromised. The breach was linked to a third-party service […]

Microsoft Unveils New Tactics to Thwart AiTM Attacks

Microsoft has published new research outlining advanced defensive strategies to counter the growing threat of Adversary-in-the-Middle (AiTM) attacks, which are becoming increasingly prevalent in cloud-based enterprise environments. These attacks exploit proxy servers to intercept authentication flows, effectively bypassing multifactor authentication (MFA) through phishing-as-a-service platforms such as Evilginx. High-profile threat groups, including Storm-0485 and Star Blizzard, […]

Lumma Infostealer Takedown May Have Fallen Short

Efforts to dismantle the Lumma infostealer operation may not have fully succeeded, according to security industry updates. Despite previous actions targeted at disrupting the malware’s infrastructure, new activity suggests that Lumma remains operational. The infostealer, known for harvesting sensitive user data including credentials and financial information, continues to pose a threat to organizations and individuals. […]

Microsoft, CrowdStrike Unite to Map Cyber Threat Actors

Microsoft Corp. and CrowdStrike Holdings Inc. have partnered to streamline threat actor identification, addressing a long-standing issue in cybersecurity intelligence: inconsistent naming of malicious groups across vendors. The initiative, announced Monday, introduces a shared mapping tool that links adversary identifiers without enforcing a universal naming standard. The collaboration aims to reduce confusion caused by divergent […]

Vodafone Fined $51 Million by Germany Over Privacy

Germany’s data privacy regulator has imposed a €49 million ($51 million) fine on Vodafone for violations of the country’s data protection rules, citing failures in safeguarding customer data. The penalty follows an investigation into the telecom company’s handling of user information, which regulators determined did not comply with established privacy standards. The regulator noted that […]

UK Tax Authority Says Scammers Stole £47 Million

The U.K.’s tax authority disclosed that cybercriminals stole £47 million ($63 million) last year by compromising taxpayer accounts. His Majesty’s Revenue & Customs (HMRC) said the losses were the result of fraudsters hijacking online profiles, allowing them to redirect tax refunds and manipulate personal data for financial gain. The agency did not specify how the […]