loader image
DDoSecrets Publishes 410GB From TeleMessage Breach

Distributed Denial of Secrets (DDoSecrets), a transparency-focused collective known for publishing leaked data, has added 410 gigabytes of breached data from TeleMessage to its indexing platform. The dataset reportedly includes sensitive communications and internal records, significantly expanding DDoSecrets’ repository of leaked information. TeleMessage, a secure messaging service marketed to enterprises and government agencies, has not […]

Russian Hackers Use Fake Entra Pages to Breach NGOs

A Russian state-linked hacking group known as Void Blizzard, also referred to as Laundry Bear, has compromised more than 20 non-governmental organizations (NGOs) through a phishing campaign that leverages Evilginx, according to Microsoft. The activity, active since at least April 2024, involves the use of fake Microsoft Entra login pages designed to steal user credentials […]

Russia Jails Coder 14 Years for Leaking Troop Data

A Russian court has sentenced a former hospital programmer to 14 years in a high-security penal colony for allegedly leaking personal data of Russian soldiers to Ukraine, authorities announced. The conviction marks one of the harshest penalties in recent months linked to accusations of aiding Ukraine amid the ongoing conflict. According to judicial statements, the […]

Linux Bugs Expose Password Hashes in Core Dumps

Two newly discovered vulnerabilities in popular Linux distributions could allow local attackers to access sensitive data, including password hashes, security researchers have found. The flaws, tracked as CVE-2025-5054 and CVE-2025-4598, affect apport and systemd-coredump—core dump handling utilities used in Ubuntu, Red Hat Enterprise Linux (RHEL), and Fedora. According to the Qualys Threat Research Unit, both […]

Microsoft, CrowdStrike Unite to Decode Hacker Aliases

Microsoft Corp. and CrowdStrike Holdings Inc. have launched a joint initiative to streamline cyber threat actor identification, aiming to eliminate confusion caused by inconsistent naming conventions across the cybersecurity industry. The collaboration, announced yesterday, introduces a cross-referenced mapping system that links varying threat actor names used by different vendors, without enforcing a unified standard. The […]

Crocodilus Malware Fakes Contacts to Mimic Banks

A newly observed campaign involving the Crocodilus malware is raising alarms among cybersecurity researchers, who warn that the Android-based threat is adopting deceptive tactics to facilitate banking fraud. The malware reportedly infiltrates victims’ devices and inserts fake entries into their contact lists, making it appear as though incoming messages or calls are coming from legitimate […]

Google Play Apps Lure Crypto Users for Seed Phrases

More than 20 malicious applications found on the Google Play Store have been targeting cryptocurrency users by attempting to steal their seed phrases, according to cybersecurity researchers. These apps, disguised as legitimate crypto wallet tools, were designed to trick users into entering sensitive information that could grant attackers full access to their digital assets. The […]

Cisco Patches ISE, CCP Flaws Amid Exploit Code Threat

Cisco has issued security updates to fix three vulnerabilities affecting its Identity Services Engine (ISE) and Customer Collaboration Platform (CCP), warning that public exploit code is already available for the flaws. The company released patches to mitigate the risks associated with these security weaknesses, which could potentially be used by threat actors to compromise affected […]

WordPress Hijacked to Spread VexTrio Scam Globally

Cybercriminals are exploiting legitimate WordPress websites in a growing scheme tied to the VexTrio Viper Traffic Distribution Service (TDS). The operation, which security researchers describe as highly organized, uses WordPress hijacked to spread malicious software and scams across a global network. VexTrio appears to operate alongside other TDS platforms, including Help TDS and Disposable TDS. […]

Tines Uses AI to Speed IT Ticket Resolution

IT teams facing a flood of support tickets can now streamline their response times with an automated workflow powered by AI and Tines. Designed to handle repetitive tasks, the system triages frequent issues such as password resets and known bugs. By automating these common requests, teams can reallocate resources to more complex problems and reduce […]

North Korea Hacks npm in Supply Chain Attack on Devs

Cybersecurity researchers have identified a new wave of North Korea hacks npm as part of an ongoing supply chain attack targeting software developers. The campaign, known as Contagious Interview, involves 35 malicious JavaScript packages published through 24 separate npm accounts. Security firm Socket reported that these packages have already been downloaded more than 4,000 times. […]

PlexTrac Unifies SOC Data to Halve Cyberattacks by 2028

PlexTrac Unifies SOC Data by integrating exposure management with incident response, offering security teams a centralized platform to streamline operations. As cyber threats grow more sophisticated, organizations face mounting pressure to reduce attack surfaces and accelerate remediation. PlexTrac’s platform consolidates critical security data, equipping analysts with real-time visibility and actionable insights. By enriching SOC data […]