loader image
Iran’s APT42 Phishes Israeli Cyber Experts for Data

An Iranian state-aligned hacking group has targeted Israeli cyber and computer science professionals in a recent phishing campaign, according to Tel Aviv-based cybersecurity firm Check Point. The group, known by multiple aliases including APT42, Educated Manticore, Charming Kitten and Mint Sandstorm, reportedly used deceptive emails and messaging apps to manipulate victims. The attackers tricked individuals […]

Fake SSA Emails Lure Victims Into ScreenConnect Trap

Cybercriminals are leveraging spoofed emails purportedly from the U.S. Social Security Administration (SSA) to trick recipients into installing the ScreenConnect remote access tool (RAT), according to cybersecurity researchers. The phishing campaign uses fake SSA warnings to create a sense of urgency and prompt users to download a malicious attachment or click on a link that […]

Linux Kernel Exploit Published for Critical nftables Bug

A proof-of-concept (PoC) exploit has been released for CVE-2024-26809, a critical vulnerability affecting the Linux kernel’s nftables subsystem. The flaw, which allows local privilege escalation, stems from a double-free bug in the nft_pipapo_destroy() function of the netfilter module. Exploiting this involves manipulating overlapping elements in the nft_set_pipapo structure, corrupting the kernel heap and enabling attackers […]

Google Pays $1.4 Billion to Settle Texas Privacy Case

Google has agreed to pay nearly $1.4 billion to resolve allegations in Texas that it illegally collected personal data, marking the largest individual penalty the tech giant has faced in the state. The settlement addresses claims that Google violated privacy protections by gathering user information without proper consent. The case reflects growing scrutiny from U.S. […]

Google Uses AI on Android to Flag Scam Texts, Fraud

Google is enhancing its Android security capabilities by expanding the reach of its “Scam Detection” tool in Google Messages. The feature, which operates using on-device artificial intelligence, will now identify a broader set of digital fraud attempts, including scam texts and investment-related fraud. By analyzing message content locally on the device, the system flags suspicious […]

Intel Hit by New Spectre Flaw With Data Leak Risk

Researchers at ETH Zurich have uncovered a new method to exploit Intel processors using a variation of the notorious Spectre vulnerability, according to findings published Tuesday. The technique leverages a branch prediction race condition to leak sensitive information from memory, reigniting concerns over speculative execution flaws in modern CPUs. The exploit, which targets Intel’s processor […]

PupkinStealer Malware Hits Windows to Grab Logins, Files

A newly identified malware dubbed PupkinStealer is targeting Windows systems to harvest sensitive user data, cybersecurity researchers say. First detected in April 2025, the .NET-based malware, written in C#, focuses on stealing browser credentials, messaging app sessions, and desktop files. It exfiltrates data through Telegram’s Bot API, a tactic increasingly used by threat actors to […]

EU Sanctions Kremlin Agents Over Disinformation Ops

The European Union has imposed new sanctions targeting individuals and organizations involved in Russia’s disinformation and sabotage operations, intensifying efforts to counter Kremlin-aligned influence campaigns. The measures focus on members of the Russian military intelligence unit GRU and individuals accused of amplifying pro-Kremlin narratives through coordinated social media activity. The sanctions underscore growing concern in […]

Anthropic Readies Claude Sonnet 4, Opus 4 AI Models

Anthropic appears to be developing two advanced artificial intelligence models, Claude Sonnet 4 and Opus 4, according to details uncovered in the company’s web configuration files. The unannounced models are believed to represent the next iteration of Anthropic’s Claude AI systems, signaling continued progress in the firm’s large language model capabilities. While the company has […]

ENISA Issues Guide to Stress-Test Critical Systems

The European Union Agency for Cybersecurity (ENISA) has published a Cyber Stress Testing handbook aimed at strengthening the resilience of critical infrastructure across member states. The new guide is designed to support the implementation of the NIS2 Directive, which enhances cybersecurity requirements for essential and important entities operating in sectors such as energy, transport, health, […]

Ransomware Disrupts U.K. Grocer Supply Chain

Peter Green Chilled, a logistics company supplying refrigerated food to British supermarkets, has suffered a ransomware attack that disrupted its operations. The incident adds to a growing list of cyberattacks targeting the U.K.’s grocery supply chain, highlighting vulnerabilities within the sector’s critical infrastructure. The company, which specializes in the transportation of chilled products, disclosed the […]

VanHelsing Ransomware Builder Leaked by Ex-Dev

The VanHelsing ransomware-as-a-service (RaaS) operation has leaked critical components of its infrastructure, including the source code for its affiliate management panel, data leak blog, and Windows encryptor builder. The disclosure occurred after a former developer attempted to sell the tools on the RAMP cybercrime forum, prompting the group to release the assets publicly. The leak […]