News
Cyber security news for MSPs and the businesses they protect.

breach
Craneware breach hits vendor behind 2,000 US hospitals
Craneware isn't a household name, but if you've ever been billed by an American hospital there's a fair chance its software was involved somewhere along the line. The Edinburgh-based firm sells billin…
2026-07-21

breach
Hugging Face Breached by AI Agent, Guardrails Blocked Forensics
There is a certain poetry to this one. Hugging Face, the world's largest repository of open-source AI models, has confirmed that its production infrastructure was breached last week by an autonomous A…
2026-07-21

vulnerability
FakeGit: 7,600 Poisoned GitHub Repos Bait AI Agents
Researchers at Island have surfaced a sprawling supply-chain campaign on GitHub: close to 7,600 malicious repositories dressed up as legitimate developer projects, with more than 800 posing specifical…
2026-07-21

vulnerability
HollowGraph: Malware That Hides Commands in Outlook Calendars
Here is a novel one. Researchers at Group-IB have pulled apart a Windows implant that turns a compromised Microsoft 365 calendar into a two-way command channel. They are calling it HollowGraph, and it…
2026-07-21

phishing
Rapid7 Grabs 1,048 Files From Exposed Phishing Server
Every so often an attacker forgets to lock the front door. This time a malware operator left its delivery server wide open, and Rapid7 walked off with 1,048 files: lure templates, filename-spoofing ex…
2026-07-21

breach
Estée Lauder Confirms Oracle EBS Breach, Ten Months On
Estée Lauder is writing to customers about a data breach that traces back to its Oracle E-Business Suite, the platform the cosmetics giant used for HR. The intrusion happened on 9 August 2025. The com…
2026-07-21

vulnerability
One in Six Windows Machines Still Runs Windows 10
Windows 10 is proving remarkably hard to kill. Asset tracking firm Lansweeper reckons 16.9 percent of the Windows devices it monitors are still running the older OS. That's down from roughly half a ye…
2026-07-17

phishing
Qantas Lost 5.7M Records to a Vishing Call and Broke No Rules
Australia's Privacy Commissioner has closed the file on the 2025 Qantas breach with a verdict you don't see often: the airline lost personal data belonging to 5.7 million customers, and it broke no ru…
2026-07-17

phishing
The Malware Pretending to Be a Font File
A phishing campaign flagged by Fortinet's FortiGuard Labs has been ticking along since March, and it relies on a small piece of misdirection that keeps paying off: the payload arrives with a .ttf exte…
2026-07-17

general
ClickLock: the macOS stealer that holds your apps hostage
There's a new macOS infostealer doing the rounds, and its selling point is coercion. ClickLock, written up this week by Group-IB, arrives the way most of these things arrive lately: a command pasted i…
2026-07-17

ransomware
Ransomware Halts Fairlife's US Milk Production
Coca-Cola told the SEC this week that its Fairlife dairy subsidiary has been hit by ransomware, and production at Fairlife's US facilities is paused while the company works through the fallout. Canadi…
2026-07-17

breach
23andMe Pays $18M Over Breach It Blamed on Customers
23andMe, now trading as Chrome Holding Co., has agreed to pay $18 million to settle claims brought by 43 US attorneys general over the 2023 breach that exposed the genetic data of 6.9 million people.…
2026-07-17

vulnerability
LegacyHive Windows zero-day drops as July Patch Tuesday ships
Hours after Microsoft wrapped its July 2026 Patch Tuesday rollout, a researcher going by Chaotic Eclipse published a proof-of-concept exploit called LegacyHive. It targets the Windows User Profile Ser…
2026-07-16

ransomware
KFC Japan Runs Low on Chicken After Logistics Partner Hit
Japan's critical infrastructure took a hit this week, and by critical infrastructure we mean fried chicken. KFC Japan has paused online orders and warned that menu cuts and store closures may follow,…
2026-07-16

general
A Russian Hacker Ran His Botnet by Asking Gemini Nicely
A Russian-speaking attacker going by "bandcampro" spent months running a small botnet by chatting to Google's Gemini CLI as if it were a helpful colleague. Trend Micro reconstructed more than 200 sess…
2026-07-16

phishing
OkoBot Fakes Ledger and Trezor Recovery Prompts From Inside
A Windows malware framework called OkoBot has been quietly working the crypto wallet crowd since April 2025, and its cleverest move is asking you for your recovery phrase from inside the wallet app yo…
2026-07-16

breach
23andMe pays $18M after blaming customers for its own breach
Forty-two state attorneys general have landed an $18 million settlement with 23andMe over the 2023 breach that exposed data belonging to 6.9 million people, genetic ancestry information included. The…
2026-07-16

vulnerability
RabbitMQ Bugs Leak OAuth Secrets and Cross-Tenant Data
Two access-control flaws in RabbitMQ, the open source message broker that quietly runs behind an enormous amount of production infrastructure, sat undiscovered in the codebase for close to two years b…
2026-07-15

vulnerability
Entra ID Blind Spot: OAuth Client ID Spoofing Explained
There is a quiet gap in Microsoft Entra ID sign-in telemetry, and at least two separate groups have worked out how to walk through it. Proofpoint researchers are calling the technique OAuth client ID…
2026-07-15

phishing
LastPass and Bitwarden Users Hit by Fake Compliance Phish
LastPass is warning customers about a phishing campaign built to look like a boring policy update. The emails arrive from [email protected], mention enhanced SaaS monitoring and admin conso…
2026-07-15

breach
Finland Issues Wanted Notice for Vastaamo Hacker Kivimäki
Finland's Supreme Court has closed the door on one of the country's ugliest cybercrime cases. It refused to hear Aleksanteri Kivimäki's appeal, leaving a February ruling from the Court of Appeal intac…
2026-07-15

breach
€140m Cyber Fraud Ring Taken Down in Spain: 800 Accounts, 67 Mules
Spanish police have dismantled a cybercrime and money-laundering operation that pulled in around €140 million through investment scams and business email compromise. Four people were arrested across S…
2026-07-15

ransomware
US Charges Russians Behind Media Land Bulletproof Host
American prosecutors have unsealed an indictment against three Russians they say ran Media Land, a St. Petersburg hosting business that kept a large chunk of the world's ransomware and card-fraud econ…
2026-07-15

vulnerability
Progress confirms ShareFile Storage Zone zero-day, patches out
Progress Software has confirmed what a lot of ShareFile customers were already whispering about: last week's abrupt shutdown of Storage Zone Controllers wasn't a cautious over-reaction. It was a live,…
2026-07-15

general
292 Fake GitHub Repos Are Handing Out Infostealers
A threat actor spent the middle of the year quietly filling GitHub with 292 repositories dressed up as legitimate software. Security tools, crypto wallets, developer utilities, macOS apps, secure emai…
2026-07-15

vulnerability
Dormant GitHub Accounts Wake Up for Mass Recon Campaign
Somebody has been playing a very long game on GitHub. Researchers at Datadog have identified more than 50 ghost accounts, all registered two to five years ago and left completely idle since, that rece…
2026-07-14

breach
Lidl Customers Hit by Supplier Breach Across Three Countries
Lidl has told customers in Germany, Belgium and the Netherlands that their personal details were pulled from an IT service provider last week. The supermarket chain, owned by Schwarz Group and operati…
2026-07-14

vulnerability
Australia Warns of Global CMS Webshell Campaign
The Australian Cyber Security Centre has issued a warning that will feel familiar to anyone who has run a website for more than five minutes. A global campaign is systematically hunting for vulnerable…
2026-07-14

breach
Malware Strands Japan's Largest Taxi Fleet, Nihon Kotsu
Nihon Kotsu, the largest taxi and chauffeur operator in Japan, spent the weekend quietly unplugging bits of its own network after finding malware inside. The intrusion was spotted early on Saturday. D…
2026-07-14

breach
Centers Laboratory breach: 540,000 patient records taken in 6 days
Centers Laboratory, a New Jersey diagnostics firm that runs testing for healthcare providers, has told US regulators that a breach it spotted in August affects 542,377 people. Attackers were inside th…
2026-07-14

vulnerability
Jscrambler's own npm package backdoored for two hours
There is something particularly awkward about a company that sells code protection watching its own package get backdoored. That is exactly what happened to Jscrambler over the weekend, when an attack…
2026-07-14

vulnerability
ModHeader pulled: 1.6M-user extension hid dormant spy kit
ModHeader, a header-editing extension used by about 1.6 million people across Chrome and Edge, has been pulled from both stores. Microsoft delisted it on 3 July. Google followed on 10 July. UK firm St…
2026-07-14

phishing
Pink vishing crew targets Microsoft 365 passkey enrollment
There is a phone scam making the rounds that piggybacks on a genuinely useful Microsoft feature. Since May, Entra admins have been able to run passkey registration campaigns to nudge staff toward stro…
2026-07-09

general
RedWing: Android Bank Fraud Sold as a Telegram Subscription
There's a new Android malware kit doing the rounds called RedWing, and the sales pitch is depressingly professional. Pay a monthly fee on Telegram and you get a full bank-fraud operation off the shelf…
2026-07-09

phishing
Netherlands tops Europe's payment fraud league in 2025
Dutch police have arrested two young men, aged 21 and 23, accused of running a credit card phishing operation out of Amsterdam and Zaandam. When officers raided their homes on 23 June 2026, they left…
2026-07-09

general
RedWing: Android Banking Trojan Rented Out on Telegram
There's a new Android spyware in circulation, and the interesting thing about it isn't the malware itself. It's the shopfront. Researchers at Zimperium's zLabs team have named it RedWing , and they de…
2026-07-09

phishing
The Facebook Verified Badge Scam That Ran for Seven Months
For roughly seven months, from November 2025 until Meta pulled the plug in June 2026, a phishing crew ran a patient, well-built scam against Facebook business users. The bait was the one thing plenty…
2026-07-09

breach
Windows Device ID Allegedly Outs Scattered Spider Suspect
U.S. prosecutors say they traced an alleged Scattered Spider member to a break-in at a luxury jewellery retailer using something most people have never heard of: a persistent Windows device ID that su…
2026-07-09

phishing
EvilTokens: The Phishing Page That Only Exists in Your Browser
There's a new phishing technique making the rounds, and it's built specifically to slip past the tools most businesses rely on to catch this stuff. Researchers are calling it ghost phishing. The campa…
2026-07-09

vulnerability
Fake Paysafe and Skrill SDKs Found on npm and PyPI
Someone spent a weekend impersonating payment SDKs, and it worked well enough to warrant a warning. Researchers at Socket found 17 malicious packages sitting on npm and PyPI, pretending to be official…
2026-07-09

vulnerability
China-linked crew hits unpatched Roundcube to spy on physicists
A suspected China-aligned espionage group has spent the past few months quietly working its way through the inboxes of physics and engineering researchers at universities across the US and Canada. Pro…
2026-07-09

vulnerability
ESET: 3,000+ Malicious AI Agent Skills Found in the Wild
AI agents are the new interns. They browse, they click, they run commands, they poke around your files, all on your behalf. To do any of that, they lean on things called skills , little modular capabi…
2026-07-09

breach
Mount Royal University Breach: H Drive Stolen, J Drive Wiped
Mount Royal University in Calgary has confirmed that attackers who broke into its network on 17 June copied files from a shared storage drive and then deleted the originals on their way out. A group c…
2026-07-09

breach
KDDI Breach: 12 Million Emails, 7.6 Million Passwords Exposed
KDDI, one of Japan's three largest telcos, has finally attached numbers to the breach it disclosed in June. More than 12.2 million customer email addresses and 7.6 million passwords were exposed after…
2026-07-08

breach
Accenture Confirms Breach as '888' Sells 35GB of Data
Accenture has confirmed it was breached after a threat actor operating under the handle '888' began offering 35GB of the consultancy's data on a cybercrime forum. The company told BleepingComputer the…
2026-07-08

ransomware
Ohio County Reportedly Paid $1M to Kairos Extortion Crew
A rural county government in Ohio appears to have paid $1 million in Bitcoin to a cyber extortion crew calling itself Kairos, according to a leaked negotiation transcript published by Ransom-ISAC. The…
2026-07-08

vulnerability
China-Linked Crew Turns Unpatched Ruckus Routers Into Relay Net
A Chinese threat group tracked by Cisco Talos as UAT-7810 has been quietly building what researchers call an Operational Relay Box network. In plainer terms, a mesh of hijacked routers used to bounce…
2026-07-08

phishing
DEBULL: device code phishing that walks past MFA
Here's a phishing technique that doesn't bother with a fake login page, doesn't need your password, and strolls straight past multi-factor authentication. It just asks you to type a short code into th…
2026-07-08

general
Hacktivist jailed, MEP hit by Pegasus, zero-days dumped
Some weeks in security don't have one big story, they have twelve small ones that together say quite a lot. This was one of those weeks. Start in a US courtroom. Aubrey Cottle, a 39-year-old Canadian…
2026-07-04

ransomware
Union County paid $1M to a crew that never encrypted a thing
A US government entity handed over roughly $1 million to keep stolen files off the internet. The details come from a case study by Rakesh Krishnan for Ransom-ISAC, pieced together from a leaked negoti…
2026-07-04

phishing
Verified X ad, fake Mac app, and the ConsentFix token trick
Two campaigns doing the rounds this week are a decent reminder that attackers have largely stopped bothering with clever exploits. Why break in when the user will happily open the door for you? The ve…
2026-07-03

phishing
ARToken: The Microsoft 365 Phishing Kit That Beats MFA
Cisco Talos has pulled apart ARToken, a phishing-as-a-service platform that looks to be an affiliate of the already well-known EvilTokens operation. While tracing infrastructure during an incident res…
2026-07-03

vulnerability
Fake Rollup npm Packages Target Developer Machines
Another week, another batch of malicious npm packages built to look like something you'd install without thinking about it. JFrog's researchers have flagged two: rollup-packages-polyfill-core and roll…
2026-07-03

vulnerability
PamStealer: Fake Maccy App Verifies Your Mac Password First
Jamf Threat Labs has surfaced a new macOS information stealer with the unlovely name PamStealer. It poses as Maccy, a well-known open-source clipboard manager, and the way it works is worth a closer l…
2026-07-03

ransomware
Avalon: The AI-Assembled Malware Kit With CrownX Ransomware
Researchers at Blackpoint Cyber have taken apart a new modular malware framework called Avalon, and it reads like a Swiss Army knife for intrusions. Credential theft, lateral movement, remote access,…
2026-07-03

breach
AdaptHealth Breach: Contractor Talked Into Handing Over Keys
AdaptHealth, a Pennsylvania medical equipment company looking after more than 4.2 million patients across the US, has told the SEC that attackers wandered into its cloud environment by way of a third-…
2026-07-03

breach
Medtronic Notifies 9 Million After ShinyHunters Breach
Medtronic, the medical device giant with operations in 150 countries and $33.5 billion in annual revenue, is in the awkward position of writing to roughly 9 million customers about a data breach. The…
2026-07-03

vulnerability
ToddyCat's Umbrij Malware Rides Live Gmail Sessions
The APT group ToddyCat has picked up a new tool, and it is a neat piece of work. Kaspersky researchers have named it Umbrij, and its sole job is to sit quietly on an infected machine and read whoever'…
2026-07-03

general
Cloudflare Flips the Defaults on AI Crawlers in Sept 2026
Cloudflare has quietly rewritten how it handles bots, and the shift is more interesting than the usual toggle-switch update. Instead of a single allow-or-block choice, site owners can now sort AI traf…
2026-07-03

general
Google Disrupts NetNut, a 2M-Device Residential Proxy Network
Google has taken a serious swipe at NetNut, a service that quietly turns ordinary home internet connections into rented relays for other people's traffic. Working with the FBI, Lumen and a handful of…
2026-07-03

general
AI Hallucination Gets a Startup Blocked as Chinese Malware
MeetingTV is suing Palo Alto Networks over a threat report that accused it of being the public face of a Chinese cyber espionage operation. According to the complaint, the report was largely drafted b…
2026-07-03

vulnerability
The MEP Investigating Pegasus Had Pegasus on His Phone
There is irony, and then there is this. Stelios Kouloglou, a Greek member of the European Parliament who sat on the very committee set up to investigate commercial spyware abuse, had his phone infecte…
2026-07-03

vulnerability
Apple drops bundled patches as AI shrinks exploit window
Apple has quietly changed the way it ships security fixes. For years it preferred to stuff patches inside major operating system releases, which left users waiting weeks or months for a fix to actuall…
2026-07-03

ransomware
An AI Ran a Full Ransomware Attack, Then Forgot the Data
Sysdig's threat researchers say they've watched a ransomware attack run from start to finish by a large language model, with no human at the keyboard. They've called the agent JadePuffer , and it walk…
2026-07-03

vulnerability
Apple patches 24+ WebKit bugs that were visible for weeks
Apple has rolled out a sizeable round of security updates across iOS, iPadOS, macOS Tahoe and Safari, fixing more than two dozen vulnerabilities in one go. The bulk of them sit inside WebKit, the brow…
2026-06-30

ransomware
BlueHammer Defender Flaw Now in the Ransomware Toolkit
Remember BlueHammer? The Microsoft Defender privilege escalation flaw a researcher tossed onto the public internet back in April, fed up with how Microsoft handles disclosures? CISA confirmed on Monda…
2026-06-30

ransomware
323 UK Firms Hit by Ransomware, Mostly Small Businesses
The City of London Police's Report Fraud line logged 323 UK businesses hit by ransomware between April 2025 and March 2026. That works out to about 26 successful attacks every month, and more than hal…
2026-06-30

vulnerability
BioShocking: AI Browsers Fooled by a Puzzle Game
Convince an AI browser that it's playing a puzzle game, and it will happily hand over your login details. That's the finding from security firm LayerX, whose new technique, BioShocking, fooled six AI…
2026-06-30

vulnerability
India's .bank.in Registry Leaked Credentials for 13 Months
Earlier this year the Reserve Bank of India had what looked like a sensible idea. Force every bank in the country onto a dedicated .bank.in subdomain so ordinary customers could glance at a URL and te…
2026-06-30

vulnerability
AirDrop and Quick Share: Six Bugs Across Five Billion Devices
Researchers at the CISPA Helmholtz Center for Information Security have spent quality time prodding the wireless file-sharing features baked into nearly every phone and laptop in circulation. Between…
2026-06-30

phishing
ClickFix Tops Malware Delivery Charts, and macOS Is in Scope
There's a particular flavour of attack that works because it convinces the victim to do the work themselves. It's called ClickFix, and a fresh ReliaQuest report covering March to May 2026 puts it at t…
2026-06-30

breach
Aflac Japan Breach: Ten-Day Intrusion Exposes Bank Details
Aflac, the supplemental insurer best known for the duck adverts, has told the SEC that intruders spent ten days inside its Japanese subsidiary's systems before being spotted. Aflac Japan caught the un…
2026-06-30

ransomware
Blackfield Ransomware Demands $2M From Nidec Subsidiary
Japanese motor giant Nidec is back in the ransomware news, this time thanks to a crew calling itself Blackfield. The gang is demanding $2 million to delete data it says it pulled from Nidec Chaun Chou…
2026-06-30

phishing
Hotels Phished With Fake Guest Complaints and Hidden Malware
Two research teams, one at Microsoft and one at Trend Micro, have independently spotted phishing campaigns aimed at hotels and other hospitality businesses across Europe, Asia, and Japan. The lures ar…
2026-06-30

general
Microsoft Brings Quantum-Safe Deadline Forward to 2029
Microsoft has decided that quantum is no longer a someday problem. This week the company said it is accelerating its Quantum Safe Program, with a new goal of moving critical products and services onto…
2026-06-30

vulnerability
A 1989 Bash Quirk Just Broke AI Coding Agent Guardrails
Bash has been around since 1989. AI coding agents have been around for about fifteen minutes. Guess which one is winning. Researchers at Adversa AI ran eleven popular open source agents, including Her…
2026-06-30

vulnerability
MCP Tool Poisoning: When the AI Agent Does As It's Told
Microsoft's incident response team has published research on a quietly worrying class of attack: hijacking AI agents by editing the text that tells them what their tools do. No malware, no exploit, no…
2026-06-30

ransomware
JLR Hack Looks Less Like a Heist and More Like Sabotage
A New York Times report this week put Russia in the frame for last year's attack on Jaguar Land Rover, an incident now reckoned to have cost the British economy around £1.9bn and the carmaker itself r…
2026-06-29

vulnerability
Millenium RAT: a $10 trojan with 62,000 victims
Group-IB has been quietly tracking a piece of malware called Millenium RAT, and the numbers are worth pausing on. 62,289 infected Windows devices across more than 160 countries, with almost 40,000 of…
2026-06-29

phishing
US Offers $10M for Russian Hackers Phishing Signal Users
The US State Department has put up to $10 million on the table for anyone who can help identify or locate members of UNC5792 and UNC4221, two crews it ties to Russia's FSB Border Guards and military i…
2026-06-29

general
Mustang Panda Hides C2 Inside Zoho WorkDrive to Spy on India
The China-aligned espionage group Mustang Panda has been quietly working two campaigns against Indian government and hydropower targets, and the interesting choice is what they used as a command chann…
2026-06-29

breach
Nissan Payroll Data Breached in Oracle PeopleSoft Attacks
Nissan has started writing to current and former employees in the United States, Canada, Mexico and Brazil to tell them their personnel records were caught up in the wave of Oracle PeopleSoft attacks…
2026-06-29

vulnerability
119 Edge Extensions Pulled After Stealing Logins and 2FA
Microsoft has pulled 119 extensions from the Edge add-on store after tracing them all back to a single adware operation its researchers are calling StegoAd. Between them, the extensions had been insta…
2026-06-29

breach
KDDI Email Breach Hits Six ISPs and 14M Logins
KDDI Corporation, one of Japan's biggest telcos, has confirmed that attackers got into an email platform it runs not only for its own subscribers but for five other internet service providers as well.…
2026-06-28

vulnerability
Amazon Q Flaw Let Malicious Repos Steal AWS Credentials
Wiz researchers have gone public with a flaw in Amazon Q Developer, the AI coding assistant that lives inside editors like VS Code and JetBrains, that managed to turn the very ordinary act of opening…
2026-06-28

general
Turla's StockStay Backdoor Hides Behind Academic Lures
Russia's long-running espionage outfit Turla, also known as Snake, Venomous Bear and Waterbug, has spent the last three years quietly building a new .NET backdoor. Google's Threat Intelligence Group h…
2026-06-27

breach
Poland Arrests SIM-Swap Crew Behind $5M Crypto Theft
Polish authorities have arrested four people accused of running a polished SIM-swapping operation that siphoned millions from cryptocurrency accounts. The Polish Cybercrime Bureau (CBZC) made the arre…
2026-06-27

phishing
Hotel Phishing Hides Node.js Backdoor in Photo ZIPs
Microsoft has flagged a phishing campaign that has been quietly grinding away at hotels across Europe and Asia since April. The lure is tuned for the audience: emails from "Booking Manager (via Calend…
2026-06-27

phishing
Mirage2FA: Phishing Kit That Walks Through MFA Prompts
Researchers at Fortra have lifted the lid on a phishing kit called Mirage2FA , and it is a neat piece of work. HTML smuggling, obfuscated JavaScript, a believable Microsoft 365 login clone, and a back…
2026-06-27

vulnerability
StrikeShark Campaign Hits Governments via Old Bugs and Fake Installers
Kaspersky researchers have stitched together what started as a single odd-looking attack on a diplomatic body in Indonesia and turned out to be something much bigger. They're calling it StrikeShark, a…
2026-06-27

general
Gamaredon Sharpens Its Toolkit Against Ukrainian Targets
Gamaredon, the FSB-linked group that has been battering Ukrainian targets since well before the full-scale invasion, has quietly raised its game. Researchers tracking the crew say the malware loaders…
2026-06-27

breach
Polymarket Users Lose $3M in Frontend Supply-Chain Attack
Polymarket, the crypto prediction market currently valued at around $9 billion, is reimbursing customers after roughly $3 million was siphoned out of their accounts. The platform's own infrastructure…
2026-06-27

phishing
Fake PDF Installs Chrome Extension That Steals Sessions
There's a phishing campaign making the rounds that takes the oldest lure in the book, a fake invoice attachment, and uses it as the door into something quite a bit more sophisticated. The file is call…
2026-06-27

phishing
Russian Spies Keep Phishing Signal and WhatsApp Accounts
CISA and the FBI have updated an earlier advisory about Russian intelligence services phishing their way into users' accounts on commercial messaging apps like Signal, WhatsApp and Telegram. The refre…
2026-06-27
phishing
Phishing Invites Sent Straight From OpenAI's Own Servers
Here is a clever one. Attackers are setting up ChatGPT organisations named after real companies, then using OpenAI's own invitation system to ask employees to join. The emails are genuine, sent from n…
2026-06-27

general
Huntress, an Ex-Analyst and a Ransomware Crew on LinkedIn
There is a peculiar argument running on LinkedIn and Reddit this week, involving the security firm Huntress, a former analyst called Ben Folland, and a ransomware operation that goes by DevMan. It beg…
2026-06-25

phishing
Bluekit phishing kit puppets the victim's browser in real time
Bluekit, the phishing-as-a-service platform first documented by Varonis back in April, has picked up a fairly significant upgrade. Netcraft researchers spotted nearly 70 new Bluekit hostnames in the p…
2026-06-25

phishing
The 'Parcel Expert' job is a reshipping mule scam
There's a job offer circulating on WhatsApp, email and social DMs promising up to $5,300 a month for what sounds like very gentle work: sit at home, take in parcels, match them against invoices, snap…
2026-06-25

vulnerability
Featured Chrome Ad Blocker, 10M Installs, One Switch From Rogue
An ad blocker called Adblock for YouTube , sitting on the Chrome Web Store with a Featured badge and more than 10 million installs, has been quietly carrying the plumbing to run arbitrary JavaScript o…
2026-06-25

phishing
Fake receipts in Shopify's Shop app fuel callback phishing
Here's a clever twist on callback phishing. Rather than blasting out dodgy invoice emails and hoping someone panics, scammers are planting fake purchase receipts directly inside Shopify's Shop app, wh…
2026-06-25

general
AI Hasn't Reinvented Hacking, Just Made It Cheaper
ReliaQuest has spent two years watching the cybercrime underground experiment with AI, and its latest report lands on a conclusion that cuts against most of the noise on the topic: AI hasn't rewritten…
2026-06-25

phishing
Xsolis phishing breach exposes 1.4 million patient records
Xsolis, a Tennessee healthcare AI company whose software sits inside more than 600 hospitals and insurers, has confirmed that a phishing attack exposed personal data belonging to nearly 1.4 million pe…
2026-06-25

general
Operation Endgame Disrupts Amadey and StealC Malware
Microsoft, Europol and a sprawling cast of partners have taken a hammer to the infrastructure behind two of the busier malware-as-a-service operations in circulation. Amadey and StealC, both rented ou…
2026-06-25

ransomware
Mistic: the quiet backdoor feeding ransomware crews
A new backdoor called Mistic has been turning up inside insurance firms, schools, IT shops and professional services outfits since April. Symantec reckon they know who is steering it: KongTuke, also t…
2026-06-25

phishing
The Help Desk Is Still the Easiest Door Into Your Network
Service desks keep getting rolled, and it isn't because the tech behind them is weak. They get rolled because someone picks up the phone, sounds convincing, and asks for a password reset. That is genu…
2026-06-25

ransomware
MuddyWater Poses as Chaos Ransomware to Hide Iran Espionage
Espionage crews have worked out a useful trick. If you want to hide a state-backed intrusion, dress it up as a ransomware job and let the investigators chase the wrong story. A new report from NCC Gro…
2026-06-25

ransomware
Edgecution: Malicious Edge Extension Escapes the Sandbox
A fake IT support call on Microsoft Teams. A convincing Microsoft branded page titled 'Outlook Updates Management Console'. A button helpfully labelled as a spam filter update. That is the entire fron…
2026-06-25

breach
ASIO Phoned a Foreign Spy at Home to Call Off the Op
Australia's spy chief Mike Burgess used his annual threat assessment to tell two stories. One should worry anyone running a network. The other is the most entertaining thing said from an intelligence…
2026-06-25

vulnerability
UK student found the school admin password in plain sight
Here is a story that should not be possible in 2026, and yet. A 17-year-old at a UK sixth form plugged his personal laptop into the school network, opened Active Directory, and found he could poke aro…
2026-06-25

breach
DraftKings Hacker "Snoopy" Sentenced to 18 Months
Nathan Austad, a 21-year-old from Minnesota who went by the alias Snoopy , has been sentenced to 18 months in prison for his role in the November 2022 DraftKings hack. He and his co-conspirators worke…
2026-06-25

vulnerability
GitHub Blocks 'Pwn Requests' in Actions Checkout
GitHub has had enough of pwn requests. From 18 June 2026, the new version of actions/checkout, the workhorse step that pulls a repo into a workflow runner, will refuse by default to fetch code from a…
2026-06-24

vulnerability
Fake postcss npm Package Drops Full Windows RAT
JFrog's researchers have taken apart a malicious npm package that spent its short life pretending to be one of the JavaScript ecosystem's workhorses. The genuine article, postcss-selector-parser, gets…
2026-06-24

phishing
Email Security Teams Are Drowning in Alert Triage
Most companies have poured real money into email security, and yet phishing, business email compromise and account takeovers still chew through analyst hours like nothing else on the desk. The detecti…
2026-06-24

vulnerability
Samsung KNOX Kernel Flaw Sat in Galaxy Phones for 8 Years
Researchers at LucidBit Labs have gone public with a high-severity flaw that quietly lived inside Samsung KNOX for nearly a decade. Tracked as CVE-2026-20971 with a CVSS of 7.8, the bug sat in the ker…
2026-06-24

phishing
Fake CAPTCHAs Trick Mac Users Into Installing AMOS Stealer
There is a new flavour of the ClickFix scam circulating, and this one has Mac users in its sights. Palo Alto Networks' Unit 42 has documented a campaign that uses a fake CAPTCHA page to convince visit…
2026-06-24

phishing
WhatsApp Phishing Hijacks PCs With Real IT Admin Software
A malware campaign spreading through WhatsApp has a clever wrinkle. Instead of dropping the usual custom malware on victim machines, the attackers are installing legitimate IT administration software…
2026-06-23

vulnerability
DifyTap: Dify Flaws Exposed Other Tenants' AI Chats
Researchers at Zafran Security have disclosed four vulnerabilities in Dify, the open-source platform a lot of teams use to build AI workflows, that together would have allowed one customer to quietly…
2026-06-23

vulnerability
PixelSmash: FFmpeg flaw turns a video file into Jellyfin RCE
A new flaw in FFmpeg, the video decoding library quietly doing the heavy lifting behind a huge chunk of internet media tooling, can be triggered without anyone actually watching a video. Scanning a fo…
2026-06-23

vulnerability
OpenAI's GPT-5.5-Cyber Turns on Unpatched Open Source
OpenAI has quietly handed an upgraded version of its GPT-5.5-Cyber model to a small group of defenders, the next step in the Daybreak programme it announced last month. The promise is ambitious: a mod…
2026-06-23

breach
Xsolis Phishing Breach Exposes 1.4 Million Patient Records
Xsolis, a Tennessee company that handles utilisation management and revenue cycle work for hospitals and insurers, has confirmed that a single phishing email on 20 January gave an attacker access to p…
2026-06-23

phishing
Gizmodo Readers Hit With Fake CAPTCHA ClickFix Attack
Gizmodo confirmed over the weekend that one of its accounts had been compromised, and that for a brief window on Saturday the site was serving its readers fake CAPTCHA prompts. The prompts asked visit…
2026-06-22

breach
The Underground Now Has a Search Bar for Stolen Logins
Sifting through billions of stolen credentials used to be the buyer's problem. Not anymore. Researchers at Flare have mapped a growing corner of the underground where sellers offer what they call a "s…
2026-06-22

phishing
The 'Legal Documents On The Way' Robocall, Decoded
A manager at Malwarebytes recently received one of those voicemails engineered to ruin your afternoon. A calm, official-sounding voice claiming to be from a document delivery service. Legal papers nee…
2026-06-22

phishing
Health board phishing test offered nurses a fake day off
Newfoundland and Labrador Health Services has apologised after a phishing simulation aimed at its own staff offered something almost no nurse in the country could resist: an extra paid day off. Click…
2026-06-22

vulnerability
ShapedPlugin Pro Update Channel Hijacked, Customers Backdoored
Here's an awkward one for the WordPress ecosystem. ShapedPlugin, a commercial plugin vendor, had its build and distribution pipeline compromised. The people who got caught out were the ones doing ever…
2026-06-22

vulnerability
Fake Node.js Google Ads Drop CastleStealer via OXLOADER
If you searched for something as boring as "lts version of node.js" earlier this year and clicked the top result, there is a non-zero chance you ended up somewhere considerably less boring. Elastic Se…
2026-06-22

breach
London Hydro Confirms Breach, Stays Quiet on the Details
London Hydro, the utility that keeps the lights on for more than 160,000 customers around London, Ontario, has confirmed that customer data may have been exposed in a security incident. Almost everyth…
2026-06-22

general
CSIS Got a Warrant to Clean Strangers' Routers
Canada's Security Intelligence Service has done something it had never done before. It walked into Federal Court, asked a judge for permission to reach into infected servers, home routers, doorbells a…
2026-06-22

general
INTERPOL: Cybercrime Hits 30% of Crime Across Asia-Pacific
INTERPOL's latest Asia and South Pacific Cyberthreat Assessment is not a comfortable read. More than half of member countries in the region now report that cybercrime accounts for at least 30% of all…
2026-06-22

vulnerability
Two Thirds of AI-Powered iOS Apps Are Leaking Their Keys
Researchers at Wake Forest University took apart 444 iOS apps built around large language models and found that 282 of them, roughly 64%, were handing out credentials or backend access to anyone willi…
2026-06-22

vulnerability
AryStinger Botnet Turns 4,000 Old D-Link Routers Into Proxies
A freshly documented botnet called AryStinger has rounded up more than 4,000 ageing routers and put them to work as proxies, scanners and tunnels for whoever is running the operation. The discovery co…
2026-06-21

breach
North Korea Poisons 140+ Mastra AI npm Packages
Microsoft has tied this week's Mastra AI supply chain attack to Sapphire Sleet, the North Korean group also tracked as BlueNoroff. They mostly chase cryptocurrency and financial credentials, and this…
2026-06-21

ransomware
Prinz Eugen ransomware encrypts your newest files first
A new ransomware strain called Prinz Eugen has a small, mean idea at its core: encrypt the files you cared about most recently, first. It sorts everything on disk by modification time and starts at th…
2026-06-21

vulnerability
Gravity SMTP WordPress Plugin Leaks Live Credentials
A WordPress plugin called Gravity SMTP, installed on roughly 100,000 sites, spent months quietly handing out its entire system report to anyone polite enough to send a GET request. No login, no token,…
2026-06-19

phishing
Slack and Teams Are the New Inbox for Phishing Attacks
Email is the channel defenders know best, and it shows. A fresh KnowBe4 survey of 169 security professionals at Infosecurity Europe found 83% are confident in their ability to stop email-based attacks…
2026-06-19

general
The logs you need are already in the bin
Half of large enterprises discard or never collect roughly 86 percent of the log data their systems generate. That figure comes from a Dynatrace survey of 450 senior IT leaders, and it isn't an accide…
2026-06-19

vulnerability
AutoJack: AI Browsing Agent Becomes Local RCE Vehicle
Microsoft researchers have published an exploit chain called AutoJack that turns an AI browsing agent into a remote code execution vehicle. The setup is almost embarrassingly tidy. Point the agent at…
2026-06-19

breach
Texas Parks & Wildlife Vendor Breach Hits 3M Licences
The Texas Parks and Wildlife Department has confirmed that 3,087,721 of its hunting and fishing licence customers had personal details exposed after a breach at the third-party vendor that runs its li…
2026-06-19

vulnerability
usbliter8: Unpatchable BootROM Exploit Hits Apple A12, A13
Researchers at Paradigm Shift have published usbliter8 , a working exploit that runs arbitrary code inside the SecureROM of Apple's A12 and A13 chips. Because SecureROM is burned into the silicon at t…
2026-06-19

general
Staff Are Quietly Feeding Company Data to ChatGPT
Employees are feeding enterprise data into AI tools at nearly double the rate they were a year ago. According to Zscaler's 2026 AI Threat Report, the volume of company information shifted to AI and ma…
2026-06-19

general
Interpol: Cybercrime Now ~30% of All Crime in Asia-Pacific
Interpol's 2025/2026 Asia and South Pacific Cyberthreat Assessment is not light reading. Across more than half of the 18 Southeast Asian and Pacific Island countries it surveyed, cybercrime now accoun…
2026-06-19

breach
Nintendo Employee Survey Data Stolen in TinyPulse Breach
Nintendo of America has confirmed that survey data belonging to some of its employees has been stolen. Not from Nintendo, mind you. From TinyPulse, the third-party engagement platform it uses to gathe…
2026-06-19

vulnerability
Beats Studio Buds Bluetooth Flaw Let Attackers Eavesdrop
Apple has quietly pushed a firmware update for the Beats Studio Buds after researchers showed that anyone within Bluetooth range could silently switch the microphone on and listen in. The buds did not…
2026-06-19

vulnerability
Google shrugs off Config Connector cloud takeover bug
In March, researcher Justin O'Leary reported something fairly spectacular to Google. From a single Kubernetes namespace, with zero Google Cloud permissions to his name, he could promote himself to Org…
2026-06-19

breach
Novo Nordisk Breach: One GitHub Token, 1.3TB Gone
Novo Nordisk, the Danish pharmaceutical company behind Ozempic and Wegovy, confirmed on 11 June that attackers had reached a "limited number" of internal systems and accessed pseudonymised clinical tr…
2026-06-19

ransomware
Gentlemen Ransomware's GentleKiller Disables 48 EDR Products
The Gentlemen ransomware crew is treating the job of switching off endpoint defences as a proper product line. Researchers at ESET have been tracking a bespoke tool they're calling GentleKiller, which…
2026-06-19

breach
Kodak Breach: ShinyHunters Claims 2.2 Million Records
Kodak, the 145-year-old imaging company based in Rochester, New York, has confirmed it is investigating a security incident in which attackers made off with some of its data. External cybersecurity sp…
2026-06-17

breach
FortiBleed: 73,000 Fortinet Firewall Credentials Leaked
A single exposed server has spilled VPN credentials for 73,932 Fortinet and FortiGate firewalls, and the affected organisations read like a roll call of the global economy. Researcher Bob Diachenko fo…
2026-06-17

general
The Fake Job Applicant Who Walked Into the Firm Hunting Him
There is a specific kind of irony in a North Korean fake IT worker applying for a job at the company that investigates North Korean fake IT workers. That is exactly what landed in the inbox of risk in…
2026-06-17

general
Google to Use UK and EU IP Addresses for Ad Tracking
From 3 August 2026, Google will begin using IP addresses to identify individual devices for ad measurement and personalisation across the UK, the EEA and Switzerland. Google already receives those add…
2026-06-17

general
75% of UK Infrastructure Attacks Now Linked to Nation-States
Britain's cyber chief used his annual lecture at RUSI this week to land a fairly blunt message. Of the 200-plus incidents the National Cyber Security Centre handled against critical national infrastru…
2026-06-17

breach
iRhythm Breach: Hackers Talked Their Way Into Patient Data
iRhythm Holdings, the cardiac monitoring company that has analysed more than two billion hours of heartbeat data from over 12 million patients, has told the SEC that attackers made off with patient he…
2026-06-16

phishing
ScarCruft Uses Fake Microsoft Alerts to Drop Python RAT
North Korea's APT37, the group better known as ScarCruft, has been caught running a spear-phishing campaign built on one of the oldest pretexts going: a fake Microsoft Account security warning. Accord…
2026-06-16

phishing
FTC: $3.5B Lost to Imposter Scams in 2025, Facebook Led
The FTC has finished its accounting for 2025, and the headline number is ugly. Americans lost $3.5 billion to imposter scams over the year, nearly triple what the same category cost in 2020. It was al…
2026-06-16

vulnerability
SimpleHelp Flaw Lets Attackers Create Rogue Technician Accounts
A critical flaw in SimpleHelp's remote management software lets unauthenticated attackers create their own privileged technician accounts and waltz past multi-factor authentication on the way in. Trac…
2026-06-16

general
UK to ban under-16s from social media by spring 2027
Keir Starmer's government has decided that British children under 16 should not be on social media, and it wants the law on the books before Christmas. Enforcement is pencilled in for spring 2027. Tik…
2026-06-16

ransomware
Ransomware halts crushing at Mackay Sugar mills
Mackay Sugar, which operates three cane-processing mills in Queensland and ranks as Australia's second-largest raw sugar producer, spent most of a week trying to get its operations back on their feet…
2026-06-16

phishing
Americans Lost $893M to AI Scams in 2024, FBI Says
The FBI's 2025 Internet Crime Report has finally put a price tag on something most people in security have been muttering about for a year: AI scams work, and they work at scale. Americans filed 22,36…
2026-06-08

phishing
FBI Dismantles Outsider Enterprise Phishing Service
The FBI, Google and Black Lotus Labs have taken down one of the biggest phishing-as-a-service operations ever documented. The group, known as Outsider Enterprise, ran out of China, coordinated on Tele…
2026-06-14

vulnerability
Copilot Bricked a Surface and Exposed a Hidden Firmware Flaw
Here is a story with an unlikely protagonist. Australian security researcher Jack Darcy asked Microsoft Copilot to help adjust the screen backlight on his Surface. Copilot wrote a Python script, ran i…
2026-06-12

general
Anthropic Pulls Fable 5 and Mythos 5 After White House Order
Anthropic has taken its two newest models, Fable 5 and Mythos 5, offline after the Trump administration issued a Friday afternoon directive ordering the company to block access by foreign nationals. I…
2026-06-13

general
Fake Spotify Premium PowerShell "Hack" Drops Vidar Infostealer
Researchers at ReversingLabs have found two campaigns running on TikTok and Instagram Reels that push Vidar, an infostealer that has been kicking around since 2018 and picked up a quiet stability and…
2026-06-12

phishing
1.5M Malicious Domains, Built Like a Factory
Researchers digging through VirusTotal data from January to May 2026 tallied roughly 1.5 million malicious domains, each flagged by at least five independent scanning engines. Nine in ten were registe…
2026-06-12

vulnerability
OpenClaw AI agent tricked by contact cards and polite emails
Two research teams spent the week poking at OpenClaw, the self-hosted AI agent that has spread fast since its late-2025 launch. Both walked away with the same uncomfortable answer. The agent does what…
2026-06-12