A senior software developer has been found guilty of sabotaging his former employer's systems, potentially facing ten years in prison. Learn about the implications and consequences of this cyber attack.
Mirai-based botnets are exploiting a zero-day flaw in Edimax IP cameras for remote command execution. US CISA warns of the vulnerability, urging organizations to report suspicious activity. Learn more about the impact and mitigation strategies.
TA415, a China-aligned cyber espionage group, exploited VS Code Remote Tunnels via spear-phishing emails to target U.S. economic policy experts, think tanks, and government officials. The attack leverages high-profile impersonation and policy-themed lures to infiltrate systems for long-term espionage. Immediate mitigation is critical to prevent data exfiltration and intellectual property theft.
Conor Fitzpatrick, founder of the BreachForums cybercrime marketplace, was sentenced to 3 years in prison after initially receiving a lenient deal for operating a platform facilitating large-scale data breaches and illegal trade of stolen data. The forum caused incalculable damage by hosting high-profile breaches, including the InfraGard FBI database and DC Health Link leaks, exposing sensitive personal and corporate data. Law enforcement's reversal of an initial non-custodial sentence underscores the severe consequences of enabling cybercrime ecosystems.
Microsoft and Cloudflare dismantled RaccoonO365, a phishing-as-a-service (PhaaS) network that compromised over 5,000 Microsoft 365 credentials across 94 countries since July 2024. The operation involved seizing 338 malicious domains used to automate and scale credential-stealing attacks. Affected organizations must audit compromised accounts and enhance phishing defenses immediately.
Microsoft and Cloudflare dismantled RaccoonO365, a phishing-as-a-service (PhaaS) platform targeting Microsoft 365 credentials via 338 malicious websites. This operation disrupted infrastructure and exposed the platform's leader, Joshua Ogundipe, protecting thousands of global Microsoft 365 users from credential theft and potential data breaches.
The Scattered Spider cybercrime group, despite claiming retirement, launched a digital intrusion into a US bank, demonstrating their continued focus on financial sector targets. This resurgence highlights the persistent risk financial institutions face from sophisticated, adaptable threat actors. Heightened vigilance and advanced threat detection are urgently needed to mitigate similar attacks.
Fifteen ransomware gangs, including the high-profile Scattered Spider, have announced their disbandment, raising concerns about the authenticity of these claims. The impact could be significant if these groups rebrand or continue operations under new identities, potentially affecting businesses worldwide with ransomware attacks. Vigilance and proactive threat intelligence are critical to verify disbandment claims and mitigate risks.
The cybercrime group Scattered Spider (UNC3944) has reactivated operations and is targeting financial institutions with lookalike domains and social engineering tactics. This attack threatens global financial services, including banks, payment processors, and fintech companies, potentially leading to credential theft, malware deployment, and financial fraud. Organizations must verify domain authenticity and enhance employee training to mitigate risks.
Conor Brian Fitzpatrick, founder of the cybercrime forum BreachForums, was resentenced to 3 years in prison for operating an illicit platform facilitating stolen data trade and possessing child sexual abuse material (CSAM). This case highlights the DOJ's crackdown on cybercrime forums enabling identity theft, fraud, and illegal services, with Fitzpatrick's actions directly impacting law enforcement efforts to dismantle such platforms.
Microsoft seized 338 domains linked to RaccoonO365, a phishing-as-a-service platform targeting Microsoft 365 credentials. Over 5,000 credentials were stolen, netting $100,000 in illicit gains, with the alleged mastermind identified. Users of Microsoft 365 are at risk of credential theft and financial fraud through sophisticated fake login pages.
Conor Brian Fitzpatrick, 22-year-old admin of the BreachForums hacking platform, was resentenced to 3 years in prison after a federal appeals court overturned his initial lenient sentence of time served and 20 years supervised release. The case highlights the legal consequences of operating platforms that facilitate cybercrime, with global implications for cybercriminal ecosystems and law enforcement. Fitzpatrick's platform enabled the trade of stolen data, malware, and attack tools, impacting thousands of users and victims worldwide.
A cyberattack on Jaguar Land Rover (JLR) disrupted operations and supply chains, forcing layoffs of thousands of workers. The UK's largest automotive union demands a Covid-style furlough scheme to prevent mass unemployment and stabilize the sector amid the crisis.
Russia conducted hypersonic missile tests near NATO borders, accompanied by drone incursions into Polish and Romanian airspace, escalating geopolitical tensions and testing NATO's military readiness. This provocative display of advanced military capabilities directly threatens NATO member states' air defense systems and regional stability. Immediate diplomatic and military countermeasures are required to de-escalate the situation and reinforce collective defense protocols.
The FBI issued a FLASH alert warning about UNC6040 and UNC6395 threat actors actively compromising Salesforce environments to steal sensitive data and extort victims. Organizations using Salesforce must urgently assess their security posture, monitor for suspicious activity, and implement mitigation strategies to prevent compromise, as these attacks pose a significant risk to cloud-based CRM platforms and customer data integrity.
In September 2025, cybercriminal groups UNC6040 and UNC6395 targeted Salesforce instances, exploiting vulnerabilities to steal data and extort victims. Organizations using Salesforce are at high risk of credential theft and ransomware. Additionally, a new HybridPetya ransomware variant bypassed UEFI Secure Boot, threatening enterprise systems with destructive encryption attacks. Immediate security updates and monitoring are critical to mitigate risks.
VoidProxy, a new phishing-as-a-service (PhaaS) platform, enables cybercriminals to bypass multi-factor authentication (MFA) and target Microsoft 365, Google, and SSO-protected accounts like Okta. This service lowers the barrier for sophisticated phishing attacks, increasing risk for organizations and individuals relying on cloud-based authentication. Immediate adoption of enhanced security measures and user education is critical to mitigate exposure.
Cybercriminal groups UNC6040 and UNC6395 are actively exploiting Salesforce platforms via phishing, credential harvesting, and misconfigured security settings to steal sensitive data and extort victims. This poses a severe risk to organizations relying on Salesforce for CRM, potentially exposing customer data, financial records, and proprietary information. Organizations are urged to audit access controls and implement advanced monitoring immediately.
The FBI issued a flash alert warning about cybercriminal groups UNC6040 and UNC6395 targeting Salesforce platforms for data theft and extortion. UNC6040 uses vishing and social engineering to trick employees into granting access to malicious apps, while UNC6395 exploits compromised OAuth tokens in the Salesloft Drift app. Major companies such as Google, Cisco, Adidas, and Allianz have already been affected, requiring immediate mitigation actions.
Russia has systematically integrated offensive cyber operations into its foreign policy under Putin, targeting democratic processes, critical infrastructure, and intelligence systems. The impact spans global governments, corporations, and individuals, reshaping international security dynamics through election interference, infrastructure disruptions, and espionage campaigns. These operations enable Russia to project power with minimal risk of direct military confrontation.
Discover how a DDoS mitigation provider faced one of the largest packet-rate attacks in history—a 1.5 billion packets per second flood. Learn about the attack's origins, its implications for cybersecurity, and how organizations can protect themselves.
U.S. Senator Ron Wyden accuses Microsoft of 'gross cybersecurity negligence' after ransomware attacks on healthcare organizations. Learn about the FTC investigation, implications for cybersecurity, and Microsoft's response.
The Panama Ministry of Economy and Finance (MEF) confirmed a cyberattack on one of its computers, attributed to the INC ransomware group. The incident highlights the vulnerability of government institutions to ransomware threats, with potential risks to sensitive citizen data and essential services. Immediate containment and forensic investigation are required to assess the full scope of the breach.
A European DDoS mitigation service provider faced an unprecedented 1.5 billion packets per second (Bpps) attack, marking one of the largest DDoS attacks in history. Discover the implications for cybersecurity, the evolving threat landscape, and how organizations can defend against such attacks.
Discover how the cybercriminal group Scattered Spider exploited social engineering to breach Clorox, causing $380M in damages. Learn why caller verification and audit trails are critical for cybersecurity.
Discover how a historic NPM supply-chain attack compromised 10% of cloud environments, yet yielded minimal profits for hackers. Learn about the attack's impact, methods, and implications for cybersecurity.
Discover how China-linked APT41 hackers are conducting cyber espionage campaigns targeting U.S. trade officials during critical 2025 negotiations. Learn about the implications, tactics, and how organizations can protect themselves.
The Czech Republic's NUKIB agency has issued a warning about Chinese-linked cyber threats targeting critical infrastructure, highlighting risks from APT31 and vulnerable devices. Discover the implications for national security and cybersecurity best practices.
Discover how hackers executed the largest supply chain attack in history by hijacking NPM packages with over 2.6 billion weekly downloads. Learn about the phishing attack, its impact, and how to protect your systems.
Discover how the Noisy Bear threat group, allegedly of Russian origin, is targeting Kazakhstan’s energy sector with Operation BarrelFire. Learn about the phishing campaign, its implications, and the broader cybersecurity risks facing critical infrastructure.