Cyber Attacks

Latest cyber attacks news, vulnerabilities, CVEs, and threat intelligence from 50+ trusted cybersecurity sources.

TA415 Cyber Espionage: How Chinese Hackers Exploit VS Code Remote Tunnels to Target U.S. Economic Policy Experts

TA415, a China-aligned cyber espionage group, exploited VS Code Remote Tunnels via spear-phishing emails to target U.S. economic policy experts, think tanks, and government officials. The attack leverages high-profile impersonation and policy-themed lures to infiltrate systems for long-term espionage. Immediate mitigation is critical to prevent data exfiltration and intellectual property theft.

#cybersecurity #threat-intelligence #spear-phishing

Read full article →

BreachForums Founder Sentenced: From Lenient Deal to 3-Year Prison Term for Cybercrime

Conor Fitzpatrick, founder of the BreachForums cybercrime marketplace, was sentenced to 3 years in prison after initially receiving a lenient deal for operating a platform facilitating large-scale data breaches and illegal trade of stolen data. The forum caused incalculable damage by hosting high-profile breaches, including the InfraGard FBI database and DC Health Link leaks, exposing sensitive personal and corporate data. Law enforcement's reversal of an initial non-custodial sentence underscores the severe consequences of enabling cybercrime ecosystems.

#cybercrime #data breaches #hacking forums

Read full article →

Microsoft and Cloudflare Dismantle RaccoonO365: How a Massive Phishing Network Was Shut Down

Microsoft and Cloudflare dismantled RaccoonO365, a phishing-as-a-service (PhaaS) network that compromised over 5,000 Microsoft 365 credentials across 94 countries since July 2024. The operation involved seizing 338 malicious domains used to automate and scale credential-stealing attacks. Affected organizations must audit compromised accounts and enhance phishing defenses immediately.

#phishing #cybersecurity #microsoft-365

Read full article →

Microsoft and Cloudflare Dismantle RaccoonO365: A Major Blow to Phishing-as-a-Service

Microsoft and Cloudflare dismantled RaccoonO365, a phishing-as-a-service (PhaaS) platform targeting Microsoft 365 credentials via 338 malicious websites. This operation disrupted infrastructure and exposed the platform's leader, Joshua Ogundipe, protecting thousands of global Microsoft 365 users from credential theft and potential data breaches.

#phishing #cybercrime #microsoft 365

Read full article →

Scattered Spider Cybercrime Group Targets US Bank Despite Retirement Claims

The Scattered Spider cybercrime group, despite claiming retirement, launched a digital intrusion into a US bank, demonstrating their continued focus on financial sector targets. This resurgence highlights the persistent risk financial institutions face from sophisticated, adaptable threat actors. Heightened vigilance and advanced threat detection are urgently needed to mitigate similar attacks.

#cybercrime #financial cybersecurity #threat actors

Read full article →

Cybersecurity Skepticism: Did Scattered Spider Really Disband? Experts Weigh In

Fifteen ransomware gangs, including the high-profile Scattered Spider, have announced their disbandment, raising concerns about the authenticity of these claims. The impact could be significant if these groups rebrand or continue operations under new identities, potentially affecting businesses worldwide with ransomware attacks. Vigilance and proactive threat intelligence are critical to verify disbandment claims and mitigate risks.

#ransomware #cybersecurity #threat-intelligence

Read full article →

Scattered Spider Cybercrime Group Targets Financial Sector: New Attacks Debunk Retirement Claims

The cybercrime group Scattered Spider (UNC3944) has reactivated operations and is targeting financial institutions with lookalike domains and social engineering tactics. This attack threatens global financial services, including banks, payment processors, and fintech companies, potentially leading to credential theft, malware deployment, and financial fraud. Organizations must verify domain authenticity and enhance employee training to mitigate risks.

#cybersecurity #threat-intelligence #financial-cybercrime

Read full article →

BreachForums Founder Sentenced to 3 Years: Cybercrime Forum Admin Faces Justice for CSAM Possession

Conor Brian Fitzpatrick, founder of the cybercrime forum BreachForums, was resentenced to 3 years in prison for operating an illicit platform facilitating stolen data trade and possessing child sexual abuse material (CSAM). This case highlights the DOJ's crackdown on cybercrime forums enabling identity theft, fraud, and illegal services, with Fitzpatrick's actions directly impacting law enforcement efforts to dismantle such platforms.

#cybercrime #breachforums #csam

Read full article →

Microsoft Disrupts RaccoonO365 Phishing Operation: 338 Domains Seized and Alleged Mastermind Identified

Microsoft seized 338 domains linked to RaccoonO365, a phishing-as-a-service platform targeting Microsoft 365 credentials. Over 5,000 credentials were stolen, netting $100,000 in illicit gains, with the alleged mastermind identified. Users of Microsoft 365 are at risk of credential theft and financial fraud through sophisticated fake login pages.

#phishing #cybersecurity #microsoft 365

Read full article →

BreachForums Admin Resentenced: 3 Years in Prison for Hacking Forum Operator

Conor Brian Fitzpatrick, 22-year-old admin of the BreachForums hacking platform, was resentenced to 3 years in prison after a federal appeals court overturned his initial lenient sentence of time served and 20 years supervised release. The case highlights the legal consequences of operating platforms that facilitate cybercrime, with global implications for cybercriminal ecosystems and law enforcement. Fitzpatrick's platform enabled the trade of stolen data, malware, and attack tools, impacting thousands of users and victims worldwide.

#cybersecurity #hacking #legal action

Read full article →

Russia’s Hypersonic Missile Test Near NATO Borders: Escalating Tensions and Strategic Implications

Russia conducted hypersonic missile tests near NATO borders, accompanied by drone incursions into Polish and Romanian airspace, escalating geopolitical tensions and testing NATO's military readiness. This provocative display of advanced military capabilities directly threatens NATO member states' air defense systems and regional stability. Immediate diplomatic and military countermeasures are required to de-escalate the situation and reinforce collective defense protocols.

#hypersonic missile #nato #geopolitical tensions

Read full article →

FBI Alert: UNC6040 and UNC6395 Hackers Target Salesforce Data – What You Need to Know

The FBI issued a FLASH alert warning about UNC6040 and UNC6395 threat actors actively compromising Salesforce environments to steal sensitive data and extort victims. Organizations using Salesforce must urgently assess their security posture, monitor for suspicious activity, and implement mitigation strategies to prevent compromise, as these attacks pose a significant risk to cloud-based CRM platforms and customer data integrity.

#cybersecurity #data breaches #threat intelligence

Read full article →

Global Cybersecurity Threats: Key Incidents and Trends in September 2025

In September 2025, cybercriminal groups UNC6040 and UNC6395 targeted Salesforce instances, exploiting vulnerabilities to steal data and extort victims. Organizations using Salesforce are at high risk of credential theft and ransomware. Additionally, a new HybridPetya ransomware variant bypassed UEFI Secure Boot, threatening enterprise systems with destructive encryption attacks. Immediate security updates and monitoring are critical to mitigate risks.

#cybersecurity #data breach #malware

Read full article →

VoidProxy: The Emerging Phishing-as-a-Service Threat Targeting Microsoft 365 and Google Accounts

VoidProxy, a new phishing-as-a-service (PhaaS) platform, enables cybercriminals to bypass multi-factor authentication (MFA) and target Microsoft 365, Google, and SSO-protected accounts like Okta. This service lowers the barrier for sophisticated phishing attacks, increasing risk for organizations and individuals relying on cloud-based authentication. Immediate adoption of enhanced security measures and user education is critical to mitigate exposure.

#phishing #cybersecurity #threat-intelligence

Read full article →

FBI Alert: UNC6040 and UNC6395 Cyber Groups Target Salesforce Platforms for Data Theft

Cybercriminal groups UNC6040 and UNC6395 are actively exploiting Salesforce platforms via phishing, credential harvesting, and misconfigured security settings to steal sensitive data and extort victims. This poses a severe risk to organizations relying on Salesforce for CRM, potentially exposing customer data, financial records, and proprietary information. Organizations are urged to audit access controls and implement advanced monitoring immediately.

#cybersecurity #data theft #salesforce

Read full article →

FBI Alert: UNC6040 and UNC6395 Cybercriminal Groups Target Salesforce Platforms for Data Theft and Extortion

The FBI issued a flash alert warning about cybercriminal groups UNC6040 and UNC6395 targeting Salesforce platforms for data theft and extortion. UNC6040 uses vishing and social engineering to trick employees into granting access to malicious apps, while UNC6395 exploits compromised OAuth tokens in the Salesloft Drift app. Major companies such as Google, Cisco, Adidas, and Allianz have already been affected, requiring immediate mitigation actions.

#fbi #salesforce #cybersecurity

Read full article →

Russian Cyber Warfare: How Putin’s Offensive Cyber Operations Shape Global Security

Russia has systematically integrated offensive cyber operations into its foreign policy under Putin, targeting democratic processes, critical infrastructure, and intelligence systems. The impact spans global governments, corporations, and individuals, reshaping international security dynamics through election interference, infrastructure disruptions, and espionage campaigns. These operations enable Russia to project power with minimal risk of direct military confrontation.

#cybersecurity #russia #cyber-warfare

Read full article →

Panama Ministry of Economy Confirms Cyberattack: INC Ransomware Group Claims Responsibility

The Panama Ministry of Economy and Finance (MEF) confirmed a cyberattack on one of its computers, attributed to the INC ransomware group. The incident highlights the vulnerability of government institutions to ransomware threats, with potential risks to sensitive citizen data and essential services. Immediate containment and forensic investigation are required to assess the full scope of the breach.

#cybersecurity #ransomware #data breach

Read full article →