Security

New Microsoft Office zero-day under active attack, patch now

Microsoft’s Security Response Center pushed an urgent Patch Tuesday fix after a new zero-day targeting earlier versions of Microsoft Office 365 surfaced in active attacks – and companies are being told to patch immediately.
Read more about New Microsoft Office zero-day under active attack, patch now

North Korea is turning open-source projects into malware traps

North Korea is doubling down on a familiar playbook by weaponizing trust in open-source software and developer workflows. The latest campaign builds on techniques seen in previous DPRK-linked fake-recruiter and supply-chain attacks, but shifts focus to VS Code automation and disguised font files.
Read more about North Korea is turning open-source projects into malware traps

Crunchbase confirms hack by ShinyHunters, 2M records up for grabs

Crunchbase, a predictive private company intelligence platform, has confirmed a data breach after the notorious ShinyHunters cybercrime group published files supposedly stolen from its systems.
Read more about Crunchbase confirms hack by ShinyHunters, 2M records up for grabs

14M Panera Bread customer records leaked: What do we know so far?

Hackers have claimed responsibility for a cyberattack against Panera Bread, a major American restaurant chain, that allegedly resulted in the leak of millions of customer and employee records.
Read more about 14M Panera Bread customer records leaked: What do we know so far?

State employee in Texas? You're now banned from using Shein, Alibaba products

Texas will bar its employees from using Shein, Alibaba and TP-Link hardware and software, the governor said in a statement on Monday, saying his state made the decision to protect the "privacy of Texans" from the Chinese government.
Read more about State employee in Texas? You're now banned from using Shein, Alibaba products

North Koreans now using AI-generated PowerShell backdoor to target devs

Konni, a North Korean threat actor, has been using PowerShell malware generated using AI tools to attack developers and engineering teams in the blockchain sector. The phishing campaign has targeted users in Japan, Australia, and India.
Read more about North Koreans now using AI-generated PowerShell backdoor to target devs

Data of 146K users leaked as hackers claim Edmunds breach

Edmunds, a major American car shopping platform, has allegedly been breached by the infamous ShinyHunters cybergang.
Read more about Data of 146K users leaked as hackers claim Edmunds breach

Prisons seize inmate laptops over security flaw

The Dutch Ministry of Justice and Security has confiscated over a hundred laptops from prisoners and inmates in secure psychiatric units due to a security vulnerability.
Read more about Prisons seize inmate laptops over security flaw

Hack exposed kids’ data, Swedish sports software firm fined €565K

SportAdmin, a Swedish software supplier to sports clubs, has been fined €565,000 for failing to provide an appropriate level of security to protect personal data.
Read more about Hack exposed kids’ data, Swedish sports software firm fined €565K

Germany’s Bundesbank sees 5,000 cyber attacks per minute

The bank is under a relentless digital storm, with cyberattacks coming in by the millisecond. Officials call the situation “never-ending” and vow to counterstrike.
Read more about Germany’s Bundesbank sees 5,000 cyber attacks per minute

Hilton pulled into Cl0p’s dark‑web hit list: hotel giant denies

A notorious ransomware gang has claimed it has a new trophy. This time, it’s Hilton.
Read more about Hilton pulled into Cl0p’s dark‑web hit list: hotel giant denies

Encryption illusion: Microsoft shared keys with FBI, leaving user data vulnerable

Last year, Microsoft handed over encryption keys for its hard drive encryption software BitLocker to the FBI. The company says it simply complied with a search warrant related to a fraud investigation in Guam, but the news has raised alarm among the cybersecurity community.
Read more about Encryption illusion: Microsoft shared keys with FBI, leaving user data vulnerable

Nike data breach: Hackers post company data, but what do we know so far?

Attackers have leaked 1.4TB of what they claim is Nike data, including nearly 190,000 unique files. The Cybernews research team believes the data could be legitimate.
Read more about Nike data breach: Hackers post company data, but what do we know so far?

India hit by China-linked phishing campaign, unleashes malware to create long-term spy backdoor

A newly-uncovered espionage campaign aimed at targeted individuals is using phishing emails that impersonate the Government of India.
Read more about India hit by China-linked phishing campaign, unleashes malware to create long-term spy backdoor

Cybercrooks are now creating live, personalized phishing pages in real time

At first glance, it’s a normal and harmless webpage, but it’s able to transform into a phishing site after a user has already loaded it. In a matter of a few seconds, AI carefully crafts a landing page specifically for the victim, thus turning it into an online crime scene.
Read more about Cybercrooks are now creating live, personalized phishing pages in real time

Major leak exposes 149M credentials with Instagram, OnlyFans, TikTok passwords

An open database, likely storing data from credential-stealing malware, has exposed tens of millions of credentials. The data includes logins and passwords for popular services such as Facebook, Gmail, Netflix, Binance, and many others, researchers claim.
Read more about Major leak exposes 149M credentials with Instagram, OnlyFans, TikTok passwords

Was Nike hacked? Attackers threaten to leak apparel giants’ data

Nike, the American apparel behemoth, may have suffered a data breach. A prominent cybercriminal gang claims it has hacked the company and is threatening to release stolen data to the public.
Read more about Was Nike hacked? Attackers threaten to leak apparel giants’ data

Spyware disguised as ChatGPT is harvesting data from 1.5M VS Code developers

A massive file harvesting campaign is ongoing, targeting VS Code developers. Over 1.5 million users have downloaded knock-off extensions that function like AI coding assistants but are also bristling with spyware.
Read more about Spyware disguised as ChatGPT is harvesting data from 1.5M VS Code developers

This will get you hacked: trusting AI deepfakes, pop-ups, fake security alerts, and evolving malware

While not everyone can be conned into thinking Aquaman has fallen in love with them via Facebook, our research round-up this week highlights just how convincing some of these scams can be, thanks to AI.
Read more about This will get you hacked: trusting AI deepfakes, pop-ups, fake security alerts, and evolving malware

Europe wants "sovereign cloud" - but can it really protect data from US?

The sovereign cloud is Europe’s answer to digital independence, protecting data, AI, and critical systems from foreign control, regulatory conflicts, and geopolitical risks.
Read more about Europe wants "sovereign cloud" - but can it really protect data from US?