Cyber Incidents briefings
Confirmed breaches and intrusions at named organizations: what was accessed, how the attackers got in, and what the affected parties have disclosed.
- Small ransomware crew Titan turns its aim on Italy 2026-08-22
- Mexico is suddenly all over the ransomware leak sites 2026-08-22
- CareCloud breach total jumps from 345,000 to 3.75 million 2026-08-21
- Cars turned into proxy bots by their own software updater 2026-08-21
- Microsoft 365 token theft is now a point and click job 2026-08-21
- npm pulled the packages, the malware kept downloading 2026-08-20
- Fake investment sites tied to a $187 million network 2026-08-20
- Industrial hacks aimed at physical damage are rising 2026-08-20
- Fake download sites beat the hover check and the signature 2026-08-19
- Scam sites pose as wallet safety checks to drain crypto 2026-08-19
- Hackers use AI scripts to probe Siemens plant controllers 2026-08-19
- Fake court notices spread AsyncRAT across Colombia 2026-08-19
- Forum seller claims staff data from Microsoft Entra tenants 2026-08-19
- A fake Claude Code guide drops a six-stage Mac stealer 2026-08-18
- Heights Finance breach exposes SSNs and bank details 2026-08-18
- Fake pharmacy refund page steals Italians' card details 2026-08-18
- Fake quote emails drop a stealer that kills antivirus 2026-08-18
- Fake Trezor app kills the real one to steal your seed 2026-08-17
- Fake VS Code extensions mapped developers, not their code 2026-08-16
- Fake state fine notices dominate Italy's phishing week 2026-08-14
- UK jails The Com member who blackmailed 117 girls 2026-08-14
- Stolen GitHub tokens used to clone thousands of repos 2026-08-13
- Underground sellers make antivirus evasion a paid service 2026-08-13
- Scammers watch you type your card on fake checkout pages 2026-08-13
- Ransomware crews pile onto Italy's industrial firms 2026-08-13
- Ransomware claims against Indian firms tripled in a month 2026-08-12
- Hacked WordPress sites push a stealer via the Deno runtime 2026-08-12
- Fake bank calls turn one card tap into instant fraud 2026-08-12
- Steam hardware buyers' delivery data stolen in Europe 2026-08-12
- Fake CCleaner site plants spyware inside Chrome 2026-08-11
- Android TV box botnet learns to fake real browser traffic 2026-08-11
- Fake CNN and Avast downloads hand PCs to attackers 2026-08-11
- Crypto-stealing botnet takes its orders from a blockchain 2026-08-11
- Fake Tesla token site sold as a $500 scam-in-a-box kit 2026-08-11
- Hackers flood npm with 993 fake packages to hit one bank 2026-08-11
- New Abyssos malware hijacks browser sessions on Windows PCs 2026-08-10
- Banking trojans slip onto Google Play inside dropper apps 2026-08-10
- Hyundai Turkey breach exposes job applicants' test results 2026-08-09
- Ransomware crews hit Southeast Asian hotels, not hospitals 2026-08-09
- WordPress plugins hijacked without changing a line of code 2026-08-09
- Hackers reached a power plant through its mobile network 2026-08-09
- Latin America's public bodies keep appearing on leak sites 2026-08-08
- Snowflake hacker pleads guilty over 165 breaches 2026-08-07
- Doxing service sells lookups on 230 million South Americans 2026-08-07
- npm worm was set to sign its malware with real provenance 2026-08-07
- Cloud extortion crew steals secrets via service accounts 2026-08-06
- Satellite attacks went from TV pranks to wiper malware 2026-08-06
- Fake Mac download pages now hide from security scanners 2026-08-05
- Crime service slips fake texts into real bank threads 2026-08-05
- Hackers stack six remote-access tools on N-able servers 2026-08-05
- npm worm spread itself to 400 packages, Microsoft says 2026-08-05
- Fake browser pop-ups on Cloudflare pages steal MFA logins 2026-08-04
- Hijacked npm packages steal cloud keys from developers 2026-08-04
- Scammers hijack WhatsApp accounts with fake voting links 2026-08-04
- Fake court notices in Colombia install a data stealing worm 2026-08-04
- Fake exploit code is stealing security researchers' secrets 2026-08-04
- Russian access broker's server exposes Ukraine spying 2026-08-03
- Ransomware hits Brazil's schools using stolen logins 2026-08-03
- Fake Roblox cheat hands attackers full control of PCs 2026-08-03
- Fake document files give hackers remote control of PCs 2026-08-03
- Fake Bahrain alert app spies on phones and steals logins 2026-08-03
- Mac malware in Xcode projects hijacks Chrome and Telegram 2026-07-31
- Hackers lock water utilities out of internet-facing PLCs 2026-07-31
- Hackers now poison open source packages instead of breaking into vendors 2026-07-31
- Fake tax penalty notices on WhatsApp are installing bank draining malware 2026-07-30
- Cryptominers hijack Linux servers and delete the logs that would catch them 2026-07-30
- AtlasRAT looks factory-built, not like one gang's private tool 2026-07-30
- Brazilian banking trojan hijacks WhatsApp to spam victims' contacts 2026-07-30
- Fake World Cup ticket sites beat card checks by stealing passcodes 2026-07-29
- Hackers turn hacked SQL servers into mining rigs and VPN relays 2026-07-29
- Phishing now starts most intrusions as attackers beat MFA 2026-07-29
- Vatican prayer app exposed 700,000 users for six months 2026-07-29
- A 200,000-device botnet now hides its servers on the blockchain 2026-07-29
- Fake Odyssey movie downloads deliver malware within hours of release 2026-07-21
- Fake game downloads spread an infostealer using a blockchain trick 2026-07-20
- Abbott probes two breaches as extortion gangs claim patient data theft 2026-07-20
- Fake fix prompts spread ACR Stealer to raid corporate browser logins 2026-07-17
- New macOS stealer locks your Mac until you type your password 2026-07-16
- Russian-speaking hackers push crypto stealers through fake app installers 2026-07-16
- Self-spreading cryptominer hijacks weakly secured Linux SSH servers 2026-07-15
- New AtlasRAT trojan runs entirely in memory to evade antivirus 2026-07-15
- Hackers exploit a GitHub Actions flaw to plant npm backdoors 2026-07-14
- Fake Tomorrowland ticket sites are stealing money and IDs 2026-07-14
- Hackers exploit a SQL injection flaw to hijack a server and mine crypto 2026-07-14
- ShinyHunters leaks data on 2.3 million Moody Bible supporters 2026-07-14
- Fake invoices and proposals target Korean firms with stealer malware 2026-07-13
- AssuranceAmerica breach exposes 6.9 million driver license numbers 2026-07-10
- RedHook Android trojan turns debugging tools into a takeover path 2026-07-10
- Fake software cracks push Vidar stealer and a hidden Monero miner 2026-07-08
- Hackers hijack Mexican bank customers with a hands-on fraud toolkit 2026-07-08
- A fake report scam is stealing Reddit and Discord accounts 2026-07-08
- Attacks on industrial control systems fall to a three-year low 2026-07-07
- Fake job applications spread Vidar infostealer that hides on Steam and Telegram 2026-07-07
- Attackers hijack Microsoft 365 accounts using Microsoft's own login page 2026-07-06
- Fake Cloudflare page hidden in an npm package redirects victims to a phishing site 2026-07-05
- Google and FBI disrupt NetNut proxy network of 2 million devices 2026-07-04
- Companies miss most intrusions, some for years, Kaspersky finds 2026-07-02
- Phishing service steals Microsoft 365 logins and survives MFA 2026-07-01
- Fake software sites hide a remote tool that drops AsyncRAT 2026-07-01
- New phishing kit hijacks Microsoft 365 accounts and survives password resets 2026-07-01
- Fake traffic fine texts in Serbia steal drivers' card details 2026-07-01
- RustDuck botnet rewrites itself in Rust as it grows DDoS firepower 2026-06-30
- Microsoft 365 account-hijack kit spreads on a Russian cybercrime forum 2026-06-30
- Hackers disable Windows Defender and dump credentials after a ColdFusion break-in 2026-06-30
- Hackers target Japanese hotels with a RAT that hides on the TON blockchain 2026-06-30
- Fake microphone app ClearMic hides a password and crypto stealer 2026-06-29
- Fake Apple security update tricks Mac users into installing an infostealer 2026-06-29
- Microsoft pulls 119 Edge extensions that secretly served malware to millions 2026-06-29
- Phishing Campaign Hijacks Chrome Sessions to Bypass MFA 2026-06-27
- A cheap subscription trojan has infected over 62,000 computers worldwide 2026-06-25
- Peter Thiel's elite network exposed personal data of 200 members 2026-06-25
- Microsoft and Europol disrupt the StealC and Amadey malware networks 2026-06-24
- Scammers hijack legitimate sites' search rankings to fuel World Cup fraud 2026-06-24
- Fake stores hit European shoppers with bogus Samsung and World Cup deals 2026-06-23
- Breach exposes passport and license data of 3 million Texans 2026-06-23
- Icarus extortion crew breaches Klue and steals customer Salesforce data 2026-06-22
- Hackers spray Fortinet and Sophos firewalls to steal corporate logins 2026-06-20
- New Android trojan Rokarolla takes over phones to loot 200 apps 2026-06-18
- Leaked attacker server reveals an advanced intrusion campaign across Mexico 2026-06-17
- 24 billion stolen credentials found in a massive exposed database 2026-06-17
- Fake Stars and Reviews Push a Crypto-Stealing Clipboard Hijacker 2026-06-17
- AryStinger botnet hijacks 4,300 old routers into a global attack relay 2026-06-17
- Hackers abuse GitHub to phish customers of a dozen Mexican banks 2026-06-17
- Hackers rig South Asian University website to spread malware 2026-06-16
- Fake World Cup streaming sites funnel fans into scams and malware 2026-06-16
- Cardiac monitoring firm iRhythm hit by data theft and extortion 2026-06-16
- Phishing kit breaks into Microsoft 365 accounts without stealing passwords 2026-06-16
- Malware-for-hire kit hijacks WordPress sites and hides on the blockchain 2026-06-16
- Malicious Steam wallpapers hijack gamers' accounts and drop backdoors 2026-06-16
- New malware hides its command servers on the Ethereum blockchain 2026-06-16
- Hackers steal gamers' Steam accounts with fake FACEIT pages 2026-06-14
- Hackers backdoor 1,500 Arch Linux packages to steal developer secrets 2026-06-14
- FBI and Google dismantle a $1.9 billion AI phishing operation 2026-06-14
- ShinyHunters breached universities through an Oracle PeopleSoft zero-day 2026-06-12
- VRChat says hackers stole data on 2.4 million users 2026-06-11
- Fake free Spotify and Windows hacks on TikTok push infostealers 2026-06-11
- Fake Mac app installers trick users into running infostealers 2026-06-11
- SniperDz phishing service turns social media lures into mass fraud 2026-06-11
- Hackers hide card skimmers inside real WooCommerce checkout pages 2026-06-10
- New malware service drains crypto wallets and bypasses Chrome encryption 2026-06-10
- Attackers can blind AWS and Google Cloud logs to hide intrusions 2026-06-10
- Scammers Ran 12,000 Fake Ad Campaigns on Meta Across Asia Pacific 2026-06-09
- Fake BlueWallet Mac App Steals Crypto and Swaps Wallet Addresses Mid-Copy 2026-06-09
- Fake Developer Tool Sites Hijack Downloads to Spread Stealers 2026-06-06
- Fake Mac Apps Hijack Chrome and Steal Documents Through Google Ads 2026-06-05
- Kaspersky Details Argamal RAT Distributed Through Trojanized Hentai Games 2026-06-04
- Group-IB Unmasks Smishing Error524 Phishing Operation Hiding Behind Fake Cloudflare Error Pages 2026-06-04
- GHOST STADIUM: Group-IB Maps a Billion-Dollar Fraud Ecosystem Targeting the 2026 FIFA World Cup 2026-06-01
- ClickFix via Ghost CMS: How CVE-2026-26980 Turned 700 Legitimate Websites Into Malware Delivery Nodes 2026-05-25
- 340 Million OnlyFans Records for Sale: Seller Admits No Platform Was Breached 2026-05-25
- Mirax Bot: New Android Banking MaaS Emerges on Underground Forums with HVNC, 700+ Injects, and ATO-Optimized Feature Stack 2026-03-05
- Tycoon 2FA Dismantled: Europol-Led Operation Takes Down MFA-Bypass Phishing Platform Used by Thousands of Cybercriminals 2026-03-04
- From RaidForums to LeakBase: The Succession of Major Credential Markets and the Law Enforcement Campaign to Dismantle Them 2026-03-04
- Operation LEAK: Europol-Led International Takedown Dismantles LeakBase, One of the World's Largest Stolen Data Forums 2026-03-04
- Keymous+ Launches #Op_Epstein_Gulf: DDoS Campaign Hits Jordan, Oman, and Kuwait Government Portals 2026-03-04
- Handala Claims Saudi Aramco Breach Amid Escalating Iranian Cyber Operations 2026-03-03
- Handala Claims Breach of Clalit, Israel's Largest Healthcare Network 2026-02-26
- The Hacktivist Network: Keymous+, the Holy League Alliance, and the Rise of Federated Cyber Operations 2026-02-16
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16
- Scattered Spider Q2 2025: vCenter Unmanaged VM ntds.dit Dumping, Chisel/Teleport/Pinggy Tunneling, S3 Browser Exfiltration, and Email Transport Rule Hijacking 2026-02-16
- Hive0145 Evolves Beyond Credential Theft: StarFish Backdoor and Persistent Access Mark a New Phase for Strela Stealer Operator 2026-02-16
- Threat Hunting Cobalt Strike: How Researchers Fingerprint and Infiltrate Attacker C2 Infrastructure 2026-02-16
- Hacktivism-as-a-Service: How Keymous+ Monetized Disruption Through the EliteStress DDoS Platform 2026-02-16
- Keymous+: Profile of a North African Hacktivist Collective Claiming 700+ DDoS Attacks in 2025 2026-02-16
- Handala Claims 2.1 Terabyte Breach of Israeli National Police 2026-02-16
- Two Sudanese Nationals Charged as Anonymous Sudan DDoS Empire Dismantled After 35,000 Attacks 2026-02-16
- Eduard Benderskiy Named: The Former KGB Officer Who Shielded Evil Corp from Russian Law Enforcement 2026-02-16
- Handala Deploys Wiper Malware Disguised as CrowdStrike Fix During Global Outage 2026-02-16
- TheMoon Botnet Powers Faceless Proxy Service with 40,000 Compromised SOHO Routers Across 88 Countries 2026-02-16
- NoName057(16) DDoSia 2024: FreeBSD and 32-bit Architecture Expansion, Machine GUID Fingerprinting, and Daily C2 Rotation Amid 20,000-Member Telegram Network 2026-02-16
- Emotet Returns in 2023 with OneNote Droppers, Zip-Bombing, and Thread-Hijacked Email Campaigns 2026-02-16
- NoName057(16) DDoSia Reverse Engineered: AES-GCM Target Decryption, Wagner Group Attack Anomaly, and Geopolitically-Triggered RATP Campaign 2026-02-16
- NoName057(16) DDoSia Go Rewrite: C1+P1+P2 Proxy Architecture, Token Authentication with 0xF Rolling Increment, and Automatic Bot Updater Enabling Hours-Long Recovery After Takedowns 2026-02-16
- NoName057(16) Infrastructure Exposed: Prometheus Monitoring, RabbitMQ/Redis Backend, and 84% Attack Traffic from MIRhosting and Stark Industries 2026-02-16
- Polish ABW Attributes Sejm DDoS to NoName057(16) as Retaliation for Russia Terrorism Designation, Warns of Escalating Hybrid Cyber Operations 2026-02-16
- DEV-0537 (LAPSUS$): Social Engineering, SIM Swapping, and Insider Recruitment Power a Pure Extortion and Destruction Campaign 2026-02-16
- FBI Warns Anonymous Hackers Breached Multiple U.S. Government Agencies in Year-Long Campaign 2026-02-16