Gmail Users at Phishing Risk After Salesforce Data Theft; Cloudflare Blocks Record DDoS Attack via Google Cloud Salesforce breach exposed data, risking 2.5B Gmail users to phishing; Google urges enhanced protections. Cloudflare blocked record 11.5 Tbps DDoS attack from compromised Google Cloud accounts. Azure AD misconfiguration leaks app credentials, risking Microsoft 365 tenant compromise; immediate action urged. Infostealer malware dominates cyber threats, targeting credentials, cookies, and session data; defense strategies needed. Malicious npm package impersonates Nodemailer, drains crypto wallets via Electron tampering. Total 908 words · 4 mins read18 More Stories5 hours ago45
WhatsApp wins $167M lawsuit against NSO Group for Pegasus spyware; Zscaler data breach via Salesloft Drift exposes customer data WhatsApp wins $167M lawsuit against NSO Group for Pegasus spyware attacks in 2019. Zscaler data breach exposed customer data via Salesloft Drift due to compromised Salesforce credentials. Chrome and Firefox web browsers are targeted by sophisticated attacks exploiting vulnerabilities. Tenable reports multiple unpatched, high-severity vulnerabilities in various Linux distributions. Next.js vulnerability (CVE-2025-29927) allows unauthenticated authorization bypass via x-middleware-subrequest header. Total 794 words · 4 mins read14 More StoriesYesterday, 9:43 AM31
Ransomware Attacks Surge Globally; Unpatched Linux/Unix Vulnerability Allows Privilege Escalation DarkMirror H1 2025 report: Ransomware attacks surged, impacting 3,535 victims globally, U.S. most affected. Tenable: Unpatched CVE-2025-22840 allows privilege escalation on Linux/Unix with CVSS v3 score of 9.8. ScarCruft's Operation HanKook Phantom delivers RokRAT malware, targeting South Korean academics to steal data. AI Waifu RAT: Malware weaponizes AI and social engineering, targets niche online communities for system access. Censys warns: 300,000+ Plex Media Servers vulnerable to CVE-2025-34158; Git CVE-2025-48384 also exploited. Total 1077 words · 5 mins read19 More StoriesMon, 9:44 AM26
Nx Build System Compromised by Malware; Data Breaches Hit Google, Air France, and KLM Nx build system compromised on August 26, 2025; malware targeted crypto wallet data. Google, Air France, and KLM experienced data breaches in August 2025. Attackers exploited Velociraptor via msiexec and Cloudflare Workers for illicit network access. Total 152 words · 1 min readRead DetailsSun, 9:49 AM3
AI Generates Exploits in Minutes; Ransomware Attacks Surge by 49% AI can now generate software exploit code in under 15 minutes, report reveals. Ransomware attacks surged 49% this year, with over 200 groups active, NordStellar reports. Facebook malvertising campaign spreads Brokewell spyware to Android users via fake TradingView ads. Cybercriminals are misusing Claude AI for extortion, fraud, and ransomware attacks: Anthropic. US sanctions Russian, Chinese entities for aiding North Korean IT workers in revenue generation. Total 1279 words · 6 mins read23 More StoriesSat, 9:44 AM39
TransUnion Data Breach Impacts 4.4 Million; SquareX Reveals Passkey Vulnerability TransUnion data breach exposed personal data of 4.4 million customers via third-party app. SquareX revealed passkey flaw threatening 15 billion accounts; criticism questions real-world impact. Salt Typhoon APT, backed by Chinese firms, breached 600 organizations globally, targeting critical sectors. Silver Fox APT exploits WatchDog driver to bypass Windows security, Check Point Research reports. Europe faces 3-4x higher ransomware rates; Safepay group active amid 179% attack surge. Total 613 words · 3 mins read10 More StoriesFri, 9:44 AM24
Claude AI Weaponized in Ransomware; Salt Typhoon APT Targets Global Infrastructure Anthropic reports Claude AI weaponized for ransomware attacks on 17 organizations, demanding over $500,000. US links Chinese companies to Salt Typhoon APT, targeting 80+ countries, stealing 1M+ data sets. Storm-0501 uses 'steal-and-destroy' ransomware in Azure, compromising Active Directory and cloud domains. Attackers used a fake TASPEN Android app to steal banking credentials from Indonesian pensioners. IBM report: US data breach costs hit $10.22M amid rising AI-driven cyber risks. Total 754 words · 4 mins read13 More StoriesThu, 9:45 AM29
Citrix NetScaler CVE-2025-7775 Actively Exploited; Google Chrome Patches Zero-Day and Use-After-Free Vulnerabilities Citrix NetScaler CVE-2025-7775 RCE vulnerability actively exploited; immediate patching is critical. Google patched Chrome for CVE-2025-9478 and CVE-2025-5419; users should update immediately. Zscaler found 77 malicious Android apps on Google Play with Joker and Anatsa trojans. Cache deception attack tricks CDNs, exposing protected resources and sensitive data. Hook v3 Android malware combines ransomware, spyware, and banking trojan functions. Total 974 words · 4 mins read18 More StoriesAug 27, 9:44 AM43
Zendesk Android SDK Zero-Click Vulnerability; UpCrypter Malware Targets Windows Users Zendesk Android SDK zero-click flaw allows account hijacking; patch released after disclosure. UpCrypter malware targets Windows users via email, granting hackers full system control. Lab Dookhtegan claims disruption of communications on 64 Iranian tankers/containerships. New AI attack hides data-theft prompts within images, bypassing AI guardrails. Kimsuky APT data leak exposes infrastructure, tactics, and stolen South Korean certificates. Total 1286 words · 6 mins read22 More StoriesAug 26, 9:43 AM39
Apple iOS Zero-Click Exploit Patched; New macOS Infostealer Mac.c Targets iCloud Keychain Apple patched iOS zero-click RCE (CVE-2025-43300) in iOS 18.6.2, iPadOS 18.6.2, macOS Sequoia 15.6.1. New macOS infostealer Mac.c targets iCloud Keychain, browser passwords, and crypto wallets for $1,500/month. SendGrid exploited in credential harvesting attacks using phishing emails to bypass security gateways. Android malware posing as Russian FSB antivirus spies on conversations and exfiltrates data. Total 303 words · 2 mins read2 More StoriesAug 25, 9:45 AM8