Category: Data Breaches

Your blog category

  • APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains

    APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains

    A China-nexus threat actor known as APT24 has been observed using a previously undocumented malware dubbed BADAUDIO to establish persistent remote access to compromised networks as part of a nearly three-year campaign.
    “While earlier operations relied on broad strategic web compromises to compromise legitimate websites, APT24 has recently pivoted to using more sophisticated vectors targeting

  • SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny

    SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny

    The U.S. Securities and Exchange Commission (SEC) has abandoned its lawsuit against SolarWinds and its chief information security officer, alleging that the company had misled investors about the security practices that led to the 2020 supply chain attack.
    In a joint motion filed November 20, 2025, the SEC, along with SolarWinds and its CISO Timothy G. Brown, asked the court to voluntarily

  • Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity

    Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity

    Salesforce has warned of detected “unusual activity” related to Gainsight-published applications connected to the platform.
    “Our investigation indicates this activity may have enabled unauthorized access to certain customers’ Salesforce data through the app’s connection,” the company said in an advisory.
    The cloud services firm said it has taken the step of revoking all active access and refresh

  • ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

    ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

    This week has been crazy in the world of hacking and online security. From Thailand to London to the US, we’ve seen arrests, spies at work, and big power moves online. Hackers are getting caught. Spies are getting better at their jobs. Even simple things like browser add-ons and smart home gadgets are being used to attack people.
    Every day, there’s a new story that shows how quickly things are

  • CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat

    CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat

    CTM360 has identified a rapidly expanding WhatsApp account-hacking campaign targeting users worldwide via a network of deceptive authentication portals and impersonation pages. The campaign, internally dubbed HackOnChat, abuses WhatsApp’s familiar web interface, using social engineering tactics to trick users into compromising their accounts.
    Investigators identified thousands of malicious URLs

  • New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

    New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

    Cybersecurity researchers have disclosed details of a new Android banking trojan called Sturnus that enables credential theft and full device takeover to conduct financial fraud.
    “A key differentiator is its ability to bypass encrypted messaging,” ThreatFabric said in a report shared with The Hacker News. “By capturing content directly from the device screen after decryption, Sturnus can monitor

  • Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt

    Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt

    Threat actors with ties to Iran engaged in cyber warfare as part of efforts to facilitate and enhance physical, real-world attacks, a trend that Amazon has called cyber-enabled kinetic targeting.
    The development is a sign that the lines between state-sponsored cyber attacks and kinetic warfare are increasingly blurring, necessitating the need for a new category of warfare, the tech giant’s

  • TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

    TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

    Threat actors are leveraging bogus installers masquerading as popular software to trick users into installing malware as part of a global malvertising campaign dubbed TamperedChef.
    The end goal of the attacks is to establish persistence and deliver JavaScript malware that facilitates remote access and control, per a new report from Acronis Threat Research Unit (TRU). The campaign, per the

  • WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide

    WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide

    A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, predominantly in Taiwan, the U.S., and Russia, to rope them into a massive network.
    The router hijacking activity has been codenamed Operation WrtHug by SecurityScorecard’s STRIKE team. Southeast Asia and European countries are some of the other regions where infections have

  • Application Containment: How to Use Ringfencing to Prevent the Weaponization of Trusted Software

    Application Containment: How to Use Ringfencing to Prevent the Weaponization of Trusted Software

    The challenge facing security leaders is monumental: Securing environments where failure is not an option. Reliance on traditional security postures, such as Endpoint Detection and Response (EDR) to chase threats after they have already entered the network, is fundamentally risky and contributes significantly to the half-trillion-dollar annual cost of cybercrime.
    Zero Trust fundamentally shifts