Category: Data Breaches

Your blog category

  • ⚡ Weekly Recap: Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more

    ⚡ Weekly Recap: Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more

    Ever wonder what happens when attackers don’t break the rules—they just follow them better than we do? When systems work exactly as they’re built to, but that “by design” behavior quietly opens the door to risk?
    This week brings stories that make you stop and rethink what’s truly under control. It’s not always about a broken firewall or missed patch—it’s about the small choices, default settings

  • FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering

    FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering

    The U.S. Federal Bureau of Investigation (FBI) has revealed that it has observed the notorious cybercrime group Scattered Spider broadening its targeting footprint to strike the airline sector.
    To that end, the agency said it’s actively working with aviation and industry partners to combat the activity and help victims.
    “These actors rely on social engineering techniques, often impersonating

  • GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool

    GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool

    The threat actor behind the GIFTEDCROOK malware has made significant updates to turn the malicious program from a basic browser data stealer to a potent intelligence-gathering tool.
    “Recent campaigns in June 2025 demonstrate GIFTEDCROOK’s enhanced ability to exfiltrate a broad range of sensitive documents from the devices of targeted individuals, including potentially proprietary files and

  • Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns

    Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns

    Facebook, the social network platform owned by Meta, is asking for users to upload pictures from their phones to suggest collages, recaps, and other ideas using artificial intelligence (AI), including those that have not been directly uploaded to the service.
    According to TechCrunch, which first reported the feature, users are being served a new pop-up message asking for permission to “allow

  • Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign

    Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign

    Threat hunters have discovered a network of more than 1,000 compromised small office and home office (SOHO) devices that have been used to facilitate a prolonged cyber espionage infrastructure campaign for China-nexus hacking groups.
    The Operational Relay Box (ORB) network has been codenamed LapDogs by SecurityScorecard’s STRIKE team.
    “The LapDogs network has a high concentration of victims

  • PUBLOAD and Pubshell Malware Used in Mustang Panda’s Tibet-Specific Attack

    PUBLOAD and Pubshell Malware Used in Mustang Panda’s Tibet-Specific Attack

    A China-linked threat actor known as Mustang Panda has been attributed to a new cyber espionage campaign directed against the Tibetan community.
    The spear-phishing attacks leveraged topics related to Tibet, such as the 9th World Parliamentarians’ Convention on Tibet (WPCT), China’s education policy in the Tibet Autonomous Region (TAR), and a recently published book by the 14th Dalai Lama,

  • Business Case for Agentic AI SOC Analysts

    Business Case for Agentic AI SOC Analysts

    Security operations centers (SOCs) are under pressure from both sides: threats are growing more complex and frequent, while security budgets are no longer keeping pace. Today’s security leaders are expected to reduce risk and deliver results without relying on larger teams or increased spending.
    At the same time, SOC inefficiencies are draining resources. Studies show that up to half of all

  • Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit

    Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit

    A new campaign has been observed leveraging fake websites advertising popular software such as WPS Office, Sogou, and DeepSeek to deliver Sainbox RAT and the open-source Hidden rootkit.
    The activity has been attributed with medium confidence to a Chinese hacking group called Silver Fox (aka Void Arachne), citing similarities in tradecraft with previous campaigns attributed to the threat actor.

  • MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted

    MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted

    Threat intelligence firm GreyNoise is warning of a “notable surge” in scanning activity targeting Progress MOVEit Transfer systems starting May 27, 2025—suggesting that attackers may be preparing for another mass exploitation campaign or probing for unpatched systems.MOVEit Transfer is a popular managed file transfer solution used by businesses and government agencies to share sensitive data

  • OneClik Malware Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

    OneClik Malware Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

    Cybersecurity researchers have detailed a new campaign dubbed OneClik that leverages Microsoft’s ClickOnce software deployment technology and bespoke Golang backdoors to compromise organizations within the energy, oil, and gas sectors.
    “The campaign exhibits characteristics aligned with Chinese-affiliated threat actors, though attribution remains cautious,” Trellix researchers Nico Paulo