May 29, 2025

AyySSHush Botnet Hacks ASUS Routers to Add SSH Backdoor

The newly discovered AyySSHush botnet campaign has silently compromised over 9,000 ASUS routers, installing a persistent SSH backdoor using a series of sophisticated and stealthy techniques. The campaign highlights a growing threat to home and small office routers, leveraging legitimate features to maintain control, all without deploying traditional malware. Security researchers at GreyNoise uncovered the campaign in mid-March 2025, but

AyySSHush Botnet
May 28, 2025

Coca Cola Data Breach Leaks Employee Info

In May 2025, Coca-Cola suffered a data breach - and not one, but two within days! These breaches exposed sensitive employee information and millions of internal Salesforce records, highlighting critical vulnerabilities in Coca-Cola’s security ecosystem. This incident serves as a stark reminder of the growing threat of sophisticated cybercriminals targeting multinational corporations. Everest Ransomware Targets Employee Information The first major

Coca Cola Data Breach
May 28, 2025

Adidas Data Breach Confirmed, Customer Info Leaked

Adidas has disclosed a data breach that exposed personal details of customers after a cyberattack targeted one of its external service providers. The incident, which occurred in May 2025, affected individuals who had previously contacted the company’s customer support. What Information Was Leaked? The breach involved unauthorized access to non-sensitive personal information. According to Adidas, the exposed data includes full

Adidas Data Breach
May 27, 2025

Fake VPNs and Browsers Spread Winos 4.0 Malware

In the dynamic cybercrime world, attackers are constantly refining their tactics. Their latest strategy is as deceptive as it is dangerous. Security researchers have uncovered a malicious campaign in which cybercriminals use fake VPNs and browsers to distribute malware and infiltrate Windows systems. At the heart of the campaign is Winos 4.0, a stealthy malware strain designed for persistence, data

Fake VPNs and Browsers Spread Malware
May 27, 2025

Bumblebee Malware Returns with SEO Poisoning Campaign

Bumblebee malware has re-emerged with a clever and concerning new distribution method. Threat actors are now using search engine optimization (SEO) poisoning to push trojanized versions of trusted networking tools like Zenmap and WinMTR, successfully deceiving even tech-savvy users into downloading malicious software. This campaign underscores the growing sophistication of cyber threats and the need for constant vigilance. What Is

Bumblebee Malware Returns
May 26, 2025

TikTok Videos Spread Malware via ClickFix Attacks

TikTok, the go-to platform for viral dances, life hacks, and bite-sized entertainment, has now entered the radar of cybersecurity experts for a far more sinister reason. A recent report from Trend Micro reveals that cybercriminals are using TikTok videos to spread infostealer malware in a new and deceptive tactic known as "ClickFix." What Is ClickFix? ClickFix is a social engineering

TikTok Videos Spread Malware
May 26, 2025

Operation Endgame: Europol Strikes a Blow to Ransomware

In a coordinated international crackdown, Europol, alongside law enforcement agencies from around the globe, has executed a sweeping operation that disrupted some of the world's most notorious ransomware operations. “Operation Endgame”, this large-scale effort resulted in the takedown of 300 servers, the neutralization of 650 domains, and the seizure of €3.5 million in cryptocurrency between May 19 and May 22,

Operation Endgame by Europol
May 25, 2025

Major Data Leak Exposed Passwords – Over 184 Million Affected

A major data leak exposed millions of passwords, including Facebook, Instagtam, Snapchat and Roblox credentials. The staggering database containing over 184 million login credentials from popular platforms was recently discovered, completely unprotected. This alarming security breach has put millions of users at risk of account takeover, identity theft, and other cyberattacks. The exposed data included plaintext usernames and passwords, suggesting

Data Leak Exposed Passwords
May 24, 2025

Aisuru Botnet Launches Devastating DDoS Attack

A recent attack on KrebsOnSecurity has set a new benchmark for the scale and speed of digital warfare. Central to this unprecedented 6.3 Tbps distributed denial-of-service (DDoS) attack is Aisuru, a recently discovered botnet powered by compromised Internet of Things (IoT) gadgets. Unlike traditional attacks, this one lasted less than a minute, packed enough power to cripple most online infrastructures.

Aisuru Botnet
May 23, 2025

BadSuccessor Vulnerability: A New Threat in Windows Server 2025

A newly discovered vulnerability in Windows Server 2025, dubbed "BadSuccessor", is raising serious alarms in the cybersecurity community. The flaw targets a recently introduced feature called delegated Managed Service Accounts (dMSAs). It allows attackers to escalate privileges and impersonate virtually any user in Active Directory. This includes highly privileged accounts. Discovered by researchers at Akamai, this unpatched vulnerability affects environments

BadSuccessor Vulnerability in Windows Server 2025