September 30, 2025

Medusa Ransomware Tried to Recruit BBC Reporter

Medusa ransomware is back in the spotlight after reports surfaced of an unusual recruitment attempt. The gang allegedly contacted a BBC journalist, asking for help in hacking into a major media organization. The case shows how far ransomware groups are willing to go when traditional methods fail. A Bold Recruitment Attempt Instead of sending phishing emails or exploiting vulnerabilities, the

Medusa ransomware
September 27, 2025

Postmark MCP npm Package Stole User Emails

The Postmark MCP npm package has been exposed as a malicious module that silently stole user emails. Disguised as a legitimate client, the package highlights ongoing risks in the software supply chain and raises concerns for developers relying on npm. How the Attack Happened Security researcher Kamil “kph” Piekarski discovered that the fake package was uploaded to npm on September

Postmark MCP
September 25, 2025

European Airport Cyberattack Suspect Arrested

The recent European airport cyberattack disrupted operations across several major hubs and triggered widespread delays. Authorities confirmed the incident was tied to a little-known ransomware strain, and a suspect connected to the attack has been arrested. The case highlights growing risks in aviation cybersecurity. Disruption Across European Airports The attack caused immediate delays, system interruptions, and logistical issues for multiple

European Airport Cyberattack
September 23, 2025

Ransomware Attack Causes European Airport Disruptions

A ransomware attack has disrupted operations at several major airports across Europe, creating widespread delays and cancellations for travelers. The cybercriminals targeted key IT systems that support check-ins, boarding, and baggage handling. As staff scrambled to implement manual workarounds, passengers faced hours of uncertainty and missed connections. This large-scale disruption underscores the aviation sector’s growing dependence on digital infrastructure —

airport ransomware attack
September 22, 2025

SpamGPT Cybercrime Tool Turns Phishing into Organized Business

The rise of the SpamGPT cybercrime tool highlights a dangerous evolution in digital threats. Artificial intelligence has long been used to enhance marketing, streamline workflows, and improve customer outreach. Cybercriminals have now adopted the same playbook, transforming AI into a weaponized service. SpamGPT packages phishing operations into a polished platform that resembles a legitimate CRM system. Instead of building malicious

SpamGPT
September 20, 2025

RaccoonO365 Phishing Service Disrupted by Microsoft and Cloudflare

Microsoft and Cloudflare have joined forces to dismantle the RaccoonO365 phishing service, one of the most widespread phishing-as-a-service operations uncovered to date. The joint takedown targeted the infrastructure and domains used by cybercriminals to conduct massive credential theft campaigns against Microsoft 365 users worldwide. This disruption represents more than just the removal of malicious domains. It highlights the ongoing battle

RaccoonO365 Phishing Service
September 18, 2025

SonicWall MySonicWall Breach Forces Credential Resets

The SonicWall MySonicWall breach has prompted urgent warnings from the cybersecurity vendor. SonicWall advised all customers to reset credentials and enable multi-factor authentication after attackers gained access to customer accounts. The incident highlights the growing risks tied to vendor platforms that hold sensitive client data. Breach Overview SonicWall confirmed unauthorized activity within its MySonicWall customer portal. This platform manages product

SonicWall MySonicWall Breach
September 12, 2025

EggStreme Fileless Malware Targets Philippine Military

A newly identified threat named EggStreme fileless malware has been deployed by a suspected Chinese advanced persistent threat (APT) group. Researchers found the campaign targeting Philippine military systems, underlining the region’s rising geopolitical cyber risks. EggStreme stands out for its stealth. Instead of leaving files on disk, it executes in memory, making detection extremely difficult. This fileless design highlights the

EggStreme Fileless Malware
September 8, 2025

Google CNIL Fine: €325M Penalty for Cookie Breaches in France

The Google CNIL fine has become one of the largest penalties ever issued in France for data protection failures. France’s data regulator, the Commission Nationale de l’informatique et des Libertés (CNIL), announced a €325 million penalty against Google after uncovering two major violations. These breaches involved misleading Gmail advertisements and a lack of valid cookie consent during account creation. The

September 7, 2025

Streameast Shutdown: Police Dismantle Pirated Streaming Giant

The Streameast shutdown represents one of the most significant anti-piracy operations in recent memory. Authorities dismantled the world’s largest illegal sports streaming platform, arresting its operators and uncovering a vast money laundering scheme. With more than a billion visits annually, Streameast had become a major player in illicit broadcasting, rivaling legitimate platforms in scale and reach. The Police Operation On

Streameast Shutdown