November 5, 2025

Miljödata Data Breach Exposes 1.5 Million Records in Sweden

A large-scale cyberattack has shaken Sweden after the Miljödata data breach exposed sensitive information belonging to about 1.5 million people. The incident, affecting a major municipal software supplier, has prompted national investigations by IMY and CERT-SE. How the Breach Happened Miljödata, one of Sweden’s most widely used IT suppliers for municipalities, revealed in late August 2025 that its systems had

Miljödata Data Breach
November 4, 2025

SesameOp Exploits OpenAI Assistants API for Covert Control

Microsoft’s latest threat report has revealed a worrying trend: attackers are now using artificial-intelligence platforms as part of their command-and-control systems. The newly discovered SesameOp backdoor abuses the OpenAI Assistants API to hide its activity inside normal network traffic. Instead of relying on custom servers or shady hosting, the operators turned OpenAI’s trusted cloud service into their covert communications channel.

SesameOp Backdoor
November 2, 2025

LinkedIn Phishing Campaign Targets Finance Executives

A new LinkedIn phishing campaign is targeting finance executives with fake invitations to join an exclusive board. The attack uses professional pretexts, trusted cloud platforms, and advanced phishing methods to steal login credentials and bypass multi-factor authentication. How this LinkedIn Phishing Campaign Works The campaign begins with a direct message on LinkedIn inviting the target to join the “Executive Board”

LinkedIn Phishing
October 30, 2025

PhantomRaven Malware Targets npm Supply Chain

The PhantomRaven malware campaign has struck the npm ecosystem, compromising 126 open-source packages and putting thousands of developers at risk. Security researchers uncovered that these malicious packages were designed to exfiltrate credentials, tokens, and sensitive data directly from developer environments. This large-scale attack underscores the growing threat of supply-chain compromise in open-source software. How PhantomRaven Malware Works PhantomRaven malware infiltrates

PhantomRaven Malware
October 29, 2025

Atroposia Malware: Hackers Exploit Systems with Local Scanner

A new threat known as Atroposia malware is making waves in the cybersecurity world. Researchers have identified it as a highly advanced Remote Access Trojan (RAT) that not only grants attackers full control over compromised systems but also scans them for weaknesses. By embedding a local vulnerability scanner, Atroposia changes how cybercriminals approach exploitation, blending data theft with automated reconnaissance.

Atroposia Malware
October 25, 2025

MuddyWater Phoenix Backdoor Targets 100+ Government Entities

An Iranian-backed hacking group known as MuddyWater has launched a major cyberespionage campaign across the Middle East and Africa. Using phishing emails sent from a compromised mailbox accessed through NordVPN, the attackers targeted over 100 government organizations and diplomatic missions. The operation delivered version 4 of the group’s custom Phoenix backdoor, which enabled remote access and long-term intelligence gathering. Large-Scale

MuddyWater
October 22, 2025

GlassWorm Malware Targets VS Code and OpenVSX Registries

The discovery of GlassWorm malware marks one of the most alarming supply chain attacks targeting developers this year. The self-spreading threat infiltrated Visual Studio Code and OpenVSX registries, distributing malicious extensions that automatically infected thousands of systems. The campaign exposed how trusted open-source ecosystems can become vectors for widespread compromise. How the GlassWorm Malware Works GlassWorm malware operates with alarming

GlassWorm Malware
October 17, 2025

Sotheby’s Data Breach Exposes Employee Financial Information

Sotheby’s data breach has sparked alarm across the luxury art world. The prestigious auction house confirmed that an unknown attacker accessed internal systems, exposing sensitive financial and personal information belonging to employees. The incident occurred in late July 2025. It was discovered after suspicious activity was detected within Sotheby’s network. The company quickly launched an investigation and involved external cybersecurity

Sotheby’s Data Breach
October 14, 2025

SonicWall VPN Breach Hits Over 100 Accounts in Cyberattacks

The SonicWall VPN breach has triggered urgent warnings for organizations worldwide. Security analysts report that attackers accessed more than 100 SonicWall SSL VPN accounts using stolen credentials. The coordinated campaign, active since early October, has already affected multiple corporate environments across several countries. Investigators confirm that the intrusions relied on valid login information rather than brute-force methods. Once inside, attackers

SonicWall VPN Breach
October 10, 2025

Crimson Collective Launches Advanced AWS Attacks for Data Theft

The Crimson Collective hacker group has launched a new wave of cyberattacks aimed at Amazon Web Services (AWS) cloud environments. Their operations focus on stealing sensitive data from misconfigured instances, exposing how vulnerable cloud infrastructures can become when security practices are neglected. How the Group Infiltrates AWS Environments Researchers report that Crimson Collective exploits exposed AWS access credentials often found

Crimson Collective