May 27, 2026

Ajax Data Breach Leads to Dutch Police Arrest

Dutch police arrested a 35-year-old man from the municipality of Buren on the morning of May 27 in connection with the Ajax data breach. Investigators determined he had accessed the football club's computer systems without authorization on multiple occasions earlier this year. Officers searched his home and seized computers, hard drives, and other digital storage devices as part of the

Ajax Data Breach
May 26, 2026

Ghost CMS Flaw Hijacks 700+ Sites in ClickFix Attack

A security flaw in Ghost CMS is turning trusted websites into traps. Attackers are exploiting a critical SQL injection vulnerability to hijack hundreds of sites and launch a large-scale ClickFix attack against ordinary visitors — people who have no idea the pages they trust have been weaponized. The vulnerability, tracked as CVE-2026-26980, carries a CVSS score of 9.4. It affects

Ghost CMS
May 22, 2026

Microsoft Shuts Down Fox Tempest Malware Operation

A cybercrime group called Fox Tempest turned Microsoft's own software infrastructure into a weapon. The group ran a malware-signing service that let ransomware gangs and other criminals make dangerous software look completely legitimate — and it worked for nearly a year before Microsoft shut it down. Microsoft's Digital Crimes Unit dismantled the operation in May 2026, seizing infrastructure, revoking over

Fox Tempest Malware
May 21, 2026

Teen Ran Infostealer Malware That Stole 28,000 Accounts

An 18-year-old from Odesa, Ukraine, has been identified as a key operator behind an infostealer malware campaign that compromised tens of thousands of online shoppers in the United States. Ukrainian cyberpolice, working alongside U.S. law enforcement, linked the suspect to attacks that ran throughout 2024 and into 2025 — draining credentials, hijacking accounts, and generating hundreds of thousands of dollars

Infostealer malware
May 20, 2026

How an npm Supply Chain Attack Poisoned 600 Packages

Over 600 software packages got poisoned in a single hour in the latest wave of the Shai-Hulud npm supply chain attack — and this time, the malware can forge the security badges developers trust to verify safe code. The npm supply chain attack represents a sharp escalation from a campaign that first emerged last September and has steadily grown more

npm supply chain attack
May 19, 2026

7-Eleven Confirms Data Breach Tied to ShinyHunters Gang

7-Eleven has confirmed a data breach affecting its internal systems, with the attack traced back to April 8, 2026. The 7-Eleven data breach exposed documents tied to the company's franchise application process, and the group behind it wasted no time making demands. ShinyHunters, one of the most active cybercrime groups operating today, claimed responsibility and threatened to publish stolen data

7-Eleven data breach
May 18, 2026

Russia’s Kazuar Malware Has Evolved Into a Modular P2P Botnet

A sophisticated Russian cyber espionage tool has undergone a significant transformation. Kazuar malware, long associated with a Kremlin-linked hacking group, has evolved from a standard backdoor into a fully modular, peer-to-peer botnet engineered for long-term stealth and intelligence collection. New analysis from Microsoft details exactly how far this tool has come — and why it now ranks among the most

Kazuar malware
May 15, 2026

West Pharmaceutical Hit by Ransomware Attack, Data Stolen

One of America's largest pharmaceutical manufacturers is recovering from a serious cyberattack after criminals broke into its network, made off with company data, and locked down critical systems. West Pharmaceutical Services, a Pennsylvania-based S&P 500 company, disclosed the ransomware attack to the U.S. Securities and Exchange Commission on May 7, 2026, classifying it as a material cybersecurity incident with global

West Pharmaceutical ransomware attack
May 12, 2026

JDownloader Malware Attack Replaced Official Installers

A serious JDownloader malware attack exposed users to malicious installers distributed through the software’s official website. Attackers reportedly compromised download links connected to the popular download manager and replaced legitimate files with malware-laced payloads designed to infect Windows and Linux systems. Security researchers warned that the incident highlights the growing danger of software supply chain attacks. Instead of targeting victims

JDownloader Malware Attack
May 11, 2026

NVIDIA GeForce NOW Data Breach Exposes Armenian User Data

A GeForce NOW data breach has been confirmed by NVIDIA, exposing personal information belonging to users of the cloud gaming service in Armenia. The incident did not touch NVIDIA's own global infrastructure, but it has put a spotlight on the security risks that come with the company's regional partner model. What Happened The breach originated at GFN.am, a third-party company

GeForce NOW Data Breach