August 29, 2025

Storm-0501 Ransomware Shifts to Cloud Attacks

Storm-0501 ransomware has entered a new phase. Security researchers report that the group has moved from on-premise intrusions to cloud-based attacks. By exploiting Azure environments, Storm-0501 has found ways to exfiltrate data, destroy backups, and pressure victims into ransom payments. This marks a major shift in how ransomware groups adapt to cloud reliance. How Storm-0501 Operates The ransomware group does

Storm-0501
August 28, 2025

Hook Android Trojan Ransomware Attacks Spread via GitHub

The Hook Android Trojan ransomware attacks mark the latest stage in the malware’s evolution. Once known mainly as a banking trojan, Hook has now gained powerful ransomware-style features, giving cybercriminals new tools to exploit Android users. What Makes the New Hook Variant Dangerous The latest version, often called Hook v3, shows how mobile malware continues to expand its reach: Ransomware-style

Hook Android Trojan
August 27, 2025

Silk Typhoon Hackers Use Fake Portals in Espionage Campaigns

Silk Typhoon hackers hijack captive portals in diplomat attacks, exposing how far advanced persistent threats will go to steal intelligence. The group, also tracked as Mustang Panda, UNC6384, and TEMP.Hex, is a known Chinese state-sponsored operation. Their latest campaign reveals new tactics designed to bypass defenses and target high-value diplomatic missions. Hijacking Captive Portals Captive portals usually appear when users

Silk Typhoon Hackers
August 25, 2025

Murky Panda Hackers Exploit Cloud Trust to Breach Customers

Murky Panda Hackers, a Chinese state-linked group, have escalated their espionage campaign by targeting cloud providers. Security researchers report that the attackers exploit cloud trust relationships to infiltrate downstream customer environments. This tactic grants them privileged access to sensitive data across multiple organizations. How the Attacks Work The group compromised SaaS providers by stealing application registration secrets in Microsoft Entra

Murky Panda Hackers
August 22, 2025

Warlock Ransomware Hits Colt, Auctions Stolen Data

Warlock Ransomware has carried out a major attack on Colt Technology Services, one of the UK’s largest telecom providers. The attackers claim to have stolen and auctioned company files, and Colt has now confirmed the breach. Sensitive data linked to customers is among the stolen material, raising concerns about privacy and trust. This incident is alarming for several reasons: Scale

Warlock Ransomware
August 20, 2025

Chrome VPN Extension Spyware Captures Every Site Visit

A verified Chrome VPN extension with more than 100,000 installs has been exposed as dangerous spyware. Researchers revealed that FreeVPN.One secretly captured screenshots of every website users visited, including sensitive content like private messages, social media chats, photos, and financial information. The stolen screenshots were quietly uploaded to servers controlled by the developers, along with data that identified each user.

Chrome VPN Extension
August 19, 2025

Charon Ransomware Tactics Show APT-Level Sophistication

Charon ransomware tactics highlight a dangerous shift in cybercrime. The new malware combines traditional ransomware methods with advanced persistent threat (APT) techniques. Security researchers have already linked its activity to targeted attacks on organizations in the Middle East, especially in aviation and public services. This evolution shows how ransomware is moving beyond simple extortion. How Charon Ransomware Operates Charon ransomware

Charon Ransomware
August 16, 2025

Crypto24 Ransomware Uses Custom EDR Evasion in Global Attack

Crypto24 ransomware is rapidly emerging as one of the most advanced cybercrime operations of the year. Security experts report that the group is executing well-planned attacks against large enterprises across multiple continents. Its operations combine tailored malware, legitimate administrative tools, and advanced evasion techniques to bypass industry-leading endpoint defenses. This calculated approach enables the attackers to remain hidden while exfiltrating

Crypto24 Ransomware
August 15, 2025

Allianz Life Data Leak Exposes Millions in Salesforce Cyberattack

The Allianz Life data leak has put millions of customers and partners at risk after attackers breached a cloud-based CRM platform. The stolen information was later released online in what experts describe as one of the most significant Salesforce-related incidents to date. From Breach to Public Leak In mid-July 2025, Allianz Life, a major U.S. insurance provider, confirmed that a

allianz life data breach
August 12, 2025

BadCam BadUSB Attack Turns Linux Webcams Into Threats

The newly discovered BadCam BadUSB attack exposes a dangerous flaw in certain Linux-based webcams. Security researchers warn that the vulnerability could allow attackers to reprogram webcams into malicious USB devices, enabling persistent threats that survive even after system reinstallation. This finding has raised concerns over USB device trust and firmware security. How the BadCam Attack Works Security firm Eclypsium identified

BadCam BadUSB Attack