August 11, 2025

Google Ads Data Breach Exposes Millions of Business Records

Google has confirmed a significant data breach involving information about potential Google Ads customers. The breach targeted one of the company’s Salesforce CRM instances, which is used to manage and track communication with prospective advertisers. According to Google, the attack took place in June 2025 and was carried out by the hacking group known as ShinyHunters, also referred to as

Google Ads Data Breach
August 9, 2025

GreedyBear Steals $1M in Crypto via Browser Extensions

A new cybercrime operation called GreedyBear has looted over $1 million in cryptocurrency through an elaborate scheme involving malicious browser extensions, cracked software, and deceptive crypto-themed websites. According to cybersecurity researchers at Lookout, this campaign represents one of the most coordinated and multifaceted threats targeting digital asset holders in recent months. Fake Wallet Extensions Flood Browser Stores GreedyBear's primary weapon

GreedyBear
August 6, 2025

Pandora Data Breach Linked to Salesforce Attack Campaign

Jewelry giant Pandora has confirmed a data breach following a targeted attack on its Salesforce environment. The breach is part of a larger wave of cyberattacks orchestrated by cybercriminal groups exploiting misconfigured or vulnerable Salesforce customer accounts. Pandora disclosed the incident in customer notifications sent out on August 5, 2025. While the company emphasized that its core infrastructure was not

Pandora Data Breach
August 4, 2025

PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Play Store Pages

The Android threat landscape has a dangerous new player. PlayPraetor is a highly sophisticated Remote Access Trojan (RAT) that has already compromised over 11,000 devices worldwide. Distributed through convincing fake Play Store pages, SMS phishing campaigns, and sponsored Meta ads, this malware is spreading rapidly, with over 2,000 new infections per week. A Look at the Distribution Tactics PlayPraetor isn’t

PlayPraetor Android Trojan
August 3, 2025

ShinyHunters Salesforce Breach Hits Qantas, Allianz Life, and LVMH

The hacking group ShinyHunters takes the spotlight again. This time tied to a wave of social engineering attacks that targeted Salesforce systems at major companies like Qantas, Allianz Life, and LVMH. The group exploited human trust, not software flaws, to access sensitive customer data across industries. Vishing Attacks Open the Door According to reports, attackers used vishing (voice phishing) to

ShinyHunters
August 1, 2025

ToxicPanda Android Malware Infects Thousands Across Europe

A new wave of the ToxicPanda Android malware is sweeping through Europe, targeting mobile banking users with advanced theft and evasion tactics. First identified in 2022, this banking trojan has evolved into one of the most dangerous threats for Android users, using fake overlays and accessibility services to steal login credentials and bypass security. Recent reports show over 4,500 devices

ToxicPanda Malware
July 25, 2025

Steam Malware Attack Targets Chemia Early Access Game

Hackers have compromised the early access Steam game Chemia, injecting it with info-stealing malware and endangering unsuspecting players. The attack marks the third major Steam-related malware campaign in 2025, raising urgent concerns about the platform’s ability to vet developer uploads. Malware Hidden in Game Files The threat actor known as EncryptHub, also tracked as Larva‑208, tampered with the official Chemia

Chemia Malware
July 24, 2025

Endgame Gear Malware Tool Infects Users Through Official Site

The official website of gaming mouse maker Endgame Gear recently hosted a malware-infected configuration tool, and it stayed live for over two weeks before anyone noticed. From June 26 to July 9, users downloading the setup tool for the OP1w 4K V2 mouse were unknowingly installing the XRed remote access trojan (RAT). The compromised version was distributed through Endgame Gear’s

Endgame Gear Malware
July 22, 2025

Snake Keylogger Evades Windows Defender in Targeted Turkish Espionage Campaign

A new variant of the infamous Snake Keylogger is making headlines after it successfully bypassed Windows Defender in a focused cyber-espionage campaign targeting Turkey’s defense and aerospace sectors. The attack, which leverages stealthy in-memory loaders and scheduled tasks, appears to specifically target firms like TUSAŞ (Turkish Aerospace Industries). Disguised as a legitimate Excel quote request, the executable lures victims into

Snake Keylogger
July 21, 2025

Konfety Malware Uses Malformed APKs to Evade Android Detection

The Android threat landscape continues to evolve, and cybercriminals are now exploiting even the ZIP format’s underbelly. A newly discovered malware variant named Konfety is setting a dangerous precedent by manipulating how Android Package (APK) files are structured. This manipulation allows it to sidestep traditional analysis and detection methods used by antivirus programs, app stores, and researchers. What makes Konfety

Konfety Malware