July 20, 2026

Ernst & Young Data Breach Exposes Client Tax Documents

Ernst & Young, one of the world's largest professional services firms, is notifying clients about a data breach tied to a compromised support ticket system. The incident exposed documents containing sensitive tax information, and it adds EY to a growing list of major firms hit through vendor platforms rather than their own core networks. EY employs 406,000 people across more

Ernst & Young data breach
July 17, 2026

Fake Game Cheats Malware Hijacks Gamers’ PCs in Real Time

Gamers looking for an edge in their favorite titles just handed attackers a front-row seat to their entire desktop. Researchers have identified a new wave of fake game cheats malware hidden inside 11 NuGet packages, disguised as cheats, bots, and management panels for popular online games. The campaign targets players of Albion Online, GTA5RP, GrandRP, Majestic RP, and Throne and

July 16, 2026

New Spirals Ransomware Hits Network in Under 24 Hours

A newly identified ransomware group known as Spirals has managed something that most cybercriminal crews take days or weeks to pull off. It broke into a corporate network, stole sensitive data, and encrypted every reachable system in less than 24 hours. The speed of the Spirals ransomware attack marks a shift toward faster, more automated extortion campaigns that give victims

Spirals Ransomware
July 13, 2026

New Helix Vishing Attacks Target SharePoint Data

A cybercrime group calling itself Helix has started targeting corporate SharePoint environments using a mix of phone calls, stolen credentials, and multi-factor authentication abuse. Rather than deploying malware, Helix vishing attacks rely on tricking employees into handing over account access directly. The result is the same as any major breach: sensitive files exposed, and companies facing extortion demands to keep

Helix Vishing Attacks
July 10, 2026

Fake Paysafe, Skrill npm Packages Steal Developer Data

Developers building payment integrations just became the target of a coordinated supply chain attack. Security researchers uncovered fake Paysafe and Skrill npm packages designed to look like legitimate SDKs, but built instead to steal credentials from anyone who installed them. The campaign also spread through PyPI, Python's package repository, hitting developers across two of the most widely used software ecosystems

fake Paysafe Skrill npm packages
July 9, 2026

KDDI Data Breach Exposes Email Data of 12 Million People

A single vulnerability in shared email infrastructure has triggered one of Japan's largest data breaches in recent memory. KDDI, the country's second-largest mobile carrier, confirmed that a security incident tied to its email platform has exposed personal information belonging to more than 12 million people. The KDDI data breach also touches customers of five smaller internet service providers that rely

KDDI Data Breach
July 8, 2026

LONGLEASH Malware Expands Chinese Hacker Router Network

A Chinese state-linked hacking group has developed a new piece of malware that turns ordinary routers into hidden relay points for cyberattacks. Researchers at Cisco Talos have traced this activity to a group tracked as UAT-7810, and the tool at the center of it is called LONGLEASH. The LONGLEASH malware is not just another backdoor. It's built to expand what

LONGLEASH Malware
July 6, 2026

JadePuffer Ransomware: The First Fully AI-Run Cyberattack

A ransomware attack usually needs a human behind the keyboard, at least at the critical moments. That assumption just broke. Security researchers at Sysdig have documented what appears to be the first ransomware operation carried out from start to finish by an autonomous AI agent, and they've named it JadePuffer ransomware. No operator typed commands during the intrusion. An AI

JadePuffer Ransomware
July 3, 2026

Microsoft 365 Password Spraying Attack Hits 78 Accounts

A large-scale password spraying attack has hit Microsoft 365 accounts across dozens of organizations, generating more than 81 million login attempts in just two weeks. Security researchers at Huntress tracked the campaign between June 12 and June 26, and confirmed that attackers successfully compromised 78 accounts spanning 64 organizations. What makes this campaign stand out isn't just its scale. The

Microsoft 365 password spraying attack
July 2, 2026

ChocoPoC Malware Hides in Fake GitHub Security Exploits

Security researchers have uncovered a malware campaign that turns the tools of the trade against the people who use them. A newly identified threat called ChocoPoC malware is spreading through fake proof-of-concept exploits on GitHub, targeting the very researchers and penetration testers who download these files to study vulnerabilities. The campaign flips a familiar trust relationship on its head, using

ChocoPoC malware