June 3, 2025

Spear Phishing Campaign Targets CFOs and Abuses Legit Tools

A sophisticated spear phishing campaign that specifically targets CFOs (Chief Financial Officers) was recently uncovered by cybersecurity firm Trellix. This ongoing operation, first detected in mid-May 2025, has already affected organizations spanning Europe, Africa, Canada, the Middle East, and South Asia. The campaign’s method? A clever blend of social engineering and abuse of legitimate remote access software. Anatomy of the

Spear Phishing Campaign Targets CFOs
June 2, 2025

Victoria’s Secret Cyberattack Shuts Down the Company Website

At the end of May 2025, Victoria’s Secret experienced a major cyberattack that forced the company to take its U.S. website offline. The sudden shutdown disrupted online shopping for millions of customers and caused ripple effects across its retail operations. Although the company has not shared specific details about the nature of the attack, the disruption suggests it may have

Victoria's Secret Cyberattack
May 31, 2025

Dark Partners Cybercrime Gang Fuels AI and Crypto Heists

A new player has entered the cybercrime arena — and they’re not after just your passwords. The Dark Partners cybercrime gang is behind a sophisticated malware campaign that’s targeting users of AI tools, VPN services, and cryptocurrency platforms. By cloning popular websites like Windscribe, Ledger, and Sora, the gang lures victims into downloading malware disguised as legitimate software. The goal:

Dark Partners Cybercrime Gang
May 30, 2025

DragonForce Ransomware Hits MSPs via SimpleHelp

In a chilling reminder of the risks posed by insecure remote access tools, the ransomware group DragonForce has launched a sophisticated supply chain attack by exploiting critical vulnerabilities in SimpleHelp, a remote monitoring and management (RMM) platform widely used by Managed Service Providers (MSPs). The campaign, first uncovered by researchers at Group-IB, reveals how three recently discovered vulnerabilities in SimpleHelp

DragonForce Ransomware
May 28, 2025

Coca Cola Data Breach Leaks Employee Info

In May 2025, Coca-Cola suffered a data breach - and not one, but two within days! These breaches exposed sensitive employee information and millions of internal Salesforce records, highlighting critical vulnerabilities in Coca-Cola’s security ecosystem. This incident serves as a stark reminder of the growing threat of sophisticated cybercriminals targeting multinational corporations. Everest Ransomware Targets Employee Information The first major

Coca Cola Data Breach
May 26, 2025

Operation Endgame: Europol Strikes a Blow to Ransomware

In a coordinated international crackdown, Europol, alongside law enforcement agencies from around the globe, has executed a sweeping operation that disrupted some of the world's most notorious ransomware operations. “Operation Endgame”, this large-scale effort resulted in the takedown of 300 servers, the neutralization of 650 domains, and the seizure of €3.5 million in cryptocurrency between May 19 and May 22,

Operation Endgame by Europol
May 21, 2025

Fake KeePass Version Executes Ransomware Attacks

A malicious version of the popular open-source password manager KeePass is being used to launch ransomware attacks on VMware ESXi servers. Security researchers have uncovered a trojanized variant, dubbed “KeeLoader” that mimics the real interface while silently compromising users' systems. Once installed, this fake KeePass plants a Cobalt Strike beacon and exfiltrates the user’s password database in plaintext. Thus, paving

Fake KeePass Version Executes Ransomware Attack
May 20, 2025

RVTools Website Hacked to Spread Bumblebee Malware

In a concerning case of software supply chain compromise, the official RVTools website was hacked to distribute malware. RVTools is a trusted utility used by VMware administrators. The installer, normally used to help IT professionals audit virtual environments, was tampered with to deliver the Bumblebee malware loader, a known precursor to ransomware attacks. This incident underscores the persistent and growing

RVTools Website Hacked
May 19, 2025

Skitnet Malware Fuels Ransomware Attacks

Ransomware gangs are evolving fast, and their newest weapon, Skitnet malware, proves it. Known alternately as “Bossnet,” this emerging post-exploitation malware is gaining traction among threat actors like BlackBasta and Cactus. Designed for stealth, Skitnet leverages in-memory execution, DNS-based command and control, and anti-forensics to maintain a low profile while enabling persistent remote access. As its use spreads in phishing

skitnet malware
May 15, 2025

CPU-Level Ransomware: Is It Possible and How Dangerous Is It?

Ransomware has officially leveled up. In a chilling new development, cybersecurity researchers have unveiled the world’s first proof-of-concept CPU-level ransomware - an attack so deeply embedded in hardware that it bypasses every traditional defense in the cybersecurity playbook. Unlike conventional ransomware that encrypts files through software-level exploits, this innovation taps directly into the processor’s microcode, rewriting the rules of engagement.

CPU-Level Ransomware