June 25, 2025

WordPress Theme Hijacked by Malware: What You Need to Know

A popular WordPress themes got hijacked by malware. A critical security flaw in one of the most widely used premium WordPress themes has put thousands of websites at risk. The Motors theme, developed by StylemixThemes and commonly used for car dealership and classified sites, has been found vulnerable to a serious exploit. Cybercriminals now actively use this exploit to hijack

WordPress Theme Hijacked
June 17, 2025

Scattered Spider Strikes With Attacks on U.S. Insurance Firms

Google’s Threat Intelligence Group has issued a stark warning: the cybercriminal group known as Scattered Spider has shifted focus once again, this time toward U.S.-based insurance companies. Infamous for their high-profile breaches in the casino and retail sectors, this adaptable and increasingly aggressive group has now taken aim at a sector rich in sensitive data and operational vulnerabilities. Who Is

Scattered Spider Strikes US Insurance Companies
June 16, 2025

Anubis Ransomware Now Wipes Files Beyond Recovery

A new, far more destructive chapter has begun for the Anubis ransomware operation. Previously known for encrypting data and extorting victims, the cybercriminals behind Anubis have now introduced a wiper feature. One that makes data recovery virtually impossible, even if the ransom is paid. This strategic shift marks a dangerous evolution in the ransomware-as-a-service (RaaS) ecosystem and signals a chilling

Anubis Ransomware
June 15, 2025

Fog Ransomware Turns Legitimate Tools Against Defenders

In May 2025, incident responders at a regional bank in Southeast  Asia stumbled upon a ransomware intrusion that looked nothing like the smash‑and‑grab playbooks they were used to. Instead of Cobalt Strike, MimiKatz or custom droppers, the adversary - operators of the Fog ransomware - stitched together a workbench of legitimate admin utilities and niche open‑source red‑team projects. Because every binary

fog ransomware
June 5, 2025

Hackers Exploit Salesforce Tool in New Data Extortion Campaign

A new cyberattack campaign uncovered by Google's Threat Intelligence team reveals how attackers are increasingly blurring the lines between legitimate software tools and malicious intent. In this case, hackers exploit a Salesforce tool to infiltrate corporate environments, exfiltrate data, and launch extortion attempts against affected organizations. Voice Phishing Leads to Compromise The attackers, identified by Google as UNC6040, are using

Hackers Exploit Salesforce Tool
May 30, 2025

DragonForce Ransomware Hits MSPs via SimpleHelp

In a chilling reminder of the risks posed by insecure remote access tools, the ransomware group DragonForce has launched a sophisticated supply chain attack by exploiting critical vulnerabilities in SimpleHelp, a remote monitoring and management (RMM) platform widely used by Managed Service Providers (MSPs). The campaign, first uncovered by researchers at Group-IB, reveals how three recently discovered vulnerabilities in SimpleHelp

DragonForce Ransomware
May 29, 2025

LexisNexis Data Breach Exposes Tons of Personal Information

One of the largest U.S. data brokers has confirmed a security breach that compromised names, Social Security numbers, and other sensitive data. LexisNexis Risk Solutions, a major player in the data brokerage industry, has disclosed a significant data breach. It exposed the personal information of more than 364,000 individuals. The breach occurred on December 25, 2024, and was only discovered

LexisNexis Data Breach
May 25, 2025

Major Data Leak Exposed Passwords – Over 184 Million Affected

A major data leak exposed millions of passwords, including Facebook, Instagtam, Snapchat and Roblox credentials. The staggering database containing over 184 million login credentials from popular platforms was recently discovered, completely unprotected. This alarming security breach has put millions of users at risk of account takeover, identity theft, and other cyberattacks. The exposed data included plaintext usernames and passwords, suggesting

Data Leak Exposed Passwords
May 23, 2025

BadSuccessor Vulnerability: A New Threat in Windows Server 2025

A newly discovered vulnerability in Windows Server 2025, dubbed "BadSuccessor", is raising serious alarms in the cybersecurity community. The flaw targets a recently introduced feature called delegated Managed Service Accounts (dMSAs). It allows attackers to escalate privileges and impersonate virtually any user in Active Directory. This includes highly privileged accounts. Discovered by researchers at Akamai, this unpatched vulnerability affects environments

BadSuccessor Vulnerability in Windows Server 2025
May 22, 2025

Ivanti EPMM Security Flaws Exploited By Hackers

Two newly identified Ivanti Endpoint Manager Mobile (EPMM) security flaws, are under active exploitation by a sophisticated hacking group believed to be operating from China. The vulnerabilities, when used together, enable attackers to bypass authentication and remotely execute malicious code, potentially giving them full control of targeted systems. The Vulnerabilities Explained Security experts have flagged two critical issues in Ivanti’s

Ivanti EPMM security flaws