LIVE · cybersecurity feed
Live wire

News Archive

555 stories · page 22 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

fifa world cup

Cybercriminals Are Targeting the FIFA World Cup 2026

Cybercriminals are leveraging the upcoming FIFA World Cup 2026 to conduct various malicious activities. These attacks include phishing campaigns, the distribution of fake tickets, malware deployment, impersonation tactics, and attempts to steal user credentials.

security

Winning the cyber marathon with Tony Giandomenico

Tony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons.

security

Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting

Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds.

vulnerability

Smashing Security podcast #470: This AI security flaw might be impossible to fix

A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to war

iothigh

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

A new variant of the Gafgyt malware, named C0XMO, has been identified. This variant is notable for its ability to exploit DD-WRT firmware and spread across multiple processor architectures, thereby increasing the reach of its Internet of Things botnet.

nation-state

Welcoming the Philippine Government to Have I Been Pwned

Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines. The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor of

espionagehigh

Gamaredon Facilitated Turla's Access to Ukrainian Targets

ESET researchers have uncovered evidence of collaboration between the Gamaredon and Turla espionage groups, with Gamaredon actively enabling Turla's access to Ukrainian targets. Between February and June 2025, Gamaredon's tools were used to deploy Turla's Kazuar backdoor and restore access. This partnership highlights a division of labor where one group establishes access and the other deploys advanced espionage tools.

threat intelligence

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.

malvertising

Malvertising Scams Proliferate Across APAC Via Social Media Ads

Bitdefender Labs has identified a significant malvertising operation targeting the Asia-Pacific region. The campaign utilizes paid advertisements on Meta platforms to distribute scams, with over 12,000 campaigns observed across 13 countries. Health and finance-related scams are the most prevalent, contributing significantly to the overall campaign volume.

ai

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how

breach

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Espec

breach

Weekly Update 506

I'm finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There's the obvious criminality of it all, but then there's also the response from organisations (or lack thereof, as it relates to disclosure t

security

Police arrest man following hack of Ajax football club

Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot

patch

Less panic patching, more precision

In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.

ransomware

MyPillow listed on ransomware gang’s leak site, but denies it has been breached

A notorious ransomware gang claims to have stolen MyPillow's private data, but CEO Mike Lindell calls it a politically motivated "hit job." With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my

vulnerability

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format.

scams

Football Fever Fuels Scam Campaigns Across Email and Social Media

Cybercriminals are leveraging the excitement surrounding football, particularly the FIFA World Cup 2026, to launch various scam campaigns. These attacks target fans through emails and social media using tactics like fake online stores, fraudulent apps, and deceptive giveaways, exploiting their passion for clubs and national teams.

phishinghigh

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

A recent phishing campaign has been identified that utilizes sophisticated techniques including obfuscated JavaScript and PowerShell. The attackers employ process hollowing and a variant of the PureLogs malware to exfiltrate sensitive user data.

nation-state

Welcoming the Bhutanese Government to Have I Been Pwned

Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’

security

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the Euro

patch

Weekly Update 505

Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I'd first heard

breach

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a v

malware

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed deni

malwarehigh

Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows

Security researchers have found that attackers are still leveraging Microsoft's MSHTA utility to run malware campaigns on Windows systems. This legacy tool, which is present on most Windows installations, can execute scripts from various sources, making it a persistent threat.