News Archive
555 stories · page 22 of 24Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Cybercriminals Are Targeting the FIFA World Cup 2026
Cybercriminals are leveraging the upcoming FIFA World Cup 2026 to conduct various malicious activities. These attacks include phishing campaigns, the distribution of fake tickets, malware deployment, impersonation tactics, and attempts to steal user credentials.

Winning the cyber marathon with Tony Giandomenico
Tony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons.

Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds.

Smashing Security podcast #470: This AI security flaw might be impossible to fix
A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to war

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
A new variant of the Gafgyt malware, named C0XMO, has been identified. This variant is notable for its ability to exploit DD-WRT firmware and spread across multiple processor architectures, thereby increasing the reach of its Internet of Things botnet.

Welcoming the Philippine Government to Have I Been Pwned
Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines. The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor of

Gamaredon Facilitated Turla's Access to Ukrainian Targets
ESET researchers have uncovered evidence of collaboration between the Gamaredon and Turla espionage groups, with Gamaredon actively enabling Turla's access to Ukrainian targets. Between February and June 2025, Gamaredon's tools were used to deploy Turla's Kazuar backdoor and restore access. This partnership highlights a division of labor where one group establishes access and the other deploys advanced espionage tools.

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence
Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.

Malvertising Scams Proliferate Across APAC Via Social Media Ads
Bitdefender Labs has identified a significant malvertising operation targeting the Asia-Pacific region. The campaign utilizes paid advertisements on Meta platforms to distribute scams, with over 12,000 campaigns observed across 13 countries. Health and finance-related scams are the most prevalent, contributing significantly to the overall campaign volume.

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever
Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Espec

Weekly Update 506
I'm finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There's the obvious criminality of it all, but then there's also the response from organisations (or lack thereof, as it relates to disclosure t

Police arrest man following hack of Ajax football club
Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot

Less panic patching, more precision
In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.

MyPillow listed on ransomware gang’s leak site, but denies it has been breached
A notorious ransomware gang claims to have stolen MyPillow's private data, but CEO Mike Lindell calls it a politically motivated "hit job." With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap
This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format.

Football Fever Fuels Scam Campaigns Across Email and Social Media
Cybercriminals are leveraging the excitement surrounding football, particularly the FIFA World Cup 2026, to launch various scam campaigns. These attacks target fans through emails and social media using tactics like fake online stores, fraudulent apps, and deceptive giveaways, exploiting their passion for clubs and national teams.

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
A recent phishing campaign has been identified that utilizes sophisticated techniques including obfuscated JavaScript and PowerShell. The attackers employ process hollowing and a variant of the PureLogs malware to exfiltrate sensitive user data.

Welcoming the Bhutanese Government to Have I Been Pwned
Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the Euro

Weekly Update 505
Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I'd first heard

Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a v

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed deni

Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Security researchers have found that attackers are still leveraging Microsoft's MSHTA utility to run malware campaigns on Windows systems. This legacy tool, which is present on most Windows installations, can execute scripts from various sources, making it a persistent threat.