News
Memory scalpers hunt scarce DRAM with bot blitz
Web scraping bots are increasing the pressure on the tech supply chain by scouring sites for DRAM, so their minders can snap up increasingly scarce inventory and resell it for a quick profit.…
Scammers try to SIM-swap Dubai citizens hours after Iranian missile strikes
Scammers targeted Dubai citizens mere hours after missiles struck the city, attempting to gain access to their bank accounts, police have warned.…
UK government's Vulnerability Monitoring System is working - fixes flow far faster
Infosec In Brief DNS vulnerabilities are being addressed 84 percent faster in the UK public sector thanks to an automated vulnerability scanning system established as part of a program kicked off early last year.…
South Korea’s tax office apologizes for leaking seed phrase to seized crypto
South Korea’s National Tax Service has apologized after it leaked passwords to a stash of stolen crypto, which parties unknown used to make off with the digi-cash.…
Denizens of DEF CON are 'fed up with government'
Interview Hackers – especially Jake Braun – are "fed up with government."…
Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool
A new remote access trojan (RAT) being sold on cybercrime networks enables double extortion attacks on Windows machines by bundling ransomware and data theft, along with credential and cryptocurrency stealers, live surveillance, and a whole host of other illicit capabilities, all controllable from a centralized dashboard.…
Suspected Nork digital intruders caught breaking into US healthcare, education orgs
Digital intruders with possible links to North Korea have been infecting US education and healthcare sectors with a never-before-seen backdoor since at least December, according to security researchers.…
Ransomware payments cratered in 2025, but attacks surged to record highs
Ransomware payments cratered in 2025, but it seems like the cybercrooks launching the attacks didn't get the memo.…
French DIY etailer ManoMano admits customer data stolen
French online marketplace ManoMano is warning customers their personal data was siphoned off after a cyberattack hit one of its customer support subcontractors – and criminals are already claiming the haul is far larger than the company's carefully worded notice suggests.…
Cops back Dutch telco Odido after second wave of ShinyHunters leaks
The Netherlands' national police is backing Odido's refusal to pay a ransom after ShinyHunters leaked a second round of records belonging to the telco.…
Rapid AI-driven development makes security unattainable, warns Veracode
Veracode has posted its annual State of Software Security report, based on data from 1.6 million applications tested on its cloud platform, finding that more vulnerabilities are being created than are being fixed, and that high-velocity development with AI is making comprehensive security unattainable.…
Scattered Lapsus$ Hunters auditioning female voices to sharpen social engineering
Prolific cybercrime crew Scattered Lapsus$ Hunters (SLSH) is reportedly recruiting women in the hope of improving its social engineering success.…
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover
The Five Eyes intelligence alliance is urgently warning defenders to patch two Cisco Catalyst SD-WAN vulnerabilities used in attacks.…
Claude collaboration tools left the door wide open to remote code execution
Security vulnerabilities in Claude Code could have allowed attackers to remotely execute code on users' machines and steal API keys by injecting malicious configurations into repositories, and then waiting for a developer to clone and open an untrustworthy project.…
Google catches Beijing spies using Sheets to spread espionage across 4 continents
A China-linked crew found a unique formula for attacking telcos and government orgs across the Americas, Asia, and Africa in its latest round of intrusions. Google's threat intelligence, along with unnamed industry partners, disrupted the gang, which used the Chocolate Factory's own spreadsheet tools as part of its exploits.…
Fake 'interview' repos lure Next.js devs into running secret-stealing malware
Next.js developers are once again in the crosshairs as hackers seed malicious repositories disguised as legitimate projects, according to Microsoft, which said a limited set of those repos were directly tied to observed compromises.…
Ex-L3Harris exec jailed 7 years for selling exploits to Russia
The former general manager of L3Harris's cyber arm will spend the next seven years behind bars for selling trade secrets to Russia.…
Wynn Resorts takes attacker's word for it that stolen staff data was deleted
Wynn Resorts has confirmed that employee data was stolen from its servers, and is taking the hackers' word that they've since deleted it.…
OpenAI says Chinese cops used ChatGPT to plan and track smear ops against opponents
A ChatGPT user with links to Chinese law enforcement tried to use the AI chatbot to run smear campaigns targeting the Japanese prime minister and other critics of the Chinese Communist Party, according to OpenAI's latest report on malicious uses of its models.…
Threat intelligence supply chain is full of weak links, researchers find
Researchers from Georgia Tech have found that the supply chain for threat intelligence data is susceptible to adversarial action, and proposed a method to improve data sharing that they think will make it stronger.…