Outpost24's KrakenLabs uncovered EncryptHub’s malware campaign, exposing their tactics through OPSEC failures such as directory listing leaks, exposed Telegram bot configurations, and storing stolen data alongside malware.

Read More
1 min read

The recently uncovered *Operation Sea Elephant* is a cyber espionage campaign targeting scientific organizations focused on ocean studies.

Read More
1 min read

Nigerian national Matthew Akande, 36, appeared in a US court facing multiple charges, including computer intrusion, wire fraud, and identity theft, for allegedly hacking US tax preparation companies.

Read More
1 min read

JavaGhost, a threat group tracked by Unit 42, has shifted from website defacement to targeting AWS environments through phishing and IAM abuse.

Read More
1 min read

The 360XSS campaign exploited a reflected XSS vulnerability (CVE-2020-24901) in the Krpano virtual tour framework to hijack search results and distribute spam ads across 350+ websites, including government, university, and news portals.

Read More
1 min read

A data breach at DISA Global Solutions exposed personal information of over 3.3 million individuals, including 15,000 Maine residents.

Read More
1 min read

A cyberespionage campaign using the FatalRAT trojan is targeting industrial organizations in the Asia-Pacific region, particularly in Taiwan, China, Japan, Thailand, and Singapore

Read More
1 min read

ACRStealer, a new information-stealing malware, is rapidly increasing in distribution since 2025, leveraging legitimate platforms like Google Docs and Steam for its command-and-control communications.

Read More
1 min read

Lee Enterprises confirmed that a recent cyberattack on its network involved ransomware, with attackers encrypting critical applications and stealing files.

Read More
1 min read

The DOGE website was hacked due to vulnerabilities, allowing unauthorized content to be posted.

Read More
1 min read

Bybit, one of the world's leading cryptocurrency exchanges, experienced a significant security breach on February 21, 2025, resulting in the theft of approximately $1.4 billion worth of Ethereum.

Read More
1 min read

Microsoft has patched CVE-2025-24989, a critical privilege escalation vulnerability in Power Pages that has been exploited in attacks.

Read More
1 min read