The Xubuntu site compromised incident has alarmed the open-source community after hackers replaced official ISO files with malware. Users who attempted to download the Linux distribution instead received a ZIP archive containing a fake “Xubuntu – Safe Downloader” executable. The malicious file posed as a legitimate installer but targeted Windows systems instead. Security researchers confirmed…
Cybercriminals are exploiting TikTok videos to spread infostealers using a technique known as ClickFix attacks. These malicious clips pose as activation or troubleshooting guides for popular software like Windows, Spotify, and Microsoft Office. Instead of fixing anything, they lead unsuspecting users to execute PowerShell commands that install information-stealing malware. The trend shows how easily criminals…
The Dutch Data Protection Authority has fined Experian €2.7 million for mass collecting and processing personal data without consent. The Experian fined for mass collecting personal data case reveals how one of the world’s largest credit agencies violated GDPR transparency rules. Investigators say the company built massive consumer profiles using private and public data sources.…
ConnectWise has fixed critical flaws in its Automate remote-management platform that could enable AiTM update attacks. The ConnectWise Automate bug allowing AiTM update attacks exposed managed service providers and enterprises to risks of malicious updates and network compromise. The company responded quickly to strengthen encryption, authentication, and package validation. Details of the Vulnerabilities Researchers discovered…
Europol has dismantled a large-scale SIM-box operation that rented mobile numbers to cybercriminals. The Europol SIM-box network allowed scammers to buy temporary access to legitimate numbers from over 80 countries. These rented numbers were then used to commit fraud, evade verification, and hide criminal identities. The takedown marks one of the most significant blows against…
A major security incident has revealed over 266,000 F5 BIG-IP instances exposed to remote attacks. Cybersecurity analysts warn that many organizations are still running vulnerable devices online. The discovery follows the F5 Networks breach, which compromised the company’s internal systems and raised urgent concerns about global infrastructure security. Details of the Exposure Researchers from the…
Beijing claims irrefutable evidence linking the United States to a massive cyberattack on a major Chinese government agency. The allegations mark another escalation in the growing digital conflict between the two nations. Chinese officials accused the US National Security Agency (NSA) of orchestrating the breach, describing it as a direct threat to China’s cybersecurity and…
The growing trade in personal data has turned into a global privacy threat. Data brokers doxing consumers has become a modern form of exposure, where private information is sold without consent. According to DeleteMe CEO Rob Shavell, these companies collect and distribute data so freely that their actions closely resemble doxing. This article explores how…
Cybercriminals are running a new campaign that uses Fake Homebrew sites and other impersonated pages to spread malware through Google Ads. The attackers trick users into downloading info-stealer malware disguised as trusted software tools like Homebrew, LogMeIn, and TradingView. The operation specifically targets macOS users, including developers who rely on these platforms for daily work.…
A Massachusetts college student has been sentenced to four years in prison for the PowerSchool cyberattack. The hacker, 20-year-old Matthew Lane, illegally accessed the education platform and stole personal data from millions of students and teachers. The sentencing follows months of investigation into one of the largest school-system breaches in recent history. Prosecutors described the…