Authorities have revealed details of Scattered Spider ransom payments worth over $115 million. Investigators traced cryptocurrency linked to the group and seized millions in digital assets. A teenager in the UK now faces charges for laundering funds tied to these attacks. How the Payments Worked Scattered Spider demanded ransom payments from dozens of victims across…
The MrBeast data collection under fire controversy highlights the risks of influencer-driven campaigns. Watchdogs accuse Jimmy Donaldson, known as MrBeast, of collecting children’s personal data without parental consent. The practices allegedly violated child privacy laws and raised questions about compliance in influencer marketing. What Sparked the Accusations The Children’s Advertising Review Unit (CARU) reviewed sweepstakes…
A verified Steam game named Block Blasters stole over $32,000 in cryptocurrency from a streamer raising funds for cancer treatment. The game was safe initially but added a cryptodrainer module on August 30. That update allowed it to drain wallets of some users while they raised money. How the Scam Worked The developer Genesis Interactive…
Microsoft recently patched a serious Entra ID flaw that allowed attackers to hijack any organization’s Azure/Entra ID tenant. The flaw emerged from a mix of legacy actor tokens and a vulnerability in the Azure AD Graph API. It risked full tenant takeover without detection. What the Flaw Entailed Security researcher Dirk-jan Mollema discovered that “actor…
The FBI warns the public about fake FBI complaint portals impersonating its Internet Crime Complaint Center (IC3). Cybercriminals use these fraudulent websites to steal personal and financial information from victims. The rise of these portals highlights the growing creativity of scammers. How the Fake Portals Work Attackers design websites that look almost identical to the…
CISA has revealed that attackers deployed Ivanti EPMM malware kits exploiting recently patched vulnerabilities. The flaws, CVE-2025-4427 and CVE-2025-4428, allow authentication bypass and code injection. Threat actors have leveraged them since May, exploiting systems whose APIs remained vulnerable. What the vulnerabilities are The two vulnerabilities affect Ivanti Endpoint Manager Mobile (EPMM) in versions 11.12.0.4, 12.3.0.1,…
Fortra has issued a warning about a max severity flaw in its GoAnywhere MFT License Servlet. The vulnerability allows remote command injection via a forged license response. It poses a serious risk to organizations that leave their Admin Console publicly accessible. What the Flaw Is The vulnerability, tracked as CVE-2025-10035, stems from deserialization of untrusted…
A cyberattack has disrupted Collins Aerospace’s MUSE system, halting check-in and boarding operations at several major European airports. The incident, which began on September 19, 2025, caused widespread delays and cancellations. Affected hubs include London Heathrow, Berlin Brandenburg, Brussels Airport, and others. What Happened The MUSE platform, a core system used for passenger check-in, baggage…
The ransomware group WarLock has escalated its activities sharply, claiming over 60 victims in September 2025. Also known as Gold Salem or Storm-2603, the group has targeted major enterprises, telecoms, and government agencies worldwide. The WarLock ransomware attacks surge highlights how quickly a new group can rise in prominence. Who Is WarLock? First observed in…
The alleged SK Telecom source code leak has raised serious security concerns. Hackers claim to have accessed the company’s internal files, exposing project repositories, build configurations, and AWS keys. While no customer data has been confirmed in the leak, experts warn that exposed source code can open the door to future vulnerabilities and intellectual property…