The Poland cybersecurity response has intensified as Russian-linked hackers target hospitals and water systems. Authorities report dozens of attacks daily. To counter the growing risk, Poland increased its cybersecurity budget to €1 billion for 2025. Escalating Cyberattacks Hospitals remain frequent targets of Russian hackers. Breaches forced some facilities to suspend operations, putting patients and staff…
The NPG Media ransomware attack has exposed sensitive employee and executive data at News-Press & Gazette Company (NPG). The Termite ransomware group claims responsibility for the incident. If verified, the breach could affect more than 800 employees and compromise critical business documents. What Happened Termite, a ransomware gang linked to Russia, claims it breached NPG…
Google has removed 224 Android malware apps linked to the SlopAds fraud campaign. These malicious apps generated more than 2.3 billion ad requests every day. They were downloaded over 38 million times before being taken down. The campaign used advanced methods to avoid detection and targeted users worldwide. How SlopAds Fraud Worked The SlopAds fraud…
Hackers are using SEO poisoning fake apps to trick users into downloading malware. By manipulating search results, attackers lure people searching for Signal, WhatsApp, Chrome, and other popular apps. Instead of safe software, victims install trojanized packages loaded with malware. How Attackers Use SEO Poisoning Security researchers at FortiGuard Labs found that attackers register lookalike…
A massive Great Firewall leak has revealed how China exports advanced censorship and surveillance technologies worldwide. The breach exposed more than 500GB of internal documents, communications, and source code tied to Geedge Networks, a developer linked to China’s censorship systems. What the Leak Uncovered The files revealed tools like the Tiangou Secure Gateway (TSG), capable…
A Google fraudulent account surfaced inside the company’s Law Enforcement Request System (LERS). The portal processes sensitive law enforcement data requests. Google confirmed the account but stated no user data was stolen. How the Incident Unfolded A malicious actor created a fake account inside the LERS system. Google detected the account and shut it down…
Apple threat notifications have been confirmed by CERT-FR, France’s national incident response team. The alerts warn users about spyware campaigns that compromise iCloud devices. High-profile targets such as journalists, politicians, and activists remain most at risk. How the Notifications Work Apple has sent threat notifications since 2021. These alerts warn individuals when advanced spyware attempts…
The FBI has issued a warning about Salesforce data theft linked to two threat groups, UNC6040 and UNC6395. Both groups exploited Salesforce OAuth apps to steal large volumes of sensitive data from multiple organizations. The incidents reveal the growing risks companies face when attackers abuse trusted access tokens. How Hackers Exploited Salesforce UNC6040 relied on…
A new watchdog report exposes CISA cybersecurity retention mismanagement. The Office of the Inspector General (OIG) revealed that the Cybersecurity and Infrastructure Security Agency misused millions of dollars from its cybersecurity retention incentive program. Between 2020 and 2024, CISA failed to enforce eligibility rules, allowed improper payments, and did not maintain required records. These failures…
HybridPetya secure boot bypass marks a dangerous step in ransomware development. Security researchers have discovered that this strain can exploit a UEFI vulnerability to bypass Secure Boot, allowing ransomware to load before Windows starts. By abusing CVE-2024-7344, attackers can plant malicious code inside the EFI System Partition, encrypt files, and demand ransom, even when Secure…