Salesforce attackers threaten Google and FBI after a major supply-chain compromise linked to Salesloft Drift. The cybercriminal groups behind the breach—ShinyHunters, LAPSUS$, and Scattered Spider—demanded an end to ongoing investigations while claiming access to sensitive systems. Who the Attackers Are The coalition of groups declared themselves “invincible” in a public statement. They demanded Google dismiss…
Amazon Disrupts APT29 in a recent cyber campaign aimed at Microsoft 365 users. The Russian-linked hacking group, also known as Cozy Bear, attempted to steal login details using a deceptive watering hole attack. Amazon’s rapid response disrupted the operation before it could spread further. Who Is APT29? APT29 is a state-backed Russian threat group with…
European Commission President Ursula von der Leyen has issued a stern warning about the growing risks of GPS jamming and spoofing attacks. These cyber threats could disrupt critical systems in aviation, maritime navigation, and military operations, raising serious concerns about national and international security. How GPS Jamming and Spoofing Work GPS jamming involves sending signals…
The NCSC malware campaign highlights a new wave of malicious apps disguised as PDF editors and manual finder tools. Attackers distribute these fake programs through paid ads and deceptive websites, infecting unsuspecting users. How the Campaign Works Threat actors promote trojanized software such as “ManualFinder” and fake PDF editors. Once installed, these apps secretly convert…
Brokewell Android malware spreads through deceptive TradingView ads that push fake apps. Attackers trick victims into installing malicious software that steals sensitive data. Researchers warn the campaign is growing fast, exposing countless devices. How the Campaign Works Cybercriminals buy ads disguised as official TradingView promotions. When users click them, they land on fraudulent websites hosting…
WhatsApp emergency update closes a spyware campaign that targeted iPhone and Mac users. Hackers exploited zero-click flaws to install malware without any clicks. As a result, the case highlights how fast threats evolve and why urgent updates remain essential. How Hackers Exploited the Flaw Attackers abused CVE-2025-55177, a WhatsApp bug on iOS and macOS. By…
YouTubers bust fraud ring in a stunning case that shows how digital creators can fight crime. Two scambaiting YouTubers helped U.S. authorities dismantle a $65 million international scheme that targeted seniors with tech support scams and fake banking calls. Their work highlights how online activism can protect vulnerable communities. The $65 Million Scam The fraud…
The 4chan Kiwi Farms Ofcom case brings global attention to online safety laws. Both platforms are suing the British regulator over age verification rules. Why the Lawsuit Began In June, Ofcom launched investigations into 4chan and Kiwi Farms. The regulator wanted details on how the sites protect UK minors from harmful content. Neither site responded.…
A joint operation between Dutch police and the FBI has dismantled VerifTools, a global marketplace for fake identification documents. The takedown highlights growing cooperation against cybercrime. Servers Seized in Amsterdam On August 27, authorities raided a data center in Amsterdam. Investigators seized two physical servers and 21 virtual machines linked to VerifTools. The operation ended…
The passkey browser vulnerability revealed at DEF CON 2025 shows that attackers can hijack authentication through compromised browsers. The flaw challenges the perception that passkeys offer unbreakable security. How the Attack Works Passkeys rely on private keys stored on devices, unlocked with biometrics or PINs. They are designed to eliminate phishing and password theft. However,…