The first half of 2025 has seen a dramatic password theft surge, with cybercriminals increasingly turning to infostealers and ransomware to break into systems, steal identities, and exfiltrate sensitive data. According to Flashpoint’s Global Threat Report, stolen credentials have become the primary tool for launching large-scale attacks. Key findings from the report show: These numbers…
A wave of cyberattacks targeting a Microsoft SharePoint vulnerability has now reached more than 90 state and local governments across the United States. According to the Center for Internet Security (CIS), a nonprofit that supports local authorities in responding to cyber threats, attackers have launched widespread scanning and intrusion attempts exploiting this critical flaw. CIS…
A newly discovered Lenovo BIOS vulnerability could allow attackers to gain full control of affected systems, bypass operating systems, and even install persistent malware. Lenovo has released urgent advisories and firmware updates, but some patches are still pending. The flaw affects select Lenovo IdeaCentre and Yoga AIO (All-In-One) computers using BIOS developed by Insyde Software.…
Russian airline Aeroflot cancelled dozens of flights on Tuesday following a massive cyberattack, but claimed its flight schedule had largely stabilized. The attack, claimed by two pro-Ukraine hacker groups, reportedly disrupted 7,000 servers and accessed sensitive employee and passenger data. The hackers, Belarusian Cyber Partisans and the group Silent Crow, said they spent a year…
The US Cybersecurity and Infrastructure Security Agency (CISA) has released an updated advisory on the Scattered Spider ransomware group, warning of newly observed tactics and even more sophisticated attacks. The group is now targeting third-party IT vendors by impersonating company employees—stepping beyond its original playbook. According to the July update, this is the third advisory…
A UK software developer has launched a parody website to protest the Online Safety Act. The site, use-their-id.com, generates fake driver’s licenses using names and AI-generated portraits of local Members of Parliament (MPs). The message is clear: people are angry, and they’re getting creative. The site suggests these fake IDs as an alternative to sending…
Age verification laws are stirring debate across the UK—but experts warn this may soon become a global standard. Since July 25, thousands of websites have introduced stricter age checks under the UK’s new Online Safety Act. From Reddit to TikTok, platforms must now verify users are over 18 before granting access to harmful content. That…
Cybercriminals are targeting German speakers with seductive emails that promise adult content—but instead deliver malware. The German romance scam malware campaign uses flirtatious messages and fake videos to lure victims into downloading malicious files from a Russia-based server. “Hello, Stranger…” — The Bait The scam begins with an email that reads like the start of…
Grindr has sparked backlash after banning the phrase “no Zionists” from user bios—while still allowing openly racist and fatphobic language such as “no Asians” or “no fats.” The decision has renewed criticism over the dating app’s inconsistent content moderation and bias policies. Ban on “No Zionists” Triggers Debate Users who try to include “no Zionists”…
A 21-year-old university student has been sentenced to seven years in prison for building and selling over 1,000 phishing kits used in cybercrime schemes across 24 countries. His actions triggered £100 million in global losses. Global Fraud Engineered from a Dorm Room The student, who studied at the University of Canterbury, created 1,052 phishing kits…