News
RSS feedCameron Wagenius, known online as 'Kiberphant0m,' was sentenced for stealing call records from over 100 million AT&T customers and extorting telecom firms.
A court-authorized takedown disrupted the EvilTokens device-code phishing platform, which used AI throughout its attack chain against organizations worldwide.
Cryptocurrency exchange Bitget says attackers linked to North Korea's TraderTraitor group breached backend wallet infrastructure to steal hundreds of millions in crypto.
Gyazo, a widely used screenshot-sharing platform, took its service offline after attackers exploited a server flaw to steal tens of millions of records.
US authorities took down the NightmareStresser booter service, used since 2022 to launch hundreds of thousands of DDoS attacks worldwide.
US, Japanese, Australian, and German authorities detail how North Korea's WaterPlum hackers used fake job interviews to steal cryptocurrency worldwide.
CISA updates its exploited-vulnerabilities catalog to flag a critical VMware vCenter bug, patched in July, as now abused in ransomware attacks.
Texas utility CenterPoint Energy confirms customer data was stolen after a threat actor leaked records it says were pulled from an unprotected API.
US prosecutors charge five suspected Black Axe leaders extradited from South Africa over a decade-long romance scam and money-laundering scheme.
Researchers found over 5,400 compromised sites serving ClickFix malware payloads hidden in BNB Smart Chain smart contracts, resisting takedown efforts.
A breach at Thomson Reuters' C-Track court software may have exposed Social Security numbers and sealed case data across 11 U.S. states and Canada.
A dark-web service called Nexus advertised scans of 153M+ driver's licenses traced to identity-verification firm IDScan, prompting an FBI probe and lawsuits.
Berlin confirmed an extortion attempt tied to an August breach of its state administrative network and said it will not pay the attackers' demand.
The Australian Federal Police arrested two Perth men accused of running the TeamPCP software supply-chain extortion operation tied to the Shai-Hulud worm.
Healthcare distributor McKesson confirms a cybersecurity incident after the ShinyHunters group claimed to have stolen roughly 284 million patient-related data records.
Truffle Security found thousands of exposed AWS keys, many years old and never rotated, still granting administrator access to company cloud accounts.
CISA, NSA, FBI and DOE warn of an active campaign using AI-generated scripts to probe and manipulate Siemens S7 industrial controllers.
DOJ settlement resolves claims TikTok let millions of children under 13 use adult accounts and collected their data without parental consent.
Brazilian and German police arrested suspects behind a 2023 scheme that exploited a service-provider flaw to drain Commerzbank customer accounts.
The ShinyHunters extortion group breached cloud communications provider RingCentral in July, exposing personal data tied to 1.6 million accounts.
Ukraine's National Police dismantled 94 scam call centers running investment fraud and bank-impersonation schemes, seizing cash, crypto access and gear.
A months-delayed disclosure reveals hackers accessed patient records at a healthcare billing vendor for five days in October 2025, exposing data on 3.8 million people.
Connor Riley Moucka admitted to hacking Snowflake customer accounts and extorting victims, in a scheme US officials say affected over 100 million individuals.
Belarusian national Maksim Silnikau was sentenced to 16 years for building and running Ransom Cartel, which extorted at least 18 companies worldwide.
Amazon attributed a string of npm package compromises, including the widely used debug and chalk libraries, to the North Korea-linked Sapphire Sleet group.
Hackers targeted exposed industrial controllers at over 30 Minnesota water systems, prompting a CISA alert on internet-facing operational technology.
A firmware bug in COLDCARD hardware wallets let attackers predict private keys, draining an estimated $88.6 million in Bitcoin from thousands of addresses.
Stadler Rail says the Everest ransomware gang demanded $12.3 million after breaching a data platform it shared with a supplier, but the company refused to pay.
Hackers spent ten months inside a South Korean diplomatic training system, stealing personal data on current and former foreign ministry staff.
German, US, and Indonesian authorities took down the infrastructure behind the Kratos phishing-as-a-service kit and arrested its alleged operator.