The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools.
28.10.2025 15:11 β π 11 π 8 π¬ 0 π 1@serghei.bsky.social
Cybersecurity/tech reporter @BleepingComputer / serghei.ro
The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools.
28.10.2025 15:11 β π 11 π 8 π¬ 0 π 1An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake emails claiming that the companies were hacked, urging them to download a supposedly more secure desktop version of the password manager.
15.10.2025 15:22 β π 58 π 58 π¬ 0 π 5On CISA media call just now to discuss the F5 hack and source code breach, CISA staffer interrupted the discussion to blame the Democrats for the government shutdown and forcing workers to work without pay
15.10.2025 16:13 β π 152 π 34 π¬ 6 π 21U.S. cybersecurity company F5 disclosed that it suffered a cyberattack in early August, where suspected nation-stateΒ hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code.
15.10.2025 09:32 β π 9 π 4 π¬ 0 π 0Discord says they will not be negotiating with threat actors who claim to have stolen the data of 5.5 million unique users from the company's Zendesk support system instance, including government IDs and partial payment information for some people.
08.10.2025 20:22 β π 11 π 6 π¬ 0 π 0The ShinyHunters extortion group has leaked samples of data belonging to dozens of companies, which were stolen in a wave of Salesforce breaches that have affected numerous companies worldwide.
03.10.2025 10:16 β π 7 π 4 π¬ 0 π 0A source shares some screenshots of the Lapsus ransomware gang celebrating the government shutdown as a disruption to the FBI investigations tracking them.
They also refer to Trump as "my king."
Astonishingly Pathetic Threat
01.10.2025 09:39 β π 1 π 0 π¬ 0 π 0CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.
25.09.2025 13:53 β π 10 π 5 π¬ 0 π 0SonicWall warned customers today to reset credentials after their firewall configuration backup files were exposed in a security breach that impacted MySonicWall accounts.
17.09.2025 12:23 β π 9 π 5 π¬ 0 π 0Screenshot with quote from article: "How Android's new risk-based update process works Instead of bundling all available security patches into the next ASB, Google now prioritizes shipping only "high-risk" vulnerabilities in its monthly releases. The majority of security fixes, meanwhile, will be shipped in quarterly ASBs. Google defines "high-risk" vulnerabilities as issues that are crucial to address immediately, such as those under active exploitation or that are part of a known exploit chain. This designation is based on real-world threat level and is distinct from a vulnerability's formal "critical" or "high" severity rating."
Google has switched to a risk-based Android update process, with βhigh-riskβ vulnerabilities patched on a monthly basis and the rest fixed on a quarterly schedule.
www.androidauthority.com/android-risk...
Finnish hacker Aleksanteri KivimΓ€ki has been released from prison following an appeal.
KivimΓ€ki hacked Finnish psychotherapy centre Vastaamo in 2020 and released highly sensitive patient files.
yle.fi/a/74-20182408
The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but attackers made little profit off it.
10.09.2025 13:56 β π 11 π 3 π¬ 1 π 0NPM has begun removing the malicious packages.
bsky.app/profile/bad-...
Phishing email sent to NPM package maintainers:
08.09.2025 17:12 β π 32 π 19 π¬ 1 π 3Orange Belgium, a subsidiary of telecommunications giant Orange Group, disclosed on Wednesday that attackers who breached its systems in July have stolen the data of approximately 850,000 customers.
21.08.2025 03:07 β π 6 π 4 π¬ 0 π 1HR giant Workday breached in Salesforce data-theft attacks
www.bleepingcomputer.com/news/securit...
UK-basedΒ telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company's operations, including hosting and porting services, Colt Online and Voice API platforms.
15.08.2025 11:25 β π 6 π 4 π¬ 0 π 0Security researchers have created a new FIDO downgrade attack against Microsoft Entra ID that tricks users into authenticating withΒ weaker login methods, making them susceptible to phishing and session hijacking.
13.08.2025 15:14 β π 12 π 4 π¬ 0 π 3some Hyundai IONIQ 5 models can be hacked to open the doors and start the car with a Game Boy-like device. Now, Hyundai is asking customers in the UK to pay Β£49 to fix this huge security flaw. Details here π www.theverge.com/news/757205/...
11.08.2025 11:53 β π 57 π 11 π¬ 4 π 1Eighty cheat websites generate between $12.8 million and $73.2 million annually, according to academics at the University of Birmingham.
Up to 174,000 people may be buying cheats every month across North America and Europe.
www.wired.com/story/inside...
Research: github.com/SamCollins13...
Microsoft warns customers to mitigate a high-severity vulnerability in Exchange Server hybrid deployments that can let attackers escalate privileges in Exchange Online cloud environments undetected.
www.bleepingcomputer.com/news/microso...
Air France and KLM announced on Wednesday that attackers had breached a customer service platform and stolen the data of an undisclosed number of customers.
07.08.2025 04:41 β π 6 π 4 π¬ 0 π 0Google is the latest company to suffer a data breach in an ongoing wave of Salesforce CRM data theft attacks conducted by the ShinyHunters extortion group.
06.08.2025 09:51 β π 7 π 6 π¬ 0 π 0Although not yet confirmed by Cisco, this is likely part of a wave of Salesforce data theft attacks linked to the ShinyHunters extortion group.
Other companies affected by Salesforce data breaches: Adidas, Qantas, Allianz Life, Chanel, and LVMH brands Louis Vuitton, Dior, and Tiffany & Co.
Ransomware gangs have recently joined ongoing attacks targeting a Microsoft SharePoint vulnerability chain,Β part of a broader exploitation campaign that has already led to the breach of at least 148 organizations worldwide.
04.08.2025 07:27 β π 10 π 5 π¬ 0 π 0Minnesota Governor Tim Walz has activated the National Guard in response to a crippling cyberattack that struck the City of Saint Paul, the state's capital, on Friday.
29.07.2025 14:58 β π 7 π 3 π¬ 0 π 0Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data.
28.07.2025 14:03 β π 13 π 3 π¬ 0 π 0NEW: A custom firmware for the Flipper Zero, being sold by a Russian hacker for up to $1,000, can bypass modern security protections on key fobs.β¨β¨
The hack defeats rolling codes & lets you clone every key fob buttonβlock, unlock, trunkβby capturing just a single command.
san.com/cc/millions-...