Security
-
Oracle has confirmed a major data breach targeting its older Gen 1 servers, exposing sensitive authentication data, usernames, and hashed passwords. The attacker gained access using an old Java exploit and demanded a $20 million ransom.
-
Samsung Germany has suffered a serious data breach, with threat actors leaking 270,000 customer support tickets on hacking forums. The breach, traced back to compromised employee credentials from 2021, exposes customer names, email addresses, home addresses, order details, payment information, and tracking data—putting affected users at high risk of scams and fraud.
-
A dangerous China-linked hacking group, Earth Alux, has been conducting cyber espionage attacks on major industries across Asia-Pacific and Latin America. Using advanced malware called VARGEIT, these hackers infiltrate organizations to steal sensitive data and disrupt operations.
-
Cybercriminals have devised a new social engineering attack known as ClickFix, which abuses fake CAPTCHA verifications to trick users into installing malware, including ransomware and banking trojans like Qakbot. This attack exploits users’ trust in CAPTCHA systems, leading them to unknowingly execute malicious commands.
-
A new ransomware strain named VanHelsing is actively targeting Windows systems, using advanced encryption and evasion techniques to bypass security defenses. First discovered on March 16, 2025, this ransomware is particularly affecting government, manufacturing, and pharmaceutical industries in France and the United States.
-
A dangerous new cyberattack method called Browser-in-the-Middle (BitM) is allowing hackers to steal user sessions within seconds—completely bypassing Multi-Factor Authentication (MFA). This technique tricks users into logging in through an attacker-controlled browser, giving hackers full access to their accounts.
-
Cybercriminals have developed a new malware attack that hides harmful software inside JPEG image files, allowing them to steal passwords from unsuspecting victims. By using steganography, a technique that hides data inside images, hackers can bypass security defenses and infect devices.
-
A new ransomware strain called Ebyte is rapidly spreading across North America and Europe, encrypting critical files and demanding high ransom payments. Security experts warn that this malware is highly advanced, making data recovery nearly impossible without paying the attackers.
-
Microsoft has uncovered a large-scale malware attack, named Storm-0408, that infected nearly one million devices worldwide. The attackers used malvertising on illegal streaming sites to spread malware hosted on GitHub, Discord, and Dropbox. The malware stole personal data, browser credentials, and even disabled security protections.
-
A new phishing scam is targeting YouTube creators using AI-generated deepfake videos of YouTube CEO Neal Mohan. Attackers trick creators into sharing login credentials by pretending to send a private video about monetization updates. Once hacked, accounts are used for scams and malware attacks.