All Articles (2790)

Sort by

31039951068?profile=RESIZE_400xCoinbase Inc. lost a private arbitration complaint with damages and costs totaling $618,000 to a client who claimed to lose funds after a 2024 cyber-attack.  The complaint of Ashok Maini versus Coinbase Inc. was heard in private arbitration in the forum of the American Arbitration Association, commonly referred to as Triple A arbitration in the industry.  Arbitration complaints involving cryptocurrencies are outside the purview of FINRA Dispute Resolution because digital assets are not legally d

31037133458?profile=RESIZE_400xHundreds of Porsche cars in Russia became undrivable after their factory-installed satellite security system malfunctioned, owners and dealers report.  Drivers in several Russian cities reported sudden engine shutdowns and fuel-delivery interruptions after Porsche cars lost satellite-alarm-module connectivity, leaving all models at risk of self-locking, according to the dealership group Rolf.  The problem appears to be caused by the Vehicle Tracking System (VTS), which is an onboard module.[1]

A

31036833856?profile=RESIZE_400xIn the cybersecurity community, the ability to see a threat before it strikes defines who stays safe and who gets hit. This was the central theme of Check Point’s recent Threat Intelligence live AMA Reddit webinar, where leading experts from Check Point Research (CPR) and External Risk Management (ERM) Research (formerly Cyberint) offered rare, behind-the-scenes insights into how they track, predict, and prevent attacks at machine speed.
These experts are :

  • Sergey Shykevich – Head of Threat Int

31027522884?profile=RESIZE_400xThe US, DHS Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning concerning malicious cyber actors using commercial spyware programs to target messaging applications.  CISA's alert highlights that various threat actors employ sophisticated targeting and social engineering methods to deliver spyware and gain unauthorized access to users' messaging applications.  This initial access then facilitates the deployment of additional malware, leading to more extensive access to t

31037135098?profile=RESIZE_400xWhile analyzing one of the affiliate programs, Doctor Web’s researchers discovered a unique piece of malware with clicker functionality and called it a Trojan.ChimeraWire. This malware targets computers running Microsoft Windows and is based on the open-source projects zlsgo and Rod for automated website and web application management.

Trojan.ChimeraWire allows cybercriminals to simulate user actions and boost a website's behavioral ranking by artificially increasing its search engine rankings.

31037127652?profile=RESIZE_400xWhen programmers encounter puzzling code, their brains react in measurable ways.  Now, researchers have shown that large language models (LLMs) exhibit similar signs of confusion when reading the same code.  In a study from Saarland University and the Max Planck Institute for Software Systems, scientists compared human brain activity with LLM uncertainty and found striking alignment.  Wherever humans struggled, the models did too.  This discovery, described in the paper “How do Humans and LLMs P

31027112062?profile=RESIZE_400xArizona Attorney General Kris Mayes is suing Temu, a large online marketplace founded in 2022.  According to a 02 December 2025 press release, Temu violated the Arizona Consumer Fraud Act through "unlawful data collection, violations of customers' privacy, and counterfeiting some of Arizona's most iconic brands."  Temu is best known for allowing primarily Chinese sellers to sell products directly to Western consumers, including those in the US.  Mayes accused Temu of harvesting sensitive user da

31026998058?profile=RESIZE_400xConsumers are urged to exercise caution this Christmas shopping season, as new research from McAfee Labs indicates a significant increase in brand impersonation by cybercriminals.  The Tech giants Apple, Nintendo, and Samsung, alongside luxury labels like Coach, Dior, and Gucci, are among the most frequently faked brands targeted by scammers.   McAfee’s analysis of festive shopping scams is based on real-world web activity data collected between October and November 2025, specifically focusing o

31036941268?profile=RESIZE_400xThe slow-motion Russian invasion of Ukraine has highlighted persistent vulnerabilities in Western military readiness, specifically concerning munitions stockpiles, supply chain resilience, and procurement agility.  As the conflict continues, nations are adjusting their force posture and defense planning.  These changes aim not only to support Ukraine but also to prepare for the realities of prolonged, multi-domain warfare.

While quantum computing and automation are shaping the following stages o

31036802288?profile=RESIZE_400xIn an age where artificial intelligence is increasingly trusted to judge human expression, a subtle but essential flaw has emerged.  Large language models (LLMs), the same systems that generate essays, screen job applications, and moderate online discourse, appear to evaluate content fairly, until they’re told who wrote it.  A new study by researchers Federico Germani and Giovanni Spitale at the University of Zurich, published in Science Advances, reveals that LLMs exhibit systematic bias when t

31017416255?profile=RESIZE_400xUS DHS, CISA, along with authoring organizations, assess pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups.  These attacks use minimally secured, internet-facing virtual network computing (VNC) connections to infiltrate (or gain access to) OT control devices within critical infrastructure systems.  Pro-Russia hacktivist groups: Cyber Army of Russia Reborn (CARR), Z-Pen

31016873059?profile=RESIZE_400xThe Hoxhunt 2025 Cyber Threat Intelligence Report delivers a sobering message for security professionals: the most dangerous threats are no longer the most obvious ones.  As 2026 approaches, enterprises are no longer fighting clumsy, error-riddled bulk spam; they are facing a quiet revolution where sophisticated, convincing attacks blend seamlessly into daily workflows, fueled by AI and advanced token-theft toolkits.

See:  https://hoxhunt.com/guide/threat-intelligence-report

The report, based on

31017397071?profile=RESIZE_400xUDPGangster is a UDP-based backdoor associated with the MuddyWater threat group, which is known for its cyber espionage operations across the Middle East and neighboring regions.  This malware enables remote control of compromised systems by allowing attackers to execute commands, exfiltrate files, and deploy additional payloads, all communicated through UDP channels designed to evade traditional network defenses.

Researchers recently observed multiple UDPGangster campaigns targeting users in Tu

31017391896?profile=RESIZE_400xDuring a recent incident response engagement, researchers at the FortiGuard IR services (FGIR) responded to a ransomware attack where the threat actor heavily used anti forensic techniques to cover their tracks and to avoid their malware getting into the hands of researchers.  They attempted to achieve this by deleting files and folders they had created, clearing logs and obfuscating malware.

Link to full report:  IR-25-344-001_AutoLogger.pdf

31016876682?profile=RESIZE_400xAt the end of October, during a global disruption of AWS connections, FortiGuard Labs observed malware named “ShadowV2” spreading via IoT vulnerabilities.  These incidents affected multiple countries worldwide and spanned seven different industries.  To date, the malware appears to have been active only during the large-scale AWS outage.  Researchers believe this activity was likely a test run conducted in preparation for future attacks.  The following article provides a detailed analysis of the

31017386491?profile=RESIZE_400xMarquis Software Solutions is notifying banks and credit unions of a ransomware attack that leaked their customer data.  The Texas-based digital and physical marketing firm learned of the ransomware cyber-attack on 14 August 2025, after detecting suspicious activity on its network.  It responded by launching an investigation and notifying law enforcement.  The probe determined that the threat actor breached its SonicWall firewall to gain initial access.[1]

After gaining access, the attackers exf

31016868683?profile=RESIZE_400xSome of the nation's largest banks, including JPMorgan Chase, Citi, and Morgan Stanley, spent the end of November 2025 assessing exposure after a significant cyberattack on SitusAMC, a major technology and services vendor in the mortgage and real estate finance ecosystem.  SitusAMC confirmed that a cyberattack hit it on 12 November 2025 and that it has spent nearly two weeks determining which information was accessed. According to a statement posted on its website, the company identified "data r

31017041096?profile=RESIZE_400xIndustrial cyber security is facing significant challenges driven by the increasing complexity of attacks, such as ransomware and supply-chain compromises, alongside a proliferation of interconnected devices and a persistent shortage of skilled professionals.  Attacks against critical infrastructure have evolved from isolated incidents into coordinated conducted by both state and non-state actors.

Cyber threats have increased in frequency and technical capability, particularly those leveraging A

31017040087?profile=RESIZE_400xA Chinese state-aligned threat actor may have been spying on Russia's government for years through its IT sector.  For all of the adversarial intelligence gathering going on in the world today, there is also plenty of spying among friends. Friendly nations, and friendly-ish nations like China and Russia, regularly use cyberspace against their allies to glean potentially valuable political or economic intelligence, gain advantages in strategic negotiations, or simply steal technology.

On 20 Novem

31016867076?profile=RESIZE_400xEuropol has taken down the illegal cryptocurrency mixing service ‘Cryptomixer’, which is suspected of facilitating cybercrime and money laundering.  During the operation, which was conducted in conjunction with Swiss and German law enforcement, €25m ($30m) worth of the cryptocurrency Bitcoin was seized.  Action took place between 24-28 November 2025 in Zurich, Switzerland.

Three servers were seized, along with the cryptomixer.io domain.  The operation resulted in the confiscation of over 12 tera