Conservative activist Robby Starbuck has filed a defamation lawsuit against Meta alleging that the social media giant’s artificial intelligence chatbot spread false statements about him, including that he participated in the riot at the US Capitol on 6 January 2021. Starbuck, known for targeting corporate DEI programs, said he discovered the claims made by Meta’s AI in August 2024, when he was going after “woke DEI” policies at motorcycle maker Harley-Davidson.[1] “One dealership was unhappy w
All Articles (2531)
A third-party data breach has compromised the personal information of more than 200,000 Harbin Clinic patients. The breach stems from a cyber-attack in July 2024 targeting Nationwide Recovery Services (NRS), a debt collection agency contracted by the Georgia-based healthcare provider. The incident came to light following unusual activity on NRS systems, which led to a network outage. Investigations revealed that threat actors accessed the NRS network between July 5 and 11, 2024, during which
New estimates suggest that international criminal outfits are stealing hundreds of billions of dollars from the US government every year. One of the major goals of the second Trump administration has been to cut what it perceives as government waste thousands of jobs or federal funding programs, for example. It has not gone so smoothly, and it has caused a lot of furors, but there is one non-partisan area the government might consider applying its resources, if the goal is to save money. In A
Improved satellite connectivity has made vessels more efficient at sea, but it has also left their operations and network systems more vulnerable to cyber-attacks. That is one of the main takeaways from a newly released report, which lays out threats to the Marine Transportation System (MTS) that Coast Guard Cyber identified in 2024, as well as ways operators can strengthen their cyber defenses against them.
The fourth annual Cyber Trends and Insights in the Marine Environment (CTIME) report i
VanHelsing Ransomware Overview—In mid-March 2025, the first sample of the VanHelsing ransomware was made available on a publicly accessible file-scanning site. Like other ransomware attacks, VanHelsing demands a ransom to decrypt files via dropped ransom notes.
Infection Vector - Information on the infection vector used by the VanHelsing ransomware threat actor is unavailable. However, it is not likely to differ significantly from other ransomware groups.[1]
Attack Method - When run, the VanHe
It is hard to believe that ten years have gone by since the devastating hack of the US Office of Personnel Management (OPM). OPM handles all personnel matters for government employees, including all associated government documents. BTW - I was a federal employee for 20 years and I am quite confident the CCP has all my personal information. Ten years ago, that was big news. Today, the threat remains high.
US Senator Mark Warner warned the OPM last week that it should not end government contr
Artificial intelligence (AI) is no longer an emerging trend but a present-day disruptor. From automated threat detection to generative content creation, AI is transforming industries, workflows, and entire careers. While some sectors are seeing productivity gains, others are bracing for significant job displacement as AI replaces or reshapes roles that rely heavily on routine, repetitive, or pattern-based tasks.
In the cybersecurity industry and across the broader workforce, the question is no
On 14 May 2025, the Nucor Corporation, which is the largest steel producer in the United States, disclosed a cybersecurity incident involving unauthorized access to certain IT systems. In response, the Charlotte-based company proactively took affected systems offline and temporarily halted production at various locations as a precautionary measure. In its 8-K filing with the US Securities and Exchange Commission, Nucor stated: "Upon detecting the incident, the company began promptly taking ste
Intel has spent much of its goodwill with customers chasing down bugs: the Spectre and Meltdown bugs it dealt with years ago, and the instability that plagued its Raptor Lake processors last year. Now there are additional chapters in each of those stories.
You don’t have to do anything; make sure your PC is patched and updated. But there will be a price to pay in performance in fixing the latest issue, and one you can’t do anything about.[1]
On 1 May, Intel issued another microcode update for
The recent cyber-attacks aimed at Marks & Spencer, the Co-op and Harrods have been in the news, but this is not just an issue for retailers, as hackers strike almost any firm, in any line of business, at anytime and anywhere in the world. The reality for business leaders, and for investors, is that the risk is practically universal. FTSE 100 CEOs and entrepreneurs running small firms are living in fear that they will be next. Cyber-attacks have cost UK companies £44 billion in lost revenue ov
Security researchers have reported on an active Phishing-as-a-service (PhaaS) operation that victimized hundreds of thousands in just a few months. According to Norwegian security firm Mnemonic, Darcula is designed to target iPhone and Android users with phishing messages, spoofing brands to trick them into handing over card details. Operating globally, it convinces victims to click through on SMS, RCS, and iMessage texts impersonating brands such as delivery firms. Victims are asked to pay d
Intel has spent much of its goodwill with customers chasing down bugs: the Spectre and Meltdown bugs it dealt with years ago, as well as the instability that plagued its Raptor Lake processors last year. Now there are additional chapters in each of those stories.
You don’t have to do anything, just make sure your PC is patched and up to date. But there will be a price to pay in performance in fixing the latest issue, and one you can’t really do anything about.[1]
On 1 May, Intel issued yet ano
The FortiMail IR team recently uncovered a new email campaign distributing a Remote Access Trojan (RAT) using multiple evasion techniques to target organizations in Spain, Italy, and Portugal. The campaign leverages the serviciodecorreo email service provider, which is configured as an authorized sender for various domains and successfully passes SPF validation.[1]
Affected platforms: Windows (primarily), Linux & macOS (if Java is installed) Impacted parties: Users on systems with Java Runti |
A new malware called LOSTKEYS, capable of stealing files and system data, has been identified by Google’s Threat Intelligence Group (GTIG) as part of a series of cyberattacks attributed to COLDRIVER, a threat actor linked to the Russian government. The malware, observed in attacks during January, March, and April 2025, marks a new step in COLDRIVER’s evolving capabilities. Previously known primarily for credential phishing targeting Western diplomats, NGOs, and intelligence personnel, the gr
Unveiled today at PIVOTcon, this joint research from Validin, the global internet intelligence platform, and SentinelLABS, the threat intelligence and research team of SentinelOne, exposes the FreeDrain Network: a sprawling, industrial-scale cryptocurrency phishing operation that has quietly siphoned digital assets for years. What began as an investigation into a single phishing page quickly uncovered a vast, coordinated campaign weaponizing search engine optimization, free-tier web services, a
In April 2025, FortiGuard Labs observed a threat actor using phishing emails with malicious HTML files to spread Horabot, malware that primarily targets Spanish-speaking users. It is known for using crafted emails that impersonate invoices or financial documents to trick victims into opening malicious attachments and can steal email credentials, harvest contact lists, and install banking trojans.
Horabot leverages Outlook COM automation to send phishing messages from the victim’s mailbox, enabl
The vulnerabilities affect SonicWall's SMA devices for secure remote access, which threat actors have heavily targeted in the past. CISA added two older SonicWall bugs to the Known Exploited Vulnerabilities (KEV) catalog, marking the latest threat activity targeting the network security vendor's products. The vulnerabilities are tracked as CVE-2023-44221 and CVE-2024-38475 and affect SonicWall's SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v secure remote access products. They can be exploi
The uncomfortable reality is that the energy sector's cyberattacks have doubled between 2020 and 2022. Indeed, 48 successful attacks hit Europe’s energy infrastructure in 2022 alone, which is why cybersecurity has become a key component of ensuring overall energy security. In particular, cybersecurity experts in the Netherlands have been closely monitoring the major power outage affecting Spain and Portugal and are raising pressing concerns about the vulnerability of critical infrastructure.[1
A critical flaw found in the open source Langflow platform was added to the US Cybersecurity and Infrastructure Security Agency’s (CISA's) Known Exploited Vulnerabilities (KEV) catalog. Langflow is a Python-based Web application, a popular tool in the realm of agentic AI that allows users to build AI-driven agents and workflows. The vulnerability, tracked as CVE-2025-3248, is described as a missing authentication flaw that allows remote attackers to compromise Langflow servers. With a CVSS sc
Venture capital firm Insight Partners has confirmed that sensitive data for employees and limited partners was stolen in a January 2025 cyberattack. Insight Partners is a prominent global venture capital and private equity firm specializing in high-growth technology, software, and internet companies, managing over $90 billion in regulatory assets. The company has significant investments in more than 800 companies worldwide, including Twitter, HelloFresh, and Veeam Software.
On 18 February 2025