Latest Articles

New Phishing Campaign by Gamaredon Targets Government Entities via WinRAR Zero-Day Exploit

New Phishing Campaign by Gamaredon Targets Government Entities via WinRAR Zero-Day Exploit

Date: October 29, 2025 Overview: The Russian-linked threat actor Gamaredon has launched a sophisticated spear-phishing campaign targeting government ministries, diplomatic services, parastatals...

Sweden’s National Grid Operator Hit by Ransomware-Linked Data Breach

Sweden’s National Grid Operator Hit by Ransomware-Linked Data Breach

Stockholm, October 28, 2025 — Sweden’s state-owned transmission system operator Svenska kraftnät (SVK) has confirmed that it suffered a major cybersecurity incident over the weekend. The breach,...

Crypto24 Ransomware Claims Breach of Bayu Buana Travel in Indonesia

Crypto24 Ransomware Claims Breach of Bayu Buana Travel in Indonesia

The Crypto24 ransomware group has claimed responsibility for a data breach impacting Bayu Buana Travel, one of Indonesia’s most prominent corporate and leisure travel agencies. The claim appeared...

Massive Gmail Password Breach (183 Million Accounts Exposed) in the latest data breach

Massive Gmail Password Breach (183 Million Accounts Exposed) in the latest data breach

Global — October 28, 2025 Summary: Security researchers and analysts have identified a massive trove of stolen credentials — roughly 183 million email account entries and associated passwords —...

Dissecting Qilin Ransomware’s Cross-Platform Attack Chain: Linux Payload Execution and BYOVD Abuse

Dissecting Qilin Ransomware’s Cross-Platform Attack Chain: Linux Payload Execution and BYOVD Abuse

The Qilin ransomware group, also known as Agenda or Water Galura, has unveiled a new hybrid attack method that blends a Linux-based payload with a Bring-Your-Own-Vulnerable-Driver (BYOVD) exploit....

Ransomware Attack on Mino Industry Co., Ltd. (Japan)

Ransomware Attack on Mino Industry Co., Ltd. (Japan)

Mino Industry Co., Ltd., a Japanese manufacturer specialising in screen-printing and stencil machinery, confirmed a ransomware incident in late October 2025. Open disclosures and monitoring platforms...

Dublin Airport passenger data could be compromised following cyber breach

Dublin Airport passenger data could be compromised following cyber breach

Published: October 26, 2025 Location: Dublin, Ireland Summary: A significant data breach at Dublin Airport has compromised passenger information for potentially millions of individuals who traveled...

Critical Alert: WSUS Deserialization Flaw (CVE-2025-59287) Under Active Exploitation

Critical Alert: WSUS Deserialization Flaw (CVE-2025-59287) Under Active Exploitation

Microsoft released an out-of-band security update for a critical remote code execution (RCE) in Windows Server Update Services (WSUS), tracked as CVE-2025-59287. The vulnerability is actively...

Critical ‘SessionReaper’ Exploit Hits Adobe Commerce and Magento - Urgent Patching Advised to Prevent Global E-Commerce Breaches

Critical ‘SessionReaper’ Exploit Hits Adobe Commerce and Magento - Urgent Patching Advised to Prevent Global E-Commerce Breaches

Hackers Ramp Up Attacks on Adobe Commerce with 'SessionReaper' Vulnerability Exploitation body { font-family: Arial, sans-serif; line-height: 1.6; margin: 20px; } h1 { color: #333; } h2 { color:...

Lanscope Zero-Day Exploit Sparks Urgent Security Response Across Asia-Pacific

Lanscope Zero-Day Exploit Sparks Urgent Security Response Across Asia-Pacific

A newly uncovered zero-day vulnerability in Lanscope Endpoint Manager has triggered a wave of emergency patching across enterprises in Japan and other parts of Asia. The flaw, now tracked as...

Jaguar Land Rover Cyber Attack Deepens Supply-Chain and Production Crisis

Jaguar Land Rover Cyber Attack Deepens Supply-Chain and Production Crisis

A major cyber incident that forced Jaguar Land Rover (JLR) to suspend production at multiple UK plants has left a measurable economic impact on the automotive sector and highlighted fragilities...

“ToolShell” SharePoint Flaw (CVE-2025-53770) Escalates Risk to On-Premises Environments

“ToolShell” SharePoint Flaw (CVE-2025-53770) Escalates Risk to On-Premises Environments

A critical remote-code-execution vulnerability in Microsoft SharePoint Server, tracked as CVE-2025-53770 and dubbed "ToolShell", has been exploited in the wild. Immediate patching and active hunting...

FIA Confirms Data Breach Exposed F1 Drivers' Personal Information

FIA Confirms Data Breach Exposed F1 Drivers' Personal Information

A vulnerability in the FIA’s driver-categorisation portal allowed access to passport scans, licence documents and internal correspondence of world-class drivers. The incident raises urgent questions...

Synthient Stealer Data Dump: The Hidden Cost of Compromised Credentials

Synthient Stealer Data Dump: The Hidden Cost of Compromised Credentials

The “Synthient” corpus consolidates infostealer logs (credentials, cookies, autofill data) harvested from compromised endpoints, plus combolists circulating in criminal channels. Expect...

China’s MSS Reports Foreign Cyberattack on National Time Service Center – Critical Timing Infrastructure Targeted

China’s MSS Reports Foreign Cyberattack on National Time Service Center – Critical Timing Infrastructure Targeted

Beijing, 19 October 2025 — China’s Ministry of State Security (MSS) issued a statement confirming that foreign intelligence actors attempted to infiltrate the National Time Service Center (NTSC), the...

Askul ransomware attack halts orders and shipments across B2B and consumer platforms

Askul ransomware attack halts orders and shipments across B2B and consumer platforms

Japanese e-commerce and office-supplies giant ASKUL Corporation confirmed a ransomware incident that caused widespread systems disruption, forcing a suspension of order intake and...

F5 Networks Breach Triggers CISA Emergency Directive Amid Fears of Supply-Chain Exploitation

F5 Networks Breach Triggers CISA Emergency Directive Amid Fears of Supply-Chain Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive following a breach at F5 Networks, a major supplier of application delivery and...

“Vocus Group Cybersecurity Incident: Email Accounts and SIM Swaps Exposed in October 2025 Attack”

“Vocus Group Cybersecurity Incident: Email Accounts and SIM Swaps Exposed in October 2025 Attack”

Overview: On 19 October 2025 Vocus Group — parent company of consumer brands including Dodo and iPrimus — experienced a cybersecurity incident that resulted in unauthorised access to a number of...

Massive 100K-Node Botnet Unleashes Coordinated RDP Blitz Across US Networks

Massive 100K-Node Botnet Unleashes Coordinated RDP Blitz Across US Networks

A massive botnet comprising more than 100,000 unique IP addresses has been observed launching a coordinated wave of attacks against Remote Desktop Protocol (RDP) services in the United States....

Stop worshipping CVSS: prioritize exploitability and blast radius, not the score

Stop worshipping CVSS: prioritize exploitability and blast radius, not the score

Opinion: CVSS was never meant to decide tomorrow’s patch queue by itself. Yet many organizations still treat 8.0+ as gospel and everything else as “later.” That mindset ships toil, not risk...