๐ง Subscribe to the podcast feed | Direct MP3
Security News
Kiteworks urges 6-hour server shutdown over potential zero-day attacks (BleepingComputer / The Record) โ Secure file-sharing platform Kiteworks told customers worldwide to shut down servers on Saturday after receiving credible threat intelligence from federal intelligence agencies warning of an imminent attack targeting its systems.
Storm-3168: Agentic-driven cloud attacks using compromised service principals (Microsoft Security Blog) โ Microsoft Research published analysis of JADEPUFFER/Storm-3168, described as the first documented agentic ransomware: the group uses compromised cloud service principals for automated, AI-driven lateral movement and extortion at scale.
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' (The Register) โ ShinyHunters claims it compromised an FBI-affiliated site to make a statement about protecting its extortion operation, with five days remaining on its current ultimatum to an unnamed victim.
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw (BleepingComputer) โ Clop's data leak site was compromised through an unpatched unauthenticated path traversal flaw in Grav CMS; Clop has since migrated to a new Tor address.
Bitget blames North Korea for $387.5M crypto wallet raid (The Register) โ Crypto exchange Bitget confirmed a North Korean-attributed attack resulted in $387.5 million stolen; some wallet addresses were frozen but most funds have moved.
CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacks (BleepingComputer) โ CISA added CVE-2026-5430, a critical WSO2 authentication bypass, to the Known Exploited Vulnerabilities catalogue alongside SharePoint and Adobe Commerce flaws under active exploitation.
There's a new way to break RSA encryption (Slashdot / Ars Technica) โ Researchers published a classical computing RSA signature forgery technique that reduces effective RSA security to an unacceptable threshold, strengthening the case for prompt RSA deprecation.
Google ads caught delivering convincing scareware to unsuspecting users (Ars Technica) โ Researchers found Google ads across high-traffic websites delivering tech support scareware that freezes browser screens on Windows and Mac, directing victims to bogus call centre numbers.
Crooks use fake desktop apps to fool HR staff into giving remote access (The Register) โ Attackers are distributing fraudulent HR software Windows apps that grant remote access once installed, targeting HR staff who have broad access to employee data.
U.S. Soldier gets 70 months in prison for AT&T, Verizon extortions (Krebs on Security) โ A US Army soldier was sentenced to 70 months for hacking AT&T and Verizon and extorting both companies using call metadata from more than 100 million customers.
Labcorp to overhaul data security practices, pay $2.3M fine (The Record) โ Labcorp agreed to a $2.3 million settlement and full security overhaul with specific focus on vendor data-sharing controls and third-party risk management.
Elementor WordPress flaw lets attackers create admin accounts (BleepingComputer) โ A CSRF vulnerability in the Elementor plugin could allow unauthenticated attackers to create WordPress administrator accounts.
UK & Critical National Infrastructure
Welsh police cyberattack ๐ฌ๐ง: Dyfed-Powys Police disclosed a cyberattack disrupting non-emergency systems and potentially compromising staff information โ the latest in a pattern of UK law enforcement targeting. (The Record)
UK energy sector โ double ransomware hit: Ar Valve Resources (Energy & Utilities, GB) was claimed by Wallstreet in this period, joining GDM Pipelines (Qilin) from yesterday. Two UK energy sector claims in 48 hours represents a notable concentration; both claims remain active and unconfirmed by the organisations.
Revolut ๐ฌ๐ง: ImNotAVillain's ransomware claim against Revolut remains live, concurrent with the DriveWealth social engineering breach disclosed yesterday that affected some Revolut customers. No indication of passwords or financial data compromised in the DriveWealth incident.
No new NCSC advisories have been published in the past 48 hours.
Ransomware Victims (48h)
40 victims ยท 16 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| dragonforce | HEC Group | ๐น๐ผ TW | Other |
| emperador | Electrolux & Ontrac | โ | Manufacturing |
| everest | CENELEC | ๐ง๐ช BE | Professional Services |
| everest | ETS | โ | Education |
| everest | Morula IVF โ ๏ธ | ๐ฟ๐ฆ ZA | Healthcare |
| everest | Reliance Audit | โ | Professional Services |
| everest | Securitas Group | ๐ธ๐ช SE | Professional Services |
| everest | UNIRITA | ๐ฏ๐ต JP | Technology |
| ImNotAVillain | Revolut ๐ฌ๐ง | ๐ฌ๐ง GB | Financial Services |
| incransom | bnlawmacau.com | ๐ฒ๐ด MO | Professional Services |
| incransom | Grupo Caberj | ๐ง๐ท BR | Manufacturing |
| incransom | pharma5.ma โ ๏ธ | ๐ฒ๐ฆ MA | Healthcare |
| incransom | ukbjja.org ๐ฌ๐ง | ๐ฌ๐ง GB | Other |
| incransom | welgenone.com โ ๏ธ | ๐บ๐ธ US | Healthcare |
| krybit | airtanzania.co.tz | ๐น๐ฟ TZ | Transportation |
| krybit | efada.sa | ๐ธ๐ฆ SA | Other |
| krybit | www.jonesthegrocer.com | ๐ฆ๐บ AU | Retail |
| lockbit5 | corisricambi.it | ๐ฎ๐น IT | Other |
| metaencryptor | GE Vernova Inc. โ ๏ธ | ๐บ๐ธ US | Energy & Utilities |
| metaencryptor | PKF Hadiwinata | ๐ฎ๐ฉ ID | Professional Services |
| metaencryptor | Platinum Healthcare Staffing โ ๏ธ | ๐บ๐ธ US | Healthcare |
| N0n | TapClicks | ๐บ๐ธ US | Technology |
| qilin | All Tech Machine & Engineering | ๐บ๐ธ US | Manufacturing |
| qilin | Dao Group | โ | Other |
| qilin | GDM Pipelines โ ๏ธ ๐ฌ๐ง | ๐ฌ๐ง GB | Energy & Utilities |
| qilin | Iberia Compositech Manufacturing | ๐ช๐ธ ES | Manufacturing |
| qilin | Inversiones Bolรญvar | ๐จ๐ด CO | Financial Services |
| qilin | Zig Inge Group | ๐ฆ๐บ AU | Other |
| rhysida | NEAD Pro | ๐ฎ๐น IT | Professional Services |
| SilentRansomGroup | N... | โ | Unknown |
| SilentRansomGroup | S... | โ | Unknown |
| Spirals | Armada Credit Bureau | ๐บ๐ฌ UG | Financial Services |
| Vexy Ransomware | Majani Insurance Brokers | ๐ฐ๐ช KE | Financial Services |
| Wallstreet | Ar Valve Resources โ ๏ธ ๐ฌ๐ง | ๐ฌ๐ง GB | Energy & Utilities |
| Wallstreet | Beatus Cartons ๐ฌ๐ง | ๐ฌ๐ง GB | Manufacturing |
| Wallstreet | Breast Implant Center of Hawaii โ ๏ธ | ๐บ๐ธ US | Healthcare |
| Wallstreet | Catholic University of El Salvador | ๐ธ๐ป SV | Education |
| Wallstreet | GTFM | ๐บ๐ธ US | Other |
| Wallstreet | Prater & Ridley Attorneys | ๐บ๐ธ US | Professional Services |
| Wallstreet | Tobin & Company | ๐บ๐ธ US | Financial Services |
shinyhunters posted a statement update โ not a victim listing: claims goals achieved, 5 days remaining, denies financial motivation.