Snowflake hacker pleads guilty, faces up to 32 years in prison

Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record.

The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.

Continue reading Snowflake hacker pleads guilty, faces up to 32 years in prison

Open-source software’s archenemy TeamPCP goes back further than anyone thought

Oligo Security uncovered evidence of a long operational history, including multiple previous attacks it traced to the same attacker infrastructure and tools.

The post Open-source software’s archenemy TeamPCP goes back further than anyone thought appeared first on CyberScoop.

Continue reading Open-source software’s archenemy TeamPCP goes back further than anyone thought

Massive supply-chain attack compromises 440 packages under four hours

Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages.

The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.

Continue reading Massive supply-chain attack compromises 440 packages under four hours

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion.

The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

Continue reading Prolific ransomware group behind SonicWall zero-day attacks

CrowdStrike: AI is now both the weapon and the target in cyberattacks

AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them.

The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.

Continue reading CrowdStrike: AI is now both the weapon and the target in cyberattacks

Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims

Derrick Van Yeboah impersonated fake romantic partners and directly interacted with victims for more than nine years.

The post Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims appeared first on CyberScoop.

Continue reading Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

Unknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said.

The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop.

Continue reading Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

AI-assisted security tools are finding more bugs, but the threat level has not changed

Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren’t being exploited any faster than traditional ones.

The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop.

Continue reading AI-assisted security tools are finding more bugs, but the threat level has not changed

Despite multiple takedowns, botnets continue to grow

Roughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint.

The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop.

Continue reading Despite multiple takedowns, botnets continue to grow

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments.

The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

Continue reading Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries