Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign

The social engineering campaign spiked last month and has targeted dozens of organizations since May 2025, according to ReliaQuest.

The post Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign appeared first on CyberScoop.

Continue reading Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign→

OpenAI’s Mac apps needs an update thanks to the Axios hack

The company said a developer tool automatically retrieved a malicious version of the popular open-source library, but insists the integrity of its systems and software were not impacted.

The post OpenAI’s Mac apps needs an update thanks to the Axios hack appeared first on CyberScoop.

Continue reading OpenAI’s Mac apps needs an update thanks to the Axios hack→

Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs

Censys researchers warned that thousands of devices are exposed to the Iranian government’s campaign targeting energy, water, and U.S. government services and facilities.

The post Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs appeared first on CyberScoop.

Continue reading Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs→

Feds quash widespread Russia-backed espionage network spanning 18,000 devices

Forest Blizzard, a threat group attributed to Russia’s GRU, hijacked network traffic to steal credentials and tokens for Microsoft accounts and other services.

The post Feds quash widespread Russia-backed espionage network spanning 18,000 devices appeared first on CyberScoop.

Continue reading Feds quash widespread Russia-backed espionage network spanning 18,000 devices→

Cybercrime losses jumped 26% to $20.9 billion in 2025

The FBI’s annual report on digital crimes exposes a worsening environment. Yet, an unknown number of victims still suffer in the shadows never reporting the crimes they endure.

The post Cybercrime losses jumped 26% to $20.9 billion in 2025 appeared first on CyberScoop.

Continue reading Cybercrime losses jumped 26% to $20.9 billion in 2025→

Fortinet customers confront actively exploited zero-day, with a full patch still pending

Two critical defects in FortiClient EMS have been exploited in the past couple weeks. Experts push for users to apply an immediate hotfix.

The post Fortinet customers confront actively exploited zero-day, with a full patch still pending appeared first on CyberScoop.

Continue reading Fortinet customers confront actively exploited zero-day, with a full patch still pending→

Former NSA chiefs worry American offensive edge in cybersecurity is slipping

A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come.

The post Former NSA chiefs worry American offensive edge in cybersecurity is slipping appeared first on CyberScoop.

Continue reading Former NSA chiefs worry American offensive edge in cybersecurity is slipping→

Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack

Attackers compromised the open-source security tool and published malicious versions of the software. Mandiant warns the fallout could impact up to 10,000 downstream victims.

The post Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack appeared first on CyberScoop.

Continue reading Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack→

Experts insist Trump administration’s cyber strategy is already paying off

Leaders from various cybersecurity institutions were quick to defend and evangelize the administration’s strategic pivots in cyberspace.

The post Experts insist Trump administration’s cyber strategy is already paying off appeared first on CyberScoop.

Continue reading Experts insist Trump administration’s cyber strategy is already paying off→

The phone call is the new phishing email

Voice-based phishing was at the root of multiple attack sprees Mandiant responded to last year, reflecting a concerning shift in tactics.

The post The phone call is the new phishing email appeared first on CyberScoop.

Continue reading The phone call is the new phishing email→