Hacker claims millions of records stolen from corporate Azure tenants

A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), accor… Continue reading Hacker claims millions of records stolen from corporate Azure tenants

France’s tax authority admits hackers made off with data on 678,000 individuals

France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after… Continue reading France’s tax authority admits hackers made off with data on 678,000 individuals

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CV… Continue reading Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

SafePal breach affects 39,798 customers, data allegedly for sale

Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorizati… Continue reading SafePal breach affects 39,798 customers, data allegedly for sale

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police nam… Continue reading Police bust cybercrime ring accused of stealing €30 million in four-day spree

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already ga… Continue reading Windows 11’s strongest security defenses can be bypassed without a screwdriver

New Android malware relays bank cards to fraudsters while victims still hold them

Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives … Continue reading New Android malware relays bank cards to fraudsters while victims still hold them

Ukrainian police raid 94 fraudulent call centers, seize $2 million

Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: C… Continue reading Ukrainian police raid 94 fraudulent call centers, seize $2 million

White House authorizes private US companies to hack foreign criminal networks

President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government.
The post White Hous… Continue reading White House authorizes private US companies to hack foreign criminal networks

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its J… Continue reading Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)