Cyber and Critical Infrastructure News

cyber threat news

China’s targeted attacks on the financial services, media, manufacturing, and the industrial sectors increased 300 percent. The current federal government shutdown, coupled with the lapse of the Cybersecurity Information Sharing Act of 2015, is significantly constraining the federal government’s ability to coordinate with industry and execute its defensive cyber mission. Senate Democrats must reopen the government so we can chart a better path forward for our nation’s collective cyber resilience.” This week’s roundup examines corporate cyberattacks, AI security risks, Microsoft zero-days, logistics disruption and threats targeting personal accounts.

Later reports assessed that the hack affected almost 70,000 customers and cost the cryptocurrency exchange $400m. The attackers planned to use the stolen data to impersonate Coinbase and trick customers into handing over their cryptocurrency holdings. Coinbase stated that cybercriminals bribed and recruited a group of rogue overseas support agents to steal its customer data and facilitate social engineering attacks. In May 2025, in a bold move against cybercrime, cryptocurrency exchange Coinbase offered a $20m reward to anyone who could help identify and bring down the perpetrators of a recent cyber-attack it had just reported.

Breaking news, news analysis, and expert commentary on cybersecurity threat intelligence, including tools & technologies. It can provide useful cyber awareness context when people are checking whether an outage might be linked to a wider cyber attack. But during major incidents, DDoS activity, DNS failures, botnet traffic and suspicious network events can all become part of the investigation. Many service disruptions are caused by misconfiguration, overloaded systems, failed updates, cloud problems or routing issues. If a telecom outage, website outage, cloud outage or service disruption happens at the same time as heavy attack activity, the map can help people investigate what is happening, but it cannot identify the exact cause by itself.

Biggest data breaches

cyber threat news

At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

cyber threat news

This massive volume reflects the expanding cybercrime growth and the need https://nutritioninpill.com/many-employee-work-habits-seem-innocent-but-invite-security-threats/ for stronger digital defenses. Incidents in 2025 increasingly disrupted food supply chains, healthcare services, airports, and government operations. Treasury, Snowflake customers, and the UK Ministry of Defence all highlight how third-party vulnerabilities can lead to disruptions. Many of 2025’s most damaging incidents began with compromised vendors or shared platforms. Data breaches grew larger and more frequent from 2023 to 2025, impacting worldwide users. The UK’s AI Safety Institute said recent behaviour from Anthropic and OpenAI models was malicious and unprecedented.

“Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints,” CISA said . A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant. Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. Anthropic has been conducting tests to identify issues in how AI agents interact with each other. Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems.

The threat intelligence and exposure management platform said it began to observe exploitation attempts within hours of public disclosure, and that it has seen hundreds of attempts originating from a small pool of IP addresses. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). “An authentication issue was addressed with improved state management,” Apple said in an advisory released on August 6, 2026.

cyber threat news

The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware. Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. “This vulnerability has no public PoC and is not known to be exploited,” the threat intelligence company said in an X post … Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

  • If a telecom outage, website outage, cloud outage or service disruption happens at the same time as heavy attack activity, the map can help people investigate what is happening, but it cannot identify the exact cause by itself.
  • The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
  • A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums.
  • Outside of nation-state actors, decentralized cybercriminal groups, such as Scattered Spider, continue to launch ransomware and data extortion campaigns against major global companies.

Every story here is about real risks that your team needs to know about right now. We’re seeing malware hidden in virtual machines, side-channel leaks exposing AI chats, and spyware quietly targeting Android devices in the wild. Four states want penalties that approach Meta’s market value, but the lasting threat is a court-ordered overhaul of Facebook and Instagram for young users. A .gov website belongs to an official government organization in the United States. The unauthenticated SQL injection flaw could lead to remote code execution on certain server configurations.

With advancements in artificial intelligence (AI), North Korea has deployed undercover information technology (IT) workers to infiltrate U.S. companies by gaining remote jobs, in part, using AI as a force multiplier. Backed by FortiGuard threat intelligence, Fortinet enables security teams to stay ahead of high-impact cyber https://ativanx.com/2018/09/05/eight-signs-of-a-strong-security-culture/ risks. A flood of companies are revealing AI models gained access to the internet – with real consequences.

In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure. These cyber history stories show how ransomware, destructive malware, industrial cyber weapons and global cyber crime incidents changed the way governments, companies and ordinary users think about cybersecurity.

The AI company said its ongoing review of the incident revealed a “small number of cases” where the models, including GPT-5.6 Sol and an “even more capable pre-release model,” identified and used exposed credentials at the account-level on other publicly-available services. OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack. Adform is telling people to clear their browser cache because the altered file may remain cached after the fix, and to check any wallet address before sending funds. Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. PNLD said, “There is no evidence to suggest that passwords or other security credentials have been compromised.” The service provides legal information, products and services to UK police forces and criminal justice organisations. That exposure could make phishing messages targeting named officers appear more convincing, according to UK government guidance .