Cybersecurity

Cybersecurity
Dutch Police Seize 200+ Servers in 17-Million-Device Botnet Takedown
Dutch law enforcement dismantled a botnet of 17 million compromised devices by seizing over 200 command-and-control servers in a major coordinated takedown with hosting provider ...
Application Security
Gogs CVSS 9.4 RCE Zero-Day Has No Patch and a Metasploit Module
A CVSS 9.4 argument injection zero-day in Gogs lets any authenticated user achieve RCE on internet-exposed servers. No patch exists and Rapid7 has released a ...
Cybersecurity
California AG Sues 23andMe Successor Over 2023 Genetic Data Breach
California AG Rob Bonta sued Chrome Holding Co., 23andMe's successor after bankruptcy, over the 2023 breach exposing genetic health data for millions of users.
Cybersecurity
LLMShare Campaign Hosts Infostealer Downloads on ChatGPT’s Own Domain
LLMShare, discovered by Push Security, abuses ChatGPT's share links on chatgpt.com to host fake outage pages that deliver infostealer malware to Windows and macOS users.
Cybersecurity
NC Man Gets 121 Months for Selling Elderly Americans’ Data to Scammers
Troy Murray, 57, of North Carolina was sentenced to 121 months in prison and ordered to forfeit $5.2 million for selling elderly Americans' data to ...
Application Security
Microsoft: 14 npm Packages Linked to Single Actor Stealing AWS Keys
Microsoft attributed 14 malicious npm packages impersonating OpenSearch and Elasticsearch to a single threat actor who stole AWS credentials and CI/CD secrets from developer environments.
Cybersecurity
Play Ransomware Lists MyPillow, US Telecom in Six-Victim Batch
Play ransomware listed six victims on May 25, led by consumer brand MyPillow and a US telecom provider, in a multi-sector batch spanning four countries.
Cybersecurity
Incransom Hits Illinois Health Center and Manufacturer
Incransom claimed two US victims on May 25 — Open Door Health Center in Illinois and manufacturer PILLER AIMMCO — part of a three-victim, 48-hour ...
Cybersecurity
Nova Ransomware Lists Russian Oil Firm Eriell in May 26 Batch
Nova ransomware posted Russian oil firm Eriell and tech company sandox info on May 26, continuing a five-victim, five-day burst spanning four world regions.
Cybersecurity
Incransom Claims Meirc Breach, Threatens to Leak 1TB of Client Data
Incransom has claimed a full-network breach of Meirc Training & Consulting on May 25, threatening to publish 1TB of employee and client data within one ...