Skip to main content

Malware & Ransomware

Brightly-lit hospital corridor with medical equipment, computers, and researchers in the distance.

Chinese hackers breach medical research servers with custom malware

Malicious hackers linked to China breached a North American medical research institution, hiding undetected for over a year and gaining access to sensitive research areas. The attackers used custom malware, known as Infinitered, with broad capabilities to siphon off valuable intel from September 2023 to November 2025.

Analyst 207
Cluttered home office desk with Linux workstation, notes, and technical books.

Arch Linux Cracks Down on Malicious Commits in User Repository

Malicious hackers have launched a massive assault on the Arch User Repository, compromising over 1,500 user-submitted packages and forcing the Arch Linux team to temporarily halt new account signups to contain the damage. The attack has been mitigated, but not before highlighting the vulnerability of community-run package repositories.

Analyst 207
Laptop on office desk surrounded by papers and supplies with a blurred screen.

Microsoft 365 Copilot Exploited in 1-Click Data Theft Attack

A critical vulnerability in Microsoft 365 Copilot Enterprise, known as SearchLeak, could be exploited with just one click to steal sensitive data from mailboxes, OneDrive, and SharePoint. Fortunately, Microsoft has patched the flaw, CVE-2026-42824, and no user action is required to stay safe.

Analyst 207
Person sitting at a desk in a well-lit room, with a subtle hint of digital vulnerability.

WordPress Plugins Compromised to Deploy Hidden Backdoors

Over 1.2 million WordPress sites are potentially at risk after a security breach compromised three popular plugins, allowing hackers to secretly install backdoors and gain admin access. The sneaky attack injects malicious code that only kicks in when a logged-in administrator visits the site, putting unsuspecting site owners in the dark.

Analyst 207
Google Chrome browser window on a laptop with blurred extensions page and cityscape outside.

Chrome Extensions Exploit User Data for Adware, Fake Traffic

Beware of Chrome extensions that seem too good to be true: 152 fake live wallpaper and new-tab add-ons have been downloaded around 105,000 times and are secretly spreading adware and fake traffic. These malicious extensions, masquerading as popular themes, have been hiding in plain sight on the Chrome Web Store.

Analyst 207
Network equipment sits in a brightly-lit corporate office setting.

Palo Alto Networks Warns of Active Exploitation of GlobalProtect VPN Flaw

Palo Alto Networks has warned of active exploitation of a critical GlobalProtect VPN flaw, CVE-2026-0257, which allows attackers to bypass security controls and set up unauthorized VPN connections. The company first observed exploitation attempts on May 17, 2026.

Analyst 207
Smartphone screen displays social media post with Arabic interface.

Sniper Dz Scams Target MENA Users with Fake Offers and Browser Exploits

Scammers are targeting people in the Middle East and North Africa with fake offers of free mobile internet, financial rewards, and government subsidies, using fraudulent Facebook accounts to trick victims into divulging sensitive info. These Sniper Dz scams impersonate trusted figures and organizations to lure users in with enticing deals.

Analyst 207
Law enforcement officials stand in a brightly-lit press conference room with subtle hints of technology and cybersecurity…

FBI Disrupts AI-Powered Phishing Service with 1 Million URLs

In a major win for cyber safety, the FBI, Google, and Black Lotus Labs joined forces to dismantle Outsider Enterprise, a notorious phishing-as-a-service operation based in China that had been spreading fake text campaigns through 1 million URLs. This coordinated takedown seized key servers and accounts used by the threat actors.

Analyst 207
Damaged IT equipment and exposed cables in a school district's network closet.

Former IT Employee Sabotages School District with Prolonged Cyberattack

A former IT employee waged a relentless cyberwar against his old employer, the Saydel Community School District, launching a devastating 21-month attack that crippled the district's systems and disrupted classrooms. The attacks began just days after he left his job, with the deletion of the district's Facebook account, and continued with repeated intrusions into critical services.

Analyst 207
University campus scene with students walking near a building, laptop on a bench.

ShinyHunters Exploits Oracle Flaw to Breach Universities

A zero-day flaw in Oracle PeopleSoft PeopleTools, known as CVE-2026-35273, has been exploited by ShinyHunters, potentially infiltrating over 100 organizations, with universities being the hardest hit. This vulnerability allows attackers to execute remote code and take over affected servers, posing a significant threat to higher education institutions.

Analyst 207
Defendant sits in federal court with blurred face, hands visible, in front of judge's bench and US flag.

Conti Ransomware Member Pleads Guilty to Cybercrimes

A longtime member of the notorious Conti ransomware group has pleaded guilty to cybercrimes in federal court, marking a major win for justice after the defendant's attacks caused millions of dollars in damage to people and businesses worldwide. Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, admitted to developing malware and participating in Conti's ransomware campaign.

Analyst 207
Rows of computer servers and networking equipment in a server room with a focus on a specific device showing a subtle hint…

China-Linked Hackers Infiltrate Linux Login Software with Decade-Long Backdoor

A stealthy China-linked hacking group, tracked as Velvet Ant, has been quietly infiltrating Linux login software since 2016, embedding a decade-long backdoor that evades routine security cleanups and password resets. This sophisticated operation, dubbed Operation Highland, has allowed the group to fly under the radar and maintain persistent access to targeted systems.

Analyst 207
Mobile phone on a plain surface with a blurred text message interface and a blurred cityscape in the background.

Google Disrupts Chinese Smishing Network Tied to AI-Generated Phishing Attacks

Google just took down a massive Chinese smishing network that used AI-generated phishing pages to scam millions of mobile users, and is now suing to dismantle the operation for good. The tech giant is teaming up with major carriers like AT&T, T-Mobile, and Verizon to block the fraudulent texts and shut down the Phishing-as-a-Service business.

Analyst 207
Dimly lit computer terminal in a quiet workspace with blurred background elements.

Arch Linux AUR Packages Targeted in Credential Stealer Campaign

Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.

Analyst 207
Blurred computer screen and security emblem in background of courtroom or IT office setting.

Disgruntled IT worker sabotages school district systems, jailed 21 months

A disgruntled IT worker wreaked havoc on a school district's systems for over a year and a half, causing chaos and destruction, after being terminated from his job. The sabotage spree, which included deleting crucial data and altering systems, earned him a 21-month jail sentence.

Analyst 207
Formal proceedings setting with podium, laptop, and blurred emblem in daylight.

Ukrainian Hacker Pleads Guilty in Conti Ransomware Case

Meet Oleksii Lytvynenko, a Ukrainian hacker who just pleaded guilty to his role in the notorious Conti ransomware case, which targeted over 1,000 victims worldwide and raked in a staggering $150 million in ransom payments. He's now facing up to 20 years in prison for his involvement.

Analyst 207
A cluttered home office workspace with an open laptop showing a terminal window, surrounded by papers and coffee cups.

Malware Exploits Arch Linux Packages to Spread Rootkit, Infostealer

Over 400 Arch Linux packages were compromised in a shocking discovery, distributing a sneaky Linux rootkit and infostealer to unsuspecting users through the Arch User Repository (AUR). A cleverly spoofed maintainer account was used to modify the packages and download malicious code.

Analyst 207
Law enforcement officials surround a dismantled cryptocurrency symbol.

FBI and Europol dismantle major crypto laundering platform

In a major crackdown, the FBI and Europol have dismantled AudiA6, a massive cryptocurrency laundering operation that helped cybercriminals move a whopping $389m in illicit funds between 2022 and 2025. The service was linked to at least 15 ransomware operations and multiple cryptocurrency theft schemes, making it a key player in the digital underworld.

Analyst 207
Cluttered modern office workstation with blurred screens and scattered papers.

AI Coding Agents Exposed to Agentjacking Attack

Imagine a sneaky new attack that tricks AI coding assistants into doing an attacker's bidding - without ever touching the victim's infrastructure. This clever hack, dubbed Agentjacking, uses a sneaky sequence of steps to get AI tools to execute malicious code on developers' machines.

Analyst 207
A cluttered workspace with a smartphone, papers, and scribbled notes, set against a blurred cityscape or office background.

Google Sues Alleged Chinese Phishers Over AI-Powered Fraud Ops

Google is taking a stand against scammers, suing a Telegram-based group called "Outsider Enterprise" for allegedly sending millions of AI-powered scam texts and impersonating trusted brands. The lawsuit aims to put a stop to their large-scale fraud operations.

Analyst 207
Brightly-lit sports stadium interior with scoreboard and tiered seating.

Cyber-Attacks Infiltrate 84% of Sports Organizations

Cyber-attacks have hit a staggering 84% of sports organizations in the past year, with over half of those being targeted multiple times - a worrying trend in an industry where timing and spectacle are everything. This alarming statistic highlights the vulnerability of professional sports teams, venues, and event bodies to cyber threats.

Analyst 207
Law enforcement officers conduct a daytime operation with a blurred emblem in the background.

INTERPOL Disrupts Sniper Dz Phishing Platform in Global Operation

In a major global crackdown, INTERPOL dismantled the notorious Sniper Dz phishing platform, a hub for cybercriminals to buy and use ready-made phishing kits, in a coordinated effort that resulted in 201 arrests across 13 countries. The operation, dubbed Operation Ramz, dealt a significant blow to the phishing-as-a-service industry.

Analyst 207
Law enforcement officers surround seized luxury vehicles in a daylight scene.

Europol Disrupts Major Crypto Laundering Service Linked to Ransomware Gangs

Europol's operation has cut off a major crypto laundering service linked to ransomware gangs, freezing hundreds of millions in illicit profits and disrupting a key financial pipeline used by criminals. The crackdown seized over €86,000 in cash, froze €692,000 in cryptocurrency, and took down 25 domains and 30 servers.

Analyst 207
University campus scene with administrative building, people walking, and laptop on a table.

ShinyHunters Exploits Oracle PeopleSoft Vulnerability in Education Sector Attacks

ShinyHunters hackers have exploited a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, to launch targeted attacks on US organizations, particularly in the higher education sector. The attacks, which involved data theft and extortion, hit a whopping 68% of US higher education institutions.

Analyst 207