UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud post, juli 31, 2025augustus 18, 2025 The financially motivated threat actor known as UNC2891 has been observed targeting Automatic Teller Machine (ATM) infrastructure using a 4G-equipped Raspberry Pi as part of a covert attack. The cyber-physical attack involved the adversary leveraging their physical access to install the Raspberry Pi device and have it connected directly to the same… Continue Reading
Sterke signalen dat Russen achter hack OM zitten, zaten mogelijk weken in systeem post, juli 24, 2025juli 25, 2025 Er zijn sterke aanwijzingen dat de hack bij het Openbaar Ministerie gelinkt is aan Rusland. Dat zeggen goed ingevoerde bronnen binnen justitie tegen deze site. De hackers hebben mogelijk wekenlang toegang gehad tot computers van justitie. Continue Reading
Casus: Citrix kwetsbaarheid post, juli 23, 2025 Op deze pagina gaat het NCSC verder in op de situatie omtrent de kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway. Ook bieden we extra duiding en handelingsperspectief in het omgaan met deze kwetsbaarheden. Continue Reading
Openbaar Ministerie bevestigt te zijn gehackt, buit nog onbekend post, juli 22, 2025juli 23, 2025 Het Openbaar Ministerie is daadwerkelijk gehackt. Dat schrijft NRC, die een interne toelichting van directeur Hans Moonen van de ICT-organisatie van het Openbaar Ministerie heeft gezien. Of er informatie is gestolen, en om welke gegevens het dan gaat, is nog niet bekend. Continue Reading
PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse post, juli 21, 2025 Cybersecurity researchers have disclosed a novel attack technique that allows threat actors to bypass Fast IDentity Online (FIDO) key protections by deceiving users into approving authentication requests from spoofed company login portals. FIDO keys are hardware- or software-based authenticators designed to eliminate phishing by binding logins to specific domains using… Continue Reading
McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’ post, juli 9, 2025juli 11, 2025 If you want a job at McDonald’s today, there’s a good chance you’ll have to talk to Olivia. Olivia is not, in fact, a human being, but instead an AI chatbot that screens applicants, asks for their contact information and résumé, directs them to a personality test, and occasionally makes them “go insane”… Continue Reading
Manufacturing Security: Why Default Passwords Must Go post, juli 7, 2025 If you didn’t hear about Iranian hackers breaching US water facilities, it’s because they only managed to control a single pressure station serving 7,000 people. What made this attack noteworthy wasn’t its scale, but how easily the hackers gained access — by simply using the manufacturer’s default password “1111.” This narrow escape… Continue Reading
Mexican Cartel Hackers Exploited FBI Agent’s Phone + Public Surveillance Cameras To locate & kill Informants post, juli 3, 2025juli 4, 2025 Sinaloa drug cartel hackers managed to access the phone records of an FBI agent and used surveillance cameras in Mexico City to track down and assassinate informants, according to a new report from the U.S. Department of Justice titled: Audit of the Federal Bureau of Investigation’s Efforts to Mitigate the… Continue Reading
A Group of Young Cybercriminals Poses the ‘Most Imminent Threat’ of Cyberattacks Right Now post, juli 2, 2025juli 4, 2025 The Scattered Spider hacking group has caused chaos among retailers, insurers, and airlines in recent months. Researchers warn that its flexible structure poses challenges for defense. Empty grocery store shelves and grounded planes tend to signal a crisis, whether it’s an extreme weather event, public health crisis, or geopolitical emergency. But these scenes of… Continue Reading
GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool post, juni 28, 2025juni 30, 2025 The threat actor behind the GIFTEDCROOK malware has made significant updates to turn the malicious program from a basic browser data stealer to a potent intelligence-gathering tool. “Recent campaigns in June 2025 demonstrate GIFTEDCROOK’s enhanced ability to exfiltrate a broad range of sensitive documents from the devices of targeted individuals,… Continue Reading