China Is Studying How to Hack and Crash Our Power Grids post, juni 19, 2025juni 23, 2025 Over the past several weeks, I’ve been conducting a large-scale bibliometric study on publicly available Chinese academic literature related to hacking and crashing Western power grids. In this article, I’m sharing the main findings of that study. EDIT (20.6.2025, 8:54 CET): All of the Chinese academic articles I examined are… Continue Reading
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware post, juni 13, 2025augustus 21, 2025 Apple has disclosed that a now-patched security flaw present in its Messages app was actively exploited in the wild to target civil society members in sophisticated cyber attacks. The vulnerability, tracked as CVE-2025-43200, was addressed on February 10, 2025, as part of iOS 18.3.1, iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS… Continue Reading
Google Cloud and Cloudflare hit by widespread service outages post, juni 12, 2025juni 13, 2025 Update June 12, 17:41 EDT: In new updates, Cloudflare said that all services have been restored and are now fully operational, while Google stated it expects “recovery to complete in less than an hour.” Update June 12, 15:29 EDT: Cloudflare says its services were impacted by Google Cloud’s outage. “This is a Google Cloud… Continue Reading
Ransomware scum disrupted utility services with SimpleHelp attacks post, juni 12, 2025juni 13, 2025 Ransomware criminals infected a utility billing software providers’ customers, and in some cases disrupted services, after exploiting unpatched versions of SimpleHelp’s remote monitoring and management (RMM) tool, according to a Thursday CISA alert. “This incident is part of a broader trend of ransomware actors exploiting unpatched versions of SimpleHelp RMM… Continue Reading
Russische hackers ontregelden maandenlang windpark Oude Maas post, juni 10, 2025juni 11, 2025 Een Russische hack bij een Duitse windturbineproducent had in 2022 ook gevolgen voor Nederlandse windmolens. Sommige stonden maandenlang stil, waaronder die van windmolenpark Oude Maas. Een reconstructie van hoe Europa’s meest gezochte criminelen een hack uitvoerden met potentiële risico’s voor de stroomvoorziening op ons continent. Hoe zit het met de… Continue Reading
Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group post, juni 9, 2025juni 10, 2025 The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025. “The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors,” SentinelOne… Continue Reading
New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack post, juni 6, 2025 A critical infrastructure entity within Ukraine was targeted by a previously unseen data wiper malware named PathWiper, according to new findings from Cisco Talos. “The attack was instrumented via a legitimate endpoint administration framework, indicating that the attackers likely had access to the administrative console, that was then used to… Continue Reading
Scattered Spider: Three things the news doesn’t tell you post, juni 3, 2025 With the recent attacks on UK retailers Marks & Spencer and Co-op, so-called Scattered Spider has been all over the media, with coverage spilling over into the mainstream news due to the severity of the disruption — currently looking like hundreds of millions in lost profits for M&S alone. This… Continue Reading
Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion post, juni 3, 2025 Microsoft and CrowdStrike have announced that they are teaming up to align their individual threat actor taxonomies by publishing a new joint threat actor mapping. “By mapping where our knowledge of these actors align, we will provide security professionals with the ability to connect insights faster and make decisions with… Continue Reading
Google patches new Chrome zero-day bug exploited in attacks post, juni 3, 2025 Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year. “Google is aware that an exploit for CVE-2025-5419 exists in the wild,” the company warned in a security advisory published on Monday. This high-severity vulnerability is caused by an out-of-bounds read and write weakness… Continue Reading