Chinese State-Sponsored Threat Actors Used Anthropic’s Claude To Automate Global Cyberattacks post, november 14, 2025november 17, 2025 Anthropic has disclosed a large-scale cyber operation in which a China-aligned threat actor leveraged the Claude Code model to automate exploitation, credential harvesting, and data exfiltration across approximately 30 global targets. The incident represents one of the first documented cases in which an LLM with agentic capabilities was weaponized to… Continue Reading
Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation post, november 8, 2025november 10, 2025 Security researchers at Palo Alto Networks Unit 42 have uncovered a sophisticated espionage campaign leveraging a zero-day vulnerability in select Samsung Galaxy Android devices. The flaw, tracked as CVE‑2025‑21042 (CVSS 8.8), is an out-of-bounds write defect in the libimagecodec.quram.so image-processing library, which could allow remote code execution. According to Unit… Continue Reading
Ernst & Young (EY) Exposes 4TB Database Online – What Went Wrong? post, november 1, 2025november 3, 2025 A mistake in the cloud has exposed a vast trove of data belonging to one of the world’s largest professional-services firms. According to multiple independent cyber-security researchers, a 4-terabyte SQL Server backup file belonging to Ernst & Young (EY) was publicly accessible on the internet via Microsoft Azure Storage. While… Continue Reading
Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics post, oktober 29, 2025oktober 31, 2025 Organizations in Ukraine have been targeted by threat actors of Russian origin with an aim to siphon sensitive data and maintain persistent access to compromised networks. The activity, according to a new report from the Symantec and Carbon Black Threat Hunter Team, targeted a large business services organization for two months and… Continue Reading
Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack post, oktober 27, 2025 The ransomware group known as Qilin (aka Agenda, Gold Feather, and Water Galura) has claimed more than 40 victims every month since the start of 2025, barring January, with the number of postings on its data leak site touching a high of 100 cases in June. The development comes as the ransomware-as-a-service… Continue Reading
Hundreds of People With ‘Top Secret’ Clearance Exposed by House Democrats’ Website post, oktober 27, 2025november 3, 2025 The sensitive personal details of more than 450 people holding “top secret” US government security clearances were left exposed online, new research seen by WIRED shows. The people’s details were included in a database of more than 7,000 individuals who have applied for jobs over the last two years with Democrats… Continue Reading
Opnieuw hack bij Albert Heijn-winkels: paspoorten en beoordelingen buitgemaakt post, oktober 23, 2025oktober 24, 2025 De grootste franchisenemer van Albert Heijn, Bun, is gehackt. Onder meer paspoorten en personeelsdossiers met informatie over salaris, ziekteverzuim en werkbeoordelingen zijn bij de hack gestolen, meldt RTL Nieuws. Bun en Albert Heijn bevestigen dat er een hack heeft plaatsgevonden. Bun heeft 29 Albert Heijn-supermarkten in Nederland, waar zo’n 3500 mensen… Continue Reading
Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access post, oktober 22, 2025 Oracle has disclosed two critical vulnerabilities in its E-Business Suite’s Marketing product that could hand full control to remote attackers. Dubbed CVE-2025-53072 and CVE-2025-62481, these flaws affect the Marketing Administration component and carry a perfect storm CVSS score of 9.8, marking them as among the most severe threats disclosed this… Continue Reading
Threat Actors Allegedly Selling Monolock Ransomware on Dark Web Forums post, oktober 22, 2025 Monolock ransomware has surfaced in underground forums, with threat actors advertising version 1.0 for sale alongside stolen corporate credentials. First detected in late September, the malware exploits phishing emails containing malicious Word documents. Continue Reading
Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign post, oktober 22, 2025oktober 23, 2025 The Iranian nation-state group known as MuddyWater has been attributed to a new campaign that has leveraged a compromised email account to distribute a backdoor called Phoenix to various organizations across the Middle East and North Africa (MENA) region, including over 100 government entities. The end goal of the campaign is to… Continue Reading