UK Government To Underwrite £1.5 Billion loan Guarantee To Jaguar Land Rover Following Devastating Cyber-Attack post, september 29, 2025oktober 3, 2025 In an unprecedented move, the UK government has announced a £1.5 billion loan guarantee to Jaguar Land Rover (JLR) as the carmaker continues to grapple with the aftermath of a crippling cyber-attack that has brought its UK production lines to a standstill for nearly a month. The loan from a… Continue Reading
Sophisticated Campaign Targets Microsoft Teams Users With Oyster Malware post, september 28, 2025oktober 3, 2025 Cybersecurity researchers have uncovered a cyberattack method that illustrates the growing sophistication of modern malvertising campaigns. This new wave of attacks sees threat actors leverage SEO poisoning techniques and search engine advertisements to lure unsuspecting users into downloading fake Microsoft Teams installers. These deceptive downloads ultimately infect Windows systems with… Continue Reading
CISA Releases Advisory on Lessons Learned from an Incident Response Engagement post, september 23, 2025oktober 3, 2025 Today, CISA released a cybersecurity advisory detailing lessons learned from an incident response engagement following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response tool. This advisory, CISA Shares Lessons Learned from an Incident Response Engagement, highlights takeaways that illuminate the urgent… Continue Reading
Critical SolarWinds Web Help Desk Vulnerability Enables Privilege Escalation post, september 23, 2025september 24, 2025 SolarWinds has issued an urgent security advisory regarding a critical remote code execution (RCE) vulnerability in its Web Help Desk (WHD) platform, warning customers of an actively exploitable flaw that could allow unauthenticated attackers to gain complete control over affected systems. The vulnerability, CVE-2025-26399, has been assigned a CVSS severity… Continue Reading
Widespread Supply Chain Compromise Impacting npm Ecosystem post, september 23, 2025september 24, 2025 CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world’s largest JavaScript registry, npmjs.com. A self-replicating worm—publicly known as “Shai-Hulud”—has compromised over 500 packages.[i] After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive… Continue Reading
Major Cyberattack Disrupts Heathrow & Other European Airports post, september 20, 2025september 22, 2025 Air travel across several major European hubs has been severely disrupted after what is being described as a cyber-attack on a key service provider responsible for check-in and boarding systems. The incident, which has impacted airports including London’s Heathrow, Brussels Airport, and Berlin Brandenburg Airport, has led to widespread delays,… Continue Reading
Jaguar Land Rover extends shutdown after cyberattack by another week post, september 16, 2025april 29, 2026 Jaguar Land Rover (JLR) announced today that it will extend the production shutdown for another week, following a devastating cyberattack that impacted its systems at the end of August. JRL is a standalone entity under Tata Motors India, following its acquisition from Ford in 2008. JLR employs approximately 39,000 people,… Continue Reading
Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs post, september 15, 2025september 18, 2025 The China-aligned threat actor known as Mustang Panda has been observed using an updated version of a backdoor called TONESHELL and a previously undocumented USB worm called SnakeDisk. “The worm only executes on devices with Thailand-based IP addresses and drops the Yokai backdoor,” IBM X-Force researchers Golo Mühr and Joshua Chung said in an analysis published… Continue Reading
Luxury Fashion Giants Gucci, Balenciaga & Alexander McQueen Hacked post, september 15, 2025september 18, 2025 Luxury fashion giants Gucci, Balenciaga, and Alexander McQueen have become the latest high-profile victims in an ongoing wave of cybercrime targeting global brands. Cybercriminals have stolen the personal data of potentially millions of customers worldwide, demanding a ransom from the brands’ parent company, Kering, in exchange for not releasing the… Continue Reading
Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign post, september 6, 2025september 8, 2025 A threat actor possibly of Russian origin has been attributed to a new set of attacks targeting the energy sector in Kazakhstan. The activity, codenamed Operation BarrelFire, is tied to a new threat group tracked by Seqrite Labs as Noisy Bear. The threat actor has been active since at least… Continue Reading