Cybersecurity News
Filters
CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks
Matched: health
CISA, the FBI, and HHS have jointly issued an updated advisory warning that Medusa ransomware attackers are actively targeting enterprise networks, disabling security tools, stealing sensitive data, and encrypting entire systems. The alert urges organizations to strengthen defenses against the group, which has escalated its activity across critical sectors.
Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC
Geekom has confirmed that several of its mini-PC models shipped with malware embedded in a network driver. The malicious executable can log keystrokes, intercept data, and steal passwords. The company has acknowledged the issue but is placing responsibility on users to manually remove the malware themselves, rather than issuing an automatic fix or patch.
Loan company breach sees nearly 750,000 users have financial info, SSNs leaked
Heights Finance disclosed a data breach affecting nearly 750,000 customers after attackers compromised a cloud account. Stolen data includes Social Security numbers, bank account details, and other sensitive financial information. The loan company is notifying affected individuals and has urged them to monitor their accounts for suspicious activity.
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Researchers at Check Point identified a ransomware operation called StopAndProtect in May 2026. The campaign uses the ClickFix social-engineering technique to trick victims into running a PowerShell command, triggering a multi-stage downloader chain. Thousands of hacked WordPress sites serve as infrastructure for the operation, which researchers have now partially unmasked through analysis of its infection chain and supporting infrastructure.
Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen
A hacker calling themselves "Hatman" has allegedly published millions of records stolen from companies including McDonald's and Vodafone, with the data appearing to originate from Microsoft Azure systems. Affected companies dispute the severity, saying the data is outdated and denying any breach of their own systems. The origin and full scope of the leak remain unclear.
Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting
Matched: cryptocurrency
A cryptocurrency fraud operation called Operation ASTERIX used AI coding tools to process over 100,000 phone numbers for targeted victim selection. The scheme combined account verification, phishing emails, phone calls, and fake wallet software to identify and pursue likely cryptocurrency holders, offering researchers an unusually detailed look at a modern crypto fraud pipeline.
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center has disclosed a data breach affecting customer information, stemming from a cyberattack on logistics partner CEVA Logistics. As a result, some orders have been cancelled or delayed. The incident is part of a broader supply chain attack targeting CEVA Logistics, with Pokémon Center among several companies affected. Customers are advised to monitor their accounts for suspicious activity.
Cybersecurity needs a new KPI: it's time to measure our ability to adapt
Traditional cybersecurity metrics focus on response and recovery times, but these don't capture an organization's ability to learn and evolve after incidents. Experts argue that "adaptability" should become a core KPI — assessing how well teams update defenses, adjust processes, and apply lessons learned. Without measuring adaptation, organizations risk repeating vulnerabilities and falling behind increasingly sophisticated threats.
National infrastructure needs a new approach to cyber resilience
Public ownership of national infrastructure does not protect against cyber threats. Britain needs a new approach based on shared intelligence between public and private sectors, clearer prioritisation of risks, and better coordinated resilience planning. Structural ownership matters less than how organisations prepare, communicate and respond to attacks.
Exclusive: SIA Medical Centre confirms it is investigating cyber incident involving patient data
Matched: medical
Victorian medical centre SIA Medical Centre is investigating a ransomware attack after the Rhysida cyber extortion group claimed to have obtained thousands of patient records. The centre confirmed it is responding to a cyber incident involving patient data. Rhysida, a known ransomware group, has listed the stolen data and is threatening to release it unless a ransom is paid.
Report: AI reasoning gains fail to eliminate racial and gender bias in medical research
Matched: health, medical
Researchers at Flinders University found that advanced AI reasoning models still reproduce racial and gender stereotypes when generating fictional medical patient cases, despite improvements in reasoning capabilities. The findings raise concerns about deploying such models in healthcare settings, where biased outputs could reinforce existing disparities in medical research and patient care.
Komatsu Australia reduces reliance on Telstra-locked SIMs in security push
Matched: Australia
Komatsu Australia has moved away from depending solely on Telstra-locked SIMs, adopting a new mobile connectivity model aimed at improving security and flexibility. The shift reduces single-carrier reliance, giving the company greater control over its connectivity infrastructure. The new consumption-based approach is currently being tested as part of a broader push to strengthen its mobile security posture.
Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk
Russia faces a cybersecurity crisis as SSL certificates for major websites, including banks, email services, and government systems, expire following Western sanctions that cut off access to foreign certificate authorities. Russia's proposed fix involves installing a state-controlled root certificate, but this would grant authorities the ability to intercept encrypted traffic, raising serious surveillance concerns. Many browsers don't trust the Russian alternative.
Ransomware gang crashes own attack — with no-one to blame but themselves
Ransomware group Akira accidentally sabotaged its own attack after using a driver exploit to disable endpoint detection software — the same technique also killed their encryption tool. Researchers noted the self-inflicted failure but warned the tactic of using vulnerable drivers to bypass security is increasingly common and remains a serious threat even when, as here, it backfires on the attackers.
MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves
Apple has patched a critical vulnerability in macOS Screen Sharing that could allow attackers to gain unauthorized access to devices and use them for cryptomining. The flaw posed significant risk to affected users. MacOS users are urged to update their systems immediately to protect against potential exploitation.
17th August – Threat Intelligence Report
Colombia's Ministry of Justice suffered a ransomware attack disrupting technology infrastructure and public services tied to drug monitoring and legal processes, with officials confirming file compromise. Other notable incidents include additional breaches and cyberattacks detailed in Check Point Research's weekly Threat Intelligence Bulletin, covering top attacks, emerging vulnerabilities, and threat actor activity for the week of 17th August.
The internet is becoming more stressful and unlikeable — with AI slop and data leaks to blame
AI-generated content and data breaches are making the internet increasingly unpleasant, pushing some users to disengage. Frustration with algorithmic feeds, privacy violations, and low-quality AI "slop" is growing, with a portion of users now saying they'd pay for an ad-free, algorithm-free online experience that doesn't harvest their personal data.
Tokenmaxxing: Why AI consumption needs control
Finance teams are pushing back on unchecked AI spending, warning that token consumption — the volume of AI queries and outputs processed — is becoming a significant and poorly tracked cost. As AI adoption scales, organizations risk overspending without clear returns. Finance leaders want governance frameworks and usage controls to ensure AI investment delivers measurable value rather than runaway infrastructure bills.
Securing adoption in the era of shadow AI
Organizations face growing risks from "shadow AI" — unauthorized AI tools employees use without IT oversight. To address this, companies should establish clear AI usage policies, create approved tool inventories, and implement monitoring. Balancing restriction with enablement is key; overly rigid controls drive workarounds. Security teams should engage employees, offer sanctioned alternatives, and build governance frameworks that allow responsible AI adoption at scale.
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Matched: cryptocurrency
Attackers posing as Web3 recruiters on LinkedIn lured cryptocurrency professionals into fake job interviews, ultimately tricking Windows users into installing malware via a signed ClickOnce application. The infection deployed NeedleStealer, which harvested private keys and browser data, alongside an hVNC remote access trojan. The campaign used Calendly scheduling and technical assessments to appear legitimate.
