Cybersecurity News
Filters
Filtered by tag: cyber security × Clear
New Windows malware lays dormant until a custom command activates it like a sleeper agent
SLEEPWALKER is a newly discovered Windows malware implant that contains no malicious code, instead lying dormant until receiving a specially crafted network signal. Disguised as ESET's Management Agent, it evades security software entirely. Once activated, it can schedule tasks, communicate with remote systems, and execute code. Researcher Dominik Reichel believes it's likely a nation-state tool targeting specific victims, though no active campaigns or confirmed victims have been identified.
Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in
The Premier League must now comply with the UK's Network and Information Systems (NIS) regulations, which have been expanded to cover major sports organisations due to their large audiences and significant revenue. Clubs face fines of up to £17 million for failing to meet required cybersecurity standards. Experts say teams must improve incident response planning, staff training, and protection of operational systems to comply.
Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring
Around 2,000 hacked WordPress sites were used as infrastructure for a global cybercrime operation. The compromised sites served multiple roles: delivering malware to victims, acting as command-and-control servers for infected devices, and storing stolen data. Security experts warn the scheme exploited the sites' legitimacy to avoid detection, highlighting risks for website owners who neglect security updates.
Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams
Cybercriminals are buying expired domains at scale — around 65,000 change hands daily — to exploit the inherited trust and search rankings of formerly legitimate sites. One criminal group is estimated to have spent $7 million acquiring these domains to distribute malware and run scams, raising concerns about how domain expiration creates persistent security vulnerabilities.
Target may have suffered another damaging data leak as hackers claim 8.6GB haul
Hackers claim to have stolen 8.6GB of data from Target, potentially exposing customer and employee information. The threat actor posted the alleged haul online, though their credibility is uncertain due to a history of dubious claims. Target has not confirmed a breach. Cybersecurity researchers are investigating, urging caution given the source's track record of exaggerating or fabricating leaks.
Security experts targeted by fake crypto conference in scam to hand over details
Cybersecurity researchers are being targeted by a scam involving a fake cryptocurrency conference. Attackers invite professionals to speak or attend, then direct them to a fraudulent website that delivers information-stealing malware, including AMOS. The scheme exploits the credibility of conference invitations to trick even security-savvy victims into compromising their own systems.
Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale — “active threat” currently hitting energy, water and agricultural industries
Hackers are using AI-generated malware to attack US critical infrastructure at an unprecedented scale, targeting energy, water, and agricultural sectors. The ongoing campaign exploits internet-facing Siemens S7 Series programmable logic controllers to identify targets. Officials describe it as an active threat, with attackers demonstrating evolved capabilities attributed to AI-assisted tools.
Scammers pose as ransomware recovery agents, but just go on to steal more from victims
Cybercriminals are posing as ransomware recovery specialists to defraud victims twice. Groups like "Ransom Busters" pose as legitimate recovery firms, approach ransomware victims, and pocket fees without delivering results. In reality, they are ransomware affiliates exploiting desperate victims. Experts warn organizations to thoroughly vet any recovery service before paying, as the fake recovery industry is growing alongside ransomware itself.
Healthtech firm CareCloud reveals March 2026 data breach impacted 3.7 million patients
Matched: health
Healthcare technology company CareCloud has disclosed a data breach that occurred in March 2026, affecting approximately 3.7 million patients. The company is notifying those impacted, though it has not revealed what specific types of patient information were compromised in the incident.
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
A facial recognition database belonging to ClarityCheck, a reverse image search and identity verification service, was left exposed, leaking over 9 million images. The breach was discovered by security researchers who notified the company, which subsequently secured the database. The incident raises serious privacy concerns given the sensitive biometric nature of the exposed data.
Experts manage to hack Microsoft Copilot by continually asking it questions about itself
Researchers discovered they could manipulate Microsoft Copilot by persistently questioning it about its own nature and system instructions. Through repeated probing, the AI revealed internal configurations it was meant to keep hidden. The findings highlight concerns that AI assistants can be socially engineered into bypassing safeguards, raising questions about whether current security measures are sufficient for enterprise deployment.
Microsoft smothers malware by tracking behavior instead of blocking domains
Microsoft has shifted its malware defense strategy from blocking malicious domains to tracking behavioral patterns. Because attackers can rapidly automate new domains to replace blocked ones, domain-blocking proves ineffective. By monitoring how malware behaves rather than where it connects, Microsoft aims to identify and neutralize threats more reliably, staying ahead of attackers who exploit the limitations of domain-based defenses.
Bluesky reveals recent outage was caused by major DDoS attack
Bluesky experienced a significant outage caused by a distributed denial-of-service (DDoS) attack, the company confirmed. The attack overwhelmed its systems, disrupting access for users. Iranian state-backed threat actors claimed responsibility, though Bluesky has not verified that claim. The platform has since restored service and is working to strengthen its defenses against future attacks.
ASIC warns scammers are using AI to create deepfake investment scam networks
Matched: Australia
Australia's financial regulator ASIC has warned that scammers are using AI to build networks of fake investment websites, making online searches an unreliable verification method. The deepfake sites mimic legitimate businesses and can include fabricated celebrity endorsements. ASIC urged Australians to independently verify investment opportunities through official registers rather than relying on search results.
Loan company breach sees nearly 750,000 users have financial info, SSNs leaked
Heights Finance disclosed a data breach affecting nearly 750,000 customers after attackers compromised a cloud account. Stolen data includes Social Security numbers, bank account details, and other sensitive financial information. The loan company is notifying affected individuals and has urged them to monitor their accounts for suspicious activity.
Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen
A hacker calling themselves "Hatman" has allegedly published millions of records stolen from companies including McDonald's and Vodafone, with the data appearing to originate from Microsoft Azure systems. Affected companies dispute the severity, saying the data is outdated and denying any breach of their own systems. The origin and full scope of the leak remain unclear.
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center has disclosed a data breach affecting customer information, stemming from a cyberattack on logistics partner CEVA Logistics. As a result, some orders have been cancelled or delayed. The incident is part of a broader supply chain attack targeting CEVA Logistics, with Pokémon Center among several companies affected. Customers are advised to monitor their accounts for suspicious activity.
Ransomware gang crashes own attack — with no-one to blame but themselves
Ransomware group Akira accidentally sabotaged its own attack after using a driver exploit to disable endpoint detection software — the same technique also killed their encryption tool. Researchers noted the self-inflicted failure but warned the tactic of using vulnerable drivers to bypass security is increasingly common and remains a serious threat even when, as here, it backfires on the attackers.
Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in
Proposed US legislation called the Water Cyber Shield Act would establish voluntary cybersecurity baseline standards for water utilities, with federal support and information sharing. Experts are divided: some say it's a meaningful step given the sector's fragmented, under-resourced nature, while others argue voluntary measures are insufficient given the severity of recent attacks by foreign actors on water infrastructure.
'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction
Researchers discovered a Windows vulnerability allowing attackers to disable antivirus software with minimal user interaction. Dubbed a near-universal "kill switch," the flaw could neutralize security tools across Windows systems. Microsoft addressed the issue in its April 2025 Patch Tuesday update. Additional fixes and mitigations are also available for users unable to apply the cumulative update immediately.
