Cybersecurity News
Filters
Filtered by tag: security × Clear
New malware targets Microsoft Teams users by posing as your company's IT helpdesk
A new backdoor malware called SynkLoader is targeting Microsoft Teams users via fake IT helpdesk messages urging victims to install a malicious "PowerShell Cleaner" hosted on Azure. Key modules include PhishLocker, which displays a fake Windows login screen to steal passwords, and Interactive Shell, enabling full remote control. Organizations are advised to treat unsolicited Teams messages with suspicion and verify requests directly with IT.
Researchers Uncover Thousands of Leaked AWS Keys
Truffle Security researchers discovered more than 9,000 active, publicly exposed AWS key pairs on GitHub. The leaked credentials, embedded in public repositories, could allow attackers to access cloud resources and sensitive data. Many keys remained valid despite being public. The findings highlight ongoing risks from developers accidentally committing credentials to code repositories without proper secrets management practices.
Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring
Around 2,000 hacked WordPress sites were used as infrastructure for a global cybercrime operation. The compromised sites served multiple roles: delivering malware to victims, acting as command-and-control servers for infected devices, and storing stolen data. Security experts warn the scheme exploited the sites' legitimacy to avoid detection, highlighting risks for website owners who neglect security updates.
Experts warn expired credit cards can be brought back from the dead to make contactless payments
Researchers have found that expired credit cards can still be used for contactless payments, with one successfully used to buy $100 worth of groceries. The vulnerability exists because some payment terminals fail to properly verify expiration dates. Experts warn consumers to properly destroy old cards and urge banks and retailers to strengthen their verification processes.
Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams
Cybercriminals are buying expired domains at scale — around 65,000 change hands daily — to exploit the inherited trust and search rankings of formerly legitimate sites. One criminal group is estimated to have spent $7 million acquiring these domains to distribute malware and run scams, raising concerns about how domain expiration creates persistent security vulnerabilities.
Target may have suffered another damaging data leak as hackers claim 8.6GB haul
Hackers claim to have stolen 8.6GB of data from Target, potentially exposing customer and employee information. The threat actor posted the alleged haul online, though their credibility is uncertain due to a history of dubious claims. Target has not confirmed a breach. Cybersecurity researchers are investigating, urging caution given the source's track record of exaggerating or fabricating leaks.
Security experts targeted by fake crypto conference in scam to hand over details
Cybersecurity researchers are being targeted by a scam involving a fake cryptocurrency conference. Attackers invite professionals to speak or attend, then direct them to a fraudulent website that delivers information-stealing malware, including AMOS. The scheme exploits the credibility of conference invitations to trick even security-savvy victims into compromising their own systems.
Scammers pose as ransomware recovery agents, but just go on to steal more from victims
Cybercriminals are posing as ransomware recovery specialists to defraud victims twice. Groups like "Ransom Busters" pose as legitimate recovery firms, approach ransomware victims, and pocket fees without delivering results. In reality, they are ransomware affiliates exploiting desperate victims. Experts warn organizations to thoroughly vet any recovery service before paying, as the fake recovery industry is growing alongside ransomware itself.
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
A facial recognition database belonging to ClarityCheck, a reverse image search and identity verification service, was left exposed, leaking over 9 million images. The breach was discovered by security researchers who notified the company, which subsequently secured the database. The incident raises serious privacy concerns given the sensitive biometric nature of the exposed data.
Experts manage to hack Microsoft Copilot by continually asking it questions about itself
Researchers discovered they could manipulate Microsoft Copilot by persistently questioning it about its own nature and system instructions. Through repeated probing, the AI revealed internal configurations it was meant to keep hidden. The findings highlight concerns that AI assistants can be socially engineered into bypassing safeguards, raising questions about whether current security measures are sufficient for enterprise deployment.
Microsoft smothers malware by tracking behavior instead of blocking domains
Microsoft has shifted its malware defense strategy from blocking malicious domains to tracking behavioral patterns. Because attackers can rapidly automate new domains to replace blocked ones, domain-blocking proves ineffective. By monitoring how malware behaves rather than where it connects, Microsoft aims to identify and neutralize threats more reliably, staying ahead of attackers who exploit the limitations of domain-based defenses.
'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers
Researchers warn that "Proactive SIM" cards can exploit a decades-old telecom standard to execute commands on host devices without user interaction. The vulnerability affects smartphones, IoT devices, and EV chargers. Because the SIM sits inside the device and communicates directly with its processor, a compromised or malicious card can run code invisibly, and researchers say discovered attacks likely represent only a fraction of what's possible.
Loan company breach sees nearly 750,000 users have financial info, SSNs leaked
Heights Finance disclosed a data breach affecting nearly 750,000 customers after attackers compromised a cloud account. Stolen data includes Social Security numbers, bank account details, and other sensitive financial information. The loan company is notifying affected individuals and has urged them to monitor their accounts for suspicious activity.
Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen
A hacker calling themselves "Hatman" has allegedly published millions of records stolen from companies including McDonald's and Vodafone, with the data appearing to originate from Microsoft Azure systems. Affected companies dispute the severity, saying the data is outdated and denying any breach of their own systems. The origin and full scope of the leak remain unclear.
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center has disclosed a data breach affecting customer information, stemming from a cyberattack on logistics partner CEVA Logistics. As a result, some orders have been cancelled or delayed. The incident is part of a broader supply chain attack targeting CEVA Logistics, with Pokémon Center among several companies affected. Customers are advised to monitor their accounts for suspicious activity.
Ransomware gang crashes own attack — with no-one to blame but themselves
Ransomware group Akira accidentally sabotaged its own attack after using a driver exploit to disable endpoint detection software — the same technique also killed their encryption tool. Researchers noted the self-inflicted failure but warned the tactic of using vulnerable drivers to bypass security is increasingly common and remains a serious threat even when, as here, it backfires on the attackers.
The internet is becoming more stressful and unlikeable — with AI slop and data leaks to blame
AI-generated content and data breaches are making the internet increasingly unpleasant, pushing some users to disengage. Frustration with algorithmic feeds, privacy violations, and low-quality AI "slop" is growing, with a portion of users now saying they'd pay for an ad-free, algorithm-free online experience that doesn't harvest their personal data.
Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in
Proposed US legislation called the Water Cyber Shield Act would establish voluntary cybersecurity baseline standards for water utilities, with federal support and information sharing. Experts are divided: some say it's a meaningful step given the sector's fragmented, under-resourced nature, while others argue voluntary measures are insufficient given the severity of recent attacks by foreign actors on water infrastructure.
Why was there an 'evil’ Delta airlines Wi-Fi network? The experts weigh in
An Australian man was arrested after allegedly creating a fake Wi-Fi hotspot on a Delta flight, mimicking the plane's legitimate network to steal passengers' credentials. Security experts say such "evil twin" attacks are simple to execute and hard to detect. They advise avoiding logging into sensitive accounts on public Wi-Fi and using a VPN, noting airlines should better educate passengers about network safety.
'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction
Researchers discovered a Windows vulnerability allowing attackers to disable antivirus software with minimal user interaction. Dubbed a near-universal "kill switch," the flaw could neutralize security tools across Windows systems. Microsoft addressed the issue in its April 2025 Patch Tuesday update. Additional fixes and mitigations are also available for users unable to apply the cumulative update immediately.
