Blog
-
F5 Security Breach, Source Code Theft Linked to Chinese Hackers
The conditions are ripe for the F5 theft to spiral into further security breaches, with not just source code but inside information on undisclosed vulnerabilities that had yet to be patched exposed to the hackers. The Chinese team suspected of being behind it is an espionage-focused outfit that specializes in quietly penetrating organizations in the…
-
UK NCSC Notes Major Spike in “Nationally Significant” Cyber Incidents
The good news from the UK report is that no incidents recorded over the year rose to the level of a “national cyber emergency,” the most serious designation … However, 18 cyber incidents in the second most serious category is bad news when that number was at just six the year before and virtually did…
-
OpenAI Report Finds Foreign Adversaries Still Limited in Use of AI Tools, But Are Hacking Workarounds
More sophisticated foreign adversaries have figured out how to exploit model “grey zones” in AI tools, however, building attack tools gradually from smaller pieces that individually do not present as threats.
-
$2 Billion in 2025, $6 Billion Total Stolen Crypto for North Korean Hackers as Focus Shifts to Individuals
The majority of the $2 billion stolen by the North Korean hackers this year came from crypto exchange Bybit, which was hit for $1.46 billion in February. About 30 more recorded incidents this year make up the difference of a little over half a billion dollars, though the Elliptic researchers warn there are likely more…
-
Oracle E‑Business Suite Zero-Day Found To Be Actively Exploited by Ransomware Gang
A high-severity vulnerability in Oracle E‑Business Suite has received security patching along with a warning that it has already been exploited in the wild by ransomware threat groups.
-
Red Hat GitLab Breach Results in Sale of Data From Private Repositories
Hacking group Crimson Collective was able to breach a self-managed GitLab instance used by the Red Hat consulting division, making off with about 570 GB of compressed data. The stolen data has since been seen for sale on Telegram channels.
-
Public-Facing Amazon Storage Bucket Exposed Over 273,000 Indian Bank Transfers
Security researchers have discovered a publicly accessible Amazon S3 storage bucket that contains records of over 273,000 transfers taking place at banks in India, some of which have highly sensitive financial information in them.
-
“ForcedLeak” Vulnerability in Agentforce Platform Addressed by Salesforce
The dangerous “ForcedLeak” flaw in Salesforce’s Agentforce platform has been addressed with a patch, plugging a hole that made it possible for attackers to exfiltrate sensitive data via a prompt injection.
-
NYC Sim Farm Bust Demonstrates Major Threat to Mobile Networks
The NYC SIM farm was thought to cost only a few million dollars in total, for rented apartments in five fairly expensive areas and 300 SIM boxes running about 100,000 SIM cards. Though there is no indication the operators had plans for terrorism, this setup would have been more than sufficient to overwhelm NYC phone…
-
Over a Dozen Ransomware Groups “Call it Quits,” But Don’t Let Your Guard Down
Right in the midst of their 2025 reign of terror, the newly-united Scattered Spider and ShinyHunters ransomware groups are calling it quits. They have been joined in their retirement announcement by about a dozen other groups, including Lapsus$ and BreachForums operator InfoBroker.










