Security News > 2025

APT41 malware abuses Google Calendar for stealthy C2 communication
2025-05-28 22:04

The Chinese APT41 hacking group uses a new malware named 'ToughProgress' that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service. [...]

New PumaBot botnet brute forces SSH credentials to breach devices
2025-05-28 19:59

A newly discovered Go-based Linux botnet malware named PumaBot is brute-forcing SSH credentials on embedded IoT devices to deploy malicious payloads. [...]

Attack on LexisNexis Risk Solutions exposes data on 300k +
2025-05-28 18:35

Data analytics and risk management biz says software dev platform breached, not itself LexisNexis Risk Solutions (LNRS) is the latest big-name organization to disclose a serious cyberattack...

Interlock ransomware gang deploys new NodeSnake RAT on universities
2025-05-28 18:14

The Interlock ransomware gang is deploying a previously undocumented remote access trojan (RAT) named NodeSnake against educational institutes for persistent access to corporate networks. [...]

Iranian Hacker Pleads Guilty in $19 Million Robbinhood Ransomware Attack on Baltimore
2025-05-28 17:20

An Iranian national has pleaded guilty in the U.S. over his involvement in an international ransomware and extortion scheme involving the Robbinhood ransomware. Sina Gholinejad (aka Sina Ghaaf),...

Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
2025-05-28 16:44

Over 9,000 ASUS routers are compromised by a novel botnet dubbed "AyySSHush" that was also observed targeting SOHO routers from Cisco, D-Link, and Linksys. [...]

Dark Partners cybercrime gang fuels large-scale crypto heists
2025-05-28 16:39

A sprawling network of fake AI, VPN, and crypto software download sites is being used by the "Dark Partner" threat actors to conduct a crypto theft attacks worldwide. [...]

Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack
2025-05-28 16:01

The Czech Republic on Wednesday formally accused a threat actor associated with the People's Republic of China (PRC) of targeting its Ministry of Foreign Affairs. In a public statement, the...

Czechia blames China for Ministry of Foreign Affairs cyberattack
2025-05-28 14:39

The Czech Republic says the Chinese-backed APT31 hacking group was behind cyberattacks targeting the country's Ministry of Foreign Affairs and critical infrastructure organizations. [...]

Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File
2025-05-28 13:41

Cybersecurity researchers have discovered a security flaw in Microsoft's OneDrive File Picker that, if successfully exploited, could allow websites to access a user's entire cloud storage content,...