KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials
Customers of the affected Japanese email services are “strongly advised” to change their email passwords
Customers of the affected Japanese email services are “strongly advised” to change their email passwords
ESET researchers participated in Operation Endgame, a coordinated effort to disrupt the Amadey botnet and Stealc infostealer malware families. The company contributed technical analysis, infrastructure tracking, and intelligence on affiliate networks involved in distributing these threats. This collaborative disruption effort targeted both the malware infrastructure and the criminal ecosystem supporting their distribution.
Iran-linked MuddyWater is disguising its cyber espionage operations by impersonating ransomware gangs, according to an NCC Group report. The state-backed group uses commercially available malware to obscure its true objectives and evade attribution. This tactic allows the threat actor to operate while misdirecting defenders and analysts toward common cybercriminal motivations.
New ReliaQuest study reveals the six ways AI is practically being used in attacks today
Public Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyber
Cloudflare has expanded OAuth access to all developers on its platform through Self-Managed OAuth, enabling broader integration capabilities within its app ecosystem. The company executed a zero-downtime migration of its core OAuth infrastructure to support this rollout, ensuring uninterrupted service during the transition.
The new executive order sets a 2030 migration deadline and establishes a powerful foundation for post-quantum resilience. We look at what it gets right, where it can go further, and our migration playbook for government and industry.
Two members of the prolific cybercrime group Scattered Spider pleaded guilty in UK court this week to charges related to an August 2024 cyberattack that disrupted Transport for London's public transit operations. The guilty pleas came on the opening day of what had been anticipated as a six-week trial, marking a significant development in the prosecution of the group's key operatives.
JFrog researchers discovered a malicious npm package masquerading as the legitimate postcss-selector-parser library, designed to deliver a multi-stage Windows remote access trojan to developers who install it. This supply chain attack demonstrates the ongoing threat of typosquatting and package impersonation in open-source ecosystems, where attackers exploit developer trust to distribute sophisticated malware.
OpenAI has expanded its Daybreak initiative with a full GPT-5.5-Cyber release designed to assist security defenders in identifying and patching software vulnerabilities. The enhanced tool aims to support defensive security teams in their remediation efforts against software flaws.
The Trump administration has issued an executive order mandating that all US federal agencies transition to post-quantum cryptography by 2031. This deadline establishes a concrete timeline for agencies to migrate away from current encryption standards vulnerable to future quantum computing threats.
Cybercriminals are exploiting the launch of GTA 6 pre-orders by creating fraudulent websites that promise early access to the game in exchange for cryptocurrency payments. These scams capitalize on high demand and consumer excitement around the title's release to deceive victims into financial loss.
Bitdefender Labs uncovered more than 55 fake-shop campaigns operating across 12 European countries between March and May 2026, impersonating major global brands including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. These counterfeit storefronts lured consumers with fraudulent deals on high-value products and World Cup-themed scams, exploiting brand recognition to steal payment information and distribute counterfeit goods. The investigation highlights a coordinated e-commerce fraud operation targeting European consumers at scale.
Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider operation, marking a significant enforcement action against the notorious threat group. The convictions demonstrate law enforcement's growing ability to identify and prosecute individual members of the distributed cybercriminal collective.
The Five Eyes Alliance has published a rare call to action for organizations facing AI threats
Trail of Bits and OpenAI launched "Patch the Planet," a landmark initiative pairing AI frontier models like GPT-5.5-Cyber with expert security engineers to systematically harden critical open-source projects, delivering 64 pull requests and 51 issues across 19 key projects in just the first week. Unlike typical AI-generated bug floods, the program goes beyond finding vulnerabilities—providing triage, patches, and long-term infrastructure improvements, with 37 patches already merged into projects like Python, RustCrypto, cURL, and PyPI. The initiative signals a fundamental shift in security work: as AI makes bug discovery trivial, the real value now lies in confirmation
ESET has identified GentleKiller, a framework distributed by the Gentlemen ransomware gang to its affiliates that specifically targets and disables endpoint detection and response (EDR) security software on victim systems. This tool represents a significant capability for ransomware operators, enabling them to neutralize defensive measures before deploying their encryption payloads.
A previously undisclosed BootROM vulnerability has been identified in Apple's A12 and A13 chips that cannot be patched due to its placement in the device's immutable firmware. The flaw is exploitable through USB, potentially allowing attackers to bypass security protections on affected devices. This unpatchable nature means the vulnerability will persist for the lifetime of devices using these chip generations.
Microsoft security researchers have attributed a supply chain attack against Mastra to North Korean threat actor Sapphire Sleet, marking another instance of state-sponsored targeting of AI-related infrastructure. The attack demonstrates continued efforts by adversaries to compromise software supply chains as a vector for broader compromise.
A breach of business intelligence platform Klue has compromised OAuth tokens that enabled threat actors to target at least four cybersecurity firms through Salesforce integration. The incident demonstrates how supply chain vulnerabilities in third-party platforms can expose security-focused organizations to unauthorized access and credential theft.