The Register

North Korean spies used Google Find Hub as remote-wipe tool

North Korea-linked threat actor KONNI has been observed abusing Google's Find My Device feature to remotely factory reset Android smartphones and tablets belonging to South Korean targets.

Backdoored ‘secure’ messaging app leads to more arrests

The operation, known as Operation Ironside, was orchestrated by the FBI and Australian Federal Police (AFP) to infiltrate and dismantle organized criminal networks globally. The AN0M operation began in 2018 following the takedown of Phantom Secure.

Docker Compose vulnerability opens door to host-level writes

Two high-severity vulnerabilities have been identified in Docker Compose and Docker Desktop for Windows, potentially allowing attackers to write arbitrary files to host systems or escalate privileges via DLL hijacking.

Cyberpunks mess with Canada's water, energy, farm systems

Hacktivists have targeted Canadian critical infrastructure systems, including water treatment facilities, energy providers, and agricultural operations. These intrusions exploited internet-accessible ICS to manipulate operational parameters

ICO fines sole trader for allegedly sending 1M spam texts

A UK-based sole trader has been fined £200,000 for orchestrating a large-scale SMS spam campaign that targeted financially vulnerable individuals. The ICO found that nearly one million unsolicited messages were sent without valid consent.

OpenAI Atlas Browser tripped up by malformed URLs

This vulnerability poses a significant risk to users of the Atlas browser, as it allows attackers to execute commands with elevated trust by bypassing standard input validation.

Iran’s MOIS-linked Ravin Academy hit by data breach

A significant data breach has impacted Ravin Academy, a cybersecurity training institution linked to Iran’s MOIS. The breach has resulted in the exposure of sensitive personal data belonging to students and associates

Google and Check Point nuke massive YouTube malware network

A sophisticated malware campaign known as the "YouTube Ghost Network" has been dismantled by Google and Check Point after distributing over 3,000 malicious videos on YouTube.

Toys R Us Canada customer data swiped, dumped online

Toys R Us Canada disclosed that attackers accessed a customer database and exfiltrated personal information including names, addresses, phone numbers, and email addresses. However, the exact number of affected individuals remains undisclosed.

Microsoft patches ASP.NET Core bug rated highly critical

Microsoft has patched a critical vulnerability (CVE-2025-55315) in ASP.NET Core's Kestrel web server, rated 9.9 on the CVSS scale. The flaw enables HTTP request smuggling, allowing attackers to bypass security mechanisms under certain conditions.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags