cyberscoop

Nigerian accused of hacking tax preparation businesses extradited to US

A Nigerian national, Chukwuemeka Victor Amachukwu, was extradited from France to the US to face charges related to a multi-year cyber-enabled fraud campaign. The scheme involved spearphishing attacks, identity theft, and fraudulent filings.

China accuses US of exploiting Microsoft zero-day in cyberattack

China has accused U.S. intelligence agencies of conducting cyberattacks on two Chinese military enterprises, including the exploitation of a Microsoft Exchange zero-day vulnerability.

Feds still trying to crack Volt Typhoon hackers’ intentions, goals

Federal cybersecurity officials are continuing to assess the strategic threat posed by the Chinese state-sponsored threat actor Volt Typhoon, which has infiltrated U.S. critical infrastructure networks, including systems on the island of Guam.

FBI alerts tie together threats of cybercrime, physical violence from The Com

The FBI has issued a series of public service announcements (PSAs) warning about “The Com,” a rapidly growing and decentralized cybercriminal network composed primarily of minors and young adults aged 11 to 25.

Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups

Two critical zero-day vulnerabilities in Microsoft SharePoint—CVE-2025-53770 and CVE-2025-53771—are being actively exploited by China-linked threat actors Linen Typhoon, Violet Typhoon, and Storm-2603.

After website hack, Arizona election officials unload on Trump’s CISA

Arizona election officials reported a cyberattack on the state’s online candidate portal, where attacker(s) replaced candidate photos with images of the late Iranian Ayatollah Ruhollah Khomeini.

Ryuk ransomware operator extradited to US, faces five years in federal prison

Karen Serobovich Vardanyan, a 33-year-old Armenian national, has been extradited to the United States and charged for his alleged involvement in Ryuk ransomware attacks that occurred between March 2019 and September 2020.

Why skipping security prompting on Grok’s newest model is a huge mistake

Researchers identified critical vulnerabilities in Grok 4, particularly when deployed without system-level security prompting. The model was found to be highly susceptible to prompt injection attacks and capable of generating harmful content.

Treasury slaps sanctions on people, companies tied to North Korean IT worker schemes

The U.S. Department of the Treasury has imposed sanctions on individuals and entities involved in a North Korean IT worker scheme designed to covertly fund DPRK weapons of mass destruction and ballistic missile programs.

China-linked attacker hit France’s critical infrastructure via trio of Ivanti zero-days last year

A China-linked threat actor, UNC5174, exploited three Ivanti CSA zero-days (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) to target French critical infrastructure sectors from September to November 2024.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags