hackread

Coca-Cola, Bottling Partner Named in Separate Ransomware and Data Breach Claims

Everest has listed Coca-Cola as a victim on its dark web leak site, releasing samples of internal HR documents affecting 959 employees. These include scans of passports and visas, salary data, and other personally identifiable information (PII).

Threat Actor Selling 1.2 Billion Facebook Records, But Details Don’t Add Up

A threat actor has claimed to have scraped 1.2 billion Facebook user records by abusing an API. The data is being sold on a breach forum, but inconsistencies in the sample data and metadata raise doubts about the legitimacy of the claim.

KrebsOnSecurity Hit with 6.3 Tbps DDoS Attack via Aisuru Botnet

KrebsOnSecurity, a prominent cybersecurity blog, was recently targeted by a massive distributed denial-of-service (DDoS) attack peaking at 6.3 Tbps. The attack, attributed to the Aisuru botnet, is one of the largest recorded to date.

New Nitrogen Ransomware Targets Financial Firms in the US, UK and Canada

Nitrogen ransomware, first publicly identified in September 2024, has emerged as a significant threat targeting organizations across the finance, construction, manufacturing, and technology sectors.

PrepHero-Linked Database Exposed Data of 3M Students and Coaches

A massive data exposure incident involving PrepHero, a college recruiting platform operated by EXACT Sports, has compromised the personal information of over 3 million student-athletes, their parents, and coaches.

Legacy Login in Microsoft Entra ID Exploited to Breach Cloud Accounts

A targeted campaign exploited Microsoft Entra ID’s legacy authentication protocol BAV2ROPC, allowing attackers to bypass MFA and gain unauthorized access to admin accounts across finance, healthcare, and tech sectors.

200+ Fake Retail Sites Used in New Wave of Subscription Scams

Bitdefender discovered over 200 incredibly realistic websites offering a wide range of products, including shoes, clothing, and electronics. Customers are tricked into providing credit card information and agreeing to monthly subscriptions.

BreachForums Displays Message About Shutdown, Cites MyBB 0day Flaw

BreachForums, operated by the ShinyHunters hacker group, abruptly went offline in early April 2025. A PGP-signed message posted on April 28, 2025, revealed that a MyBB 0day vulnerability prompted the shutdown.

JokerOTP Dismantled After 28,000 Phishing Attacks, 2 Arrested

Two individuals have been arrested in a joint international operation dismantling JokerOTP, a sophisticated phishing tool used to intercept 2FA codes and steal over £7.5 million.

Planet Technology Industrial Switch Flaws Risk Full Takeover – Patch Now

Immersive Labs discovered critical vulnerabilities in Planet Technology’s network management systems and industrial switches, risking full device takeover. Immediate patching is urged to prevent exploitation.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags