theregister

Qantas reveals data theft impacting six million customers

Australian airline Qantas detected a cyberattack involving a third-party platform used by its contact center. The breach, publicly disclosed on July 2, 2025, potentially exposed personal data of up to six million customers.

Seven months for IT worker who trashed his work network

A British IT worker has been sentenced to over seven months in prison after launching a retaliatory cyberattack against his employer’s network. Within hours of suspension, he began altering login names and passwords, disrupting internal operations.

Home Office anti-encryption site pushes payday loan scheme

A UK government website originally created for the Home Office’s 2022 “No Place to Hide” anti-encryption campaign has been hijacked to promote a payday loan scheme. The campaign was initially expected to target Facebook Messenger.

Qilin’s 'on-call lawyer' capability is fooling no one

Qilin introduced a controversial new feature in its affiliate panel—a "Call lawyer" button. This feature is designed to provide affiliates with access to legal experts who can assist in ransom negotiations by advising on legal implications.

Freedman HealthCare targeted by cyber extortionists

A cyber extortion group known as World Leaks has claimed responsibility for a significant data breach at Freedman HealthCare. The attackers allege they have exfiltrated 52.4 GB of sensitive data comprising 42,204 files.

Cyberattack on NHS Professionals Leads to Theft of Active Directory Database and Major Security Failures

In May 2024, cybercriminals breached NHS Professionals (NHSP), stealing its AD database. The attackers gained domain admin access and exfiltrated sensitive data, exposing critical security gaps.

Lee Enterprises cyberattack compromised 40K people’s data

Lee Enterprises, a prominent U.S.-based regional newspaper publisher, has confirmed a significant cybersecurity incident involving the unauthorized access and exfiltration of sensitive personal data belonging to approximately 40,000 individuals.

Play Ransomware Exploits CVE-2024-57727 in SimpleHelp for Double-Extortion Attacks

The Play ransomware group has adopted new tactics, including exploiting a critical vulnerability in SimpleHelp (CVE-2024-57727), and continues to evolve its methods to evade detection and maximize impact.

Scattered Spider snared financial orgs before retail

A recent wave of cyberattacks attributed to the threat actor Scattered Spider has targeted financial services and retail organizations across the United Kingdom and the United States.

OpenPGP.js bug enables encrypted message spoofing

A high-severity vulnerability (CVE-2025-47934) has been discovered in OpenPGP.js, a JavaScript implementation of the OpenPGP protocol. This flaw allows attackers to spoof both signed and signed-and-encrypted messages.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags