🟠 HIGH · OT/ICS & Critical National Infrastructure
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek .
SecurityWeek
Read →
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek .
SecurityWeek
Read →
SecurityWeek
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out.
🟡 NOTABLE · Ransomware
[DRAGONFORCE] – Ransomware Victim: RUS Industrial
Verification alert Listings attributed to DRAGONFORCE have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issu…
RedPacket Ransomware
Read →
[DRAGONFORCE] – Ransomware Victim: RUS Industrial
Verification alert Listings attributed to DRAGONFORCE have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issu…
RedPacket Ransomware
Read →
RedPacket Security
[DRAGONFORCE] - Ransomware Victim: RUS Industrial - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
🟡 NOTABLE · Ransomware
[DRAGONFORCE] – Ransomware Victim: www[.]mbmlawsc[.]com
Verification alert Listings attributed to DRAGONFORCE have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issu…
RedPacket Ransomware
Read →
[DRAGONFORCE] – Ransomware Victim: www[.]mbmlawsc[.]com
Verification alert Listings attributed to DRAGONFORCE have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issu…
RedPacket Ransomware
Read →
RedPacket Security
[DRAGONFORCE] - Ransomware Victim: www[.]mbmlawsc[.]com - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
🟠 HIGH · Malware & Botnets
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box
The Hacker News
Read →
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box
The Hacker News
Read →
🟠 HIGH · Data Breaches
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek .
SecurityWeek
Read →
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek .
SecurityWeek
Read →
SecurityWeek
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records.
🟡 NOTABLE · Data Breaches
Consumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data Breach
Lee Yong-seong reports: The Consumer Dispute Settlement Committee has decided that Coupang must compensate affected consumers 100,000 won [about $70 USD] in cash or 100,000 won in Coupang Cash per person over a large-scale personal data breach, the committee said on the 31st. … The case began on December 8 last year, when 50 consumers... Source
DataBreaches.net
Read →
Consumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data Breach
Lee Yong-seong reports: The Consumer Dispute Settlement Committee has decided that Coupang must compensate affected consumers 100,000 won [about $70 USD] in cash or 100,000 won in Coupang Cash per person over a large-scale personal data breach, the committee said on the 31st. … The case began on December 8 last year, when 50 consumers... Source
DataBreaches.net
Read →
🟡 NOTABLE · AI & Emerging Tech Security
How Status Labs Helps Brands Get Cited in ChatGPT: The Data Behind AI Search Visibility
Disclosure: This article was created in collaboration with Status Labs.
HackRead
Read →
How Status Labs Helps Brands Get Cited in ChatGPT: The Data Behind AI Search Visibility
Disclosure: This article was created in collaboration with Status Labs.
HackRead
Read →
Hackread
How Status Labs Helps Brands Get Cited in ChatGPT: The Data Behind AI Search Visibility
See how Status Labs uses citation data, content structure, SEO signals, and GEO tactics to help brands gain visibility and citations across ChatGPT search results.
🟡 NOTABLE · AI & Emerging Tech Security
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non…
Schneier on Security
Read →
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non…
Schneier on Security
Read →
Schneier on Security
Anthropic's Opus 5 Is Better at Resisting Prompt Injection - Schneier on Security
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos…
🟡 NOTABLE · Threat Intelligence & APTs
Cyber Command plans Silicon Valley office to drive innovation
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
The Record
Read →
Cyber Command plans Silicon Valley office to drive innovation
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
The Record
Read →
therecord.media
Cyber Command plans Silicon Valley office to drive innovation
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
🟠 HIGH · Cybercrime & Dark Web
Weaponizing Exposed Data
Lab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is published or sold — removing the “weaponization tax” and turning breaches into searchable, tranched and targetable asset…
DataBreaches.net
Read →
Weaponizing Exposed Data
Lab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is published or sold — removing the “weaponization tax” and turning breaches into searchable, tranched and targetable asset…
DataBreaches.net
Read →
🟡 NOTABLE · Ransomware
Ransomware in Italy: RedACT report sheds light on an evolving threat environment
SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the co…
DataBreaches.net
Read →
Ransomware in Italy: RedACT report sheds light on an evolving threat environment
SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the co…
DataBreaches.net
Read →
🟡 NOTABLE · Policy & Regulation
RESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the world
From the Thomson Reuters Foundation, a welcome email describes the situation in South Africa and then turns to global support: I’m getting in touch to share some new reports and resources to support media freedom work in East and Southern Africa. Journalists who hold power to account are increasingly being targeted through “lawfare” tactics that silence, intimidate and financially... Source
DataBreaches.net
Read →
RESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the world
From the Thomson Reuters Foundation, a welcome email describes the situation in South Africa and then turns to global support: I’m getting in touch to share some new reports and resources to support media freedom work in East and Southern Africa. Journalists who hold power to account are increasingly being targeted through “lawfare” tactics that silence, intimidate and financially... Source
DataBreaches.net
Read →
🟠 HIGH · OT/ICS & Critical National Infrastructure
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
The Record
Read →
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
The Record
Read →
therecord.media
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
🟠 HIGH · Malware & Botnets
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
The Hacker News
Read →
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
The Hacker News
Read →
🟡 NOTABLE · Application & Supply Chain Security
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
Dark Reading
Read →
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
Dark Reading
Read →
Dark Reading
CISA Issues New SBOM Guidance. Did They Get It Right?
A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
🟠 HIGH · Nation-State & Espionage
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,
The Hacker News
Read →
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,
The Hacker News
Read →
🟠 HIGH · Vulnerabilities & CVEs
Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
HackRead
Read →
Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
HackRead
Read →
Hackread
Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
🟡 NOTABLE · OT/ICS & Critical National Infrastructure
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.” Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The Wh…
CyberScoop
Read →
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.” Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The Wh…
CyberScoop
Read →
CyberScoop
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
Trump blamed Minnesota for recent water cyberattacks, rejecting U.S. intelligence attributing the strikes to Iran. Experts and Gov. Tim Walz pushed back.
🟡 NOTABLE · Research & Analysis
Friday Squid Blogging: Squid Helps Discover New Marine Species
The Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do …
Schneier on Security
Read →
Friday Squid Blogging: Squid Helps Discover New Marine Species
The Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do …
Schneier on Security
Read →
Schneier on Security
Friday Squid Blogging: Squid Helps Discover New Marine Species - Schneier on Security
The Squid is a new scientific machine: One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up…
🟠 HIGH · Malware & Botnets
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
In this article The CaptiveCrunch campaign Storm-2945 and Midnight Blizzard CaptiveCrunch tradecraft and tooling How to protect against CaptiveCrunch activity Microsoft Defender detections and hunting guidance Indicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipu…
Microsoft Security Blog
Read →
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
In this article The CaptiveCrunch campaign Storm-2945 and Midnight Blizzard CaptiveCrunch tradecraft and tooling How to protect against CaptiveCrunch activity Microsoft Defender detections and hunting guidance Indicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipu…
Microsoft Security Blog
Read →
Microsoft News
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in…