Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical giant Amgen has announced a significant data breach that exposes sensitive information, including patient health records and proprietary corporate data. The breach occurred in multiple cloud systems operated by third-party service providers, with threat actors successfully exfiltrating large volumes of data. Amgen, a California-based biotechnology company, develops and manufactures medicines for serious illnesses such … Read more

CISA warns of cyberattacks disrupting U.S. water utilities

Cyberattacks on US Water Utilities Expose Vulnerabilities in Critical Infrastructure The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a dire warning about a surge in cyberattacks targeting water and wastewater systems across the country. Hackers have already disrupted more than 30 community water systems in Minnesota, leaving thousands of people without access to … Read more

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Cybersecurity Experts Sound Alarm as Autonomous AI-Driven Attacks Emerge A sophisticated threat actor has been using a cutting-edge artificial intelligence (AI) model called DeepSeek and an open-source agent called Hermes to launch autonomous cyberattacks on exposed servers. The attacks, which were discovered by Palo Alto Networks’ Unit 42 researchers, demonstrate the alarming capabilities of AI-driven … Read more

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

A sophisticated malware campaign targeting a law firm has been uncovered, with hackers using an advanced technique called Matryoshka nesting to deliver a stealthy backdoor into compromised systems. The attack, attributed to the HollowFrame Loader group, raises concerns about the increasing sophistication of cyber threats and the potential for devastating breaches. At its core, this … Read more

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A sophisticated cyber espionage campaign targeting Central Asian governments has been uncovered, with suspected Chinese-speaking hackers employing a pair of custom-built malware tools known as OctLurk and SilkLurk. The attacks have compromised several high-profile targets in the region, sparking concerns about the extent to which these nations’ sensitive information may be at risk. The use … Read more

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor has been using a sophisticated AI-powered attack framework to autonomously target vulnerable servers with limited human involvement. The campaign, discovered by Palo Alto Networks’ Unit 42 researchers, utilizes the DeepSeek AI model and the open-source Hermes Agent to identify, evaluate, and attack exposed systems. The activity was uncovered after the Hermes … Read more

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

A Wave of Malware-Harboring Android TV Boxes is Hijacking Home Broadband Connections, Turning Devices into Proxies A disturbing trend has emerged in the cybersecurity landscape, where cheap Android TV boxes are being repurposed as malware-laden devices that pose as smartphones and turn owners’ home broadband connections into unwitting proxies. These malicious devices are slipping through … Read more

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

A sophisticated spear-phishing attack has compromised a law firm, with hackers deploying a custom backdoor known as Matryoshka through a previously unknown loader called HollowFrame. The breach highlights the evolving threat landscape and the need for organizations to stay vigilant against AI-powered attacks. The attackers targeted a law firm, exploiting human vulnerabilities in their employees … Read more