CISA warns of cyberattacks disrupting U.S. water utilities

A Growing Concern: Cyberattacks Disrupt US Water Utilities, Leaving Residents Without Access to Clean Drinking Water The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning about a significant increase in cyberattacks targeting the water and wastewater systems sector across the country. The agency’s alert comes after hackers disrupted more than 30 … Read more

Online ad firm Adform’s script compromised to steal cryptocurrency

Online Advertising Firm Adform Hit by Supply-Chain Attack, Cryptocurrency Stealers Prey on Unaware Users A sophisticated supply-chain attack has compromised online advertising firm Adform’s script, allowing hackers to steal cryptocurrency from unsuspecting users. The malicious code, embedded in Adform’s JavaScript tracking script, monitored clipboard activity and replaced legitimate wallet addresses with attacker-controlled ones, siphoning off … Read more

Arch Linux disables AUR package adoption to stop malware flood

Arch Linux has temporarily disabled package adoption from its popular Arch User Repository (AUR) after a wave of malicious takeovers left users vulnerable to malware infections. The decision, announced by contributor Robin Candau on the distribution’s mailing list, aims to mitigate the spread of malware until a solution is found. The issue stems from a … Read more

Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical giant Amgen has announced a significant data breach that exposes sensitive information, including patient health records and proprietary corporate data. The breach occurred in multiple cloud systems operated by third-party service providers, with threat actors successfully exfiltrating large volumes of data. Amgen, a California-based biotechnology company, develops and manufactures medicines for serious illnesses such … Read more

CISA warns of cyberattacks disrupting U.S. water utilities

Cyberattacks on US Water Utilities Expose Vulnerabilities in Critical Infrastructure The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a dire warning about a surge in cyberattacks targeting water and wastewater systems across the country. Hackers have already disrupted more than 30 community water systems in Minnesota, leaving thousands of people without access to … Read more

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Cybersecurity Experts Sound Alarm as Autonomous AI-Driven Attacks Emerge A sophisticated threat actor has been using a cutting-edge artificial intelligence (AI) model called DeepSeek and an open-source agent called Hermes to launch autonomous cyberattacks on exposed servers. The attacks, which were discovered by Palo Alto Networks’ Unit 42 researchers, demonstrate the alarming capabilities of AI-driven … Read more

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

A sophisticated malware campaign targeting a law firm has been uncovered, with hackers using an advanced technique called Matryoshka nesting to deliver a stealthy backdoor into compromised systems. The attack, attributed to the HollowFrame Loader group, raises concerns about the increasing sophistication of cyber threats and the potential for devastating breaches. At its core, this … Read more

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A sophisticated cyber espionage campaign targeting Central Asian governments has been uncovered, with suspected Chinese-speaking hackers employing a pair of custom-built malware tools known as OctLurk and SilkLurk. The attacks have compromised several high-profile targets in the region, sparking concerns about the extent to which these nations’ sensitive information may be at risk. The use … Read more

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

A Chinese-speaking threat actor has been using a sophisticated AI-powered attack framework to autonomously target vulnerable servers with limited human involvement. The campaign, discovered by Palo Alto Networks’ Unit 42 researchers, utilizes the DeepSeek AI model and the open-source Hermes Agent to identify, evaluate, and attack exposed systems. The activity was uncovered after the Hermes … Read more