< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

2719 articles · page 74 of 136

France Arrests Suspect Linked to Interior Ministry Hack

🔒 French authorities arrested a 22-year-old on December 17, 2025, in connection with a cyberattack that breached the Ministry of the Interior's internal email servers earlier in the month. The suspect, born in 2003 and previously convicted for similar offenses in 2025, faces charges of unauthorized access to an automated personal data processing system as part of an organized group, punishable by up to 10 years' imprisonment. Investigations involve the Paris cybercrime unit and OFAC, and officials said a further statement will follow after police custody.
read more →

Amazon warns of cryptomining campaign abusing AWS IAM

⚠️ Amazon's GuardDuty team is tracking an ongoing cryptomining campaign that uses compromised Identity and Access Management (IAM) credentials to abuse EC2 and ECS resources. The attacker deployed an yenik65958/secret Docker Hub image containing the SBRMiner-MULTI miner and configured large ECS tasks and auto-scaling EC2 groups to maximize mining. The actor also enabled instance termination protection to hinder remediation; Amazon has removed the malicious image, alerted affected customers, and recommends rotating compromised IAM credentials while following GuardDuty mitigation guidance.
read more →

WhatsApp device-linking abused in GhostPairing campaign

🔒 Threat actors are abusing WhatsApp's legitimate device-linking feature in a campaign named GhostPairing, tricking victims into entering pairing codes on fake verification pages. Once a code is submitted, attackers gain full access to conversations and shared media and can send messages as the victim to propagate the lure. Users should check Settings → Linked Devices for unauthorized sessions, block and report suspicious messages, and enable two-factor authentication.
read more →

Kimwolf Botnet Hijacks 1.8M Android TV Devices Worldwide

🛡️ Researchers at QiAnXin XLab disclosed a large-scale NDK-compiled botnet dubbed Kimwolf that has infected at least 1.8 million Android-based TVs, set-top boxes, and tablets across multiple countries. The infrastructure issued an estimated 1.7 billion DDoS commands over a three-day period in November 2025 and supports 13 UDP/TCP/ICMP attack methods while also offering proxy forwarding, reverse shell, and file management functions. Operators responded to repeated C2 takedowns by moving to ENS domains and deploying an EtherHiding technique that resolves C2 IPs via a smart contract.
read more →

Chinese-nexus APT UAT-9686 Targets Cisco AsyncOS Appliances

🔒 Cisco Talos identified a targeted campaign, tracked as UAT-9686, that compromises appliances running Cisco AsyncOS, including Secure Email Gateway and Secure Email and Web Manager. The actor, assessed as a Chinese-nexus APT, deployed a Python backdoor called AquaShell that decodes specially crafted HTTP POSTs and executes system shell commands after being placed in a web server file. Operators also used a Go-based reverse SSH tool (AquaTunnel), Chisel for tunneling, and a log wiper named AquaPurge. Cisco has published advisories and recommends following remediation guidance and opening cases with TAC if IOCs are observed.
read more →

Critical React2Shell Vulnerability Used in Ransomware Attack

🔴 Researchers observed the critical React2Shell vulnerability (CVE-2025-55182) being exploited to gain initial access and deploy the Weaxor ransomware in under a minute. The attacker executed an obfuscated PowerShell command to stage a Cobalt Strike beacon, disabled Windows Defender real‑time protection, and launched the encryptor. Encrypted files used the .WEAX extension while shadow copies were removed and event logs cleared to impede recovery and forensic analysis.
read more →

APT28 Targets Ukrainian UKR-net Users in Credential Theft

🔒 Recorded Future's Insikt Group observed APT28 conducting a sustained credential-phishing campaign targeting users of UKR.net between June 2024 and April 2025. The actor, tracked as APT28 or BlueDelta and assessed as affiliated with the GRU, used UKR.net-themed login pages hosted on legitimate services like Mocky and chained redirects from link shorteners and Blogger subdomains to capture passwords and 2FA codes. Phishing emails delivered PDFs that directed recipients to these pages, and the group has moved from abusing compromised routers to leveraging proxy tunneling services such as ngrok and Serveo.
read more →

ForumTroll Phishing Targets Russian Scholars via eLibrary

📚 Kaspersky reported a targeted phishing campaign linked to Operation ForumTroll observed in October 2025 that impersonated the Russian eLibrary service. Attackers used a long-aged bogus domain to send personalized emails with one-time links to ZIP archives named for each victim, which contained a .LNK that runs a PowerShell downloader. The chain fetches a staged payload that loads a final DLL, persists via COM hijacking, deploys the Tuoni C2 framework for remote access, and shows a decoy PDF to victims.
read more →

China-Linked Ink Dragon Employs ShadowPad and FINALDRAFT

🛡️ Check Point Research links a sustained espionage campaign to the China-aligned cluster known as Ink Dragon (also tracked as Jewelbug, CL-STA-0049, Earth Alux/REF7707) that has targeted government and telecommunications organisations across Europe, Asia and Africa since at least March 2023. The actor exploits exposed web applications and predictable ASP.NET machine keys to drop web shells and install a custom ShadowPad IIS Listener, turning compromised servers into resilient C2 relays. Operators deploy a modular backdoor FINALDRAFT (aka Squidoor), alongside NANOREMOTE, loaders and tooling such as VARGEIT and Cobalt Strike to enable stealthy lateral movement, credential theft and high-throughput exfiltration.
read more →

Russian APT Targets Energy and Critical Infrastructure

🔎 Amazon Threat Intelligence reports a Russian state-sponsored cyber espionage team has increasingly targeted energy providers and other critical infrastructure, operating since at least 2021. The actors have shifted toward exploiting device misconfigurations while continuing to leverage known vulnerabilities such as CVE-2022-26318, CVE-2021-26084, CVE-2023-22518 and CVE-2023-2753. Observed tradecraft includes compromise of network-edge devices hosted on AWS EC2, passive credential capture and credential-replay attacks to move laterally across victim environments. Amazon provides indicators of compromise and specific mitigation guidance, including configuration audits, isolation of management interfaces and deployment of multi-factor authentication.
read more →

LKQ Confirms Oracle E-Business Suite Data Breach with SSNs

🔒 LKQ has confirmed a cyber-attack targeting its Oracle E-Business Suite environment that exposed personal information for more than 9,070 individuals. The company reports the intrusion occurred on August 9 and was discovered on October 3, with a detailed data analysis finalised on December 1 and notifications sent on December 15. Compromised items include LKQ Employer Identification Numbers and Social Security numbers; LKQ took the EBS environment offline, engaged an external forensic firm, and is offering two years of complimentary credit monitoring and identity restoration through Cyberscout (a TransUnion company). LKQ says it has implemented additional safeguards, strengthened security monitoring, and reinforced policies and controls.
read more →

ForumTroll Targets Political Scientists with Tuoni

📧 Kaspersky researchers have uncovered a targeted campaign by the ForumTroll APT that lures political scientists with personalized plagiarism-check links impersonating the eLibrary service. The downloaded archive contained a malicious .lnk and a .Thumbs directory with images used to evade security; filenames included each victim’s full name. When executed on Windows the .lnk ran a PowerShell chain that installed the commercial red-team framework Tuoni, used COM hijacking for persistence, and displayed a decoy PDF named for the target. Kaspersky reports detections and recommends endpoint and mail-gateway protections to stop similar email-delivered threats.
read more →

European Operation Dismantles €10M Ukraine Call-Center Ring

🔍 Eurojust coordinated a cross-border operation that disrupted a Ukraine-based call-centre fraud ring alleged to have defrauded consumers of more than €10m ($11.7m). An action day on 9 December produced 72 searches in Dnipro, Ivano-Frankivsk and Kyiv, resulting in 12 arrests and 45 suspects identified. Authorities seized forged IDs, computers, phones, a polygraph machine, cash, 21 vehicles and weapons. Investigators say scammers used remote-access tools and bogus 'safe' accounts, recruiting staff from multiple countries and offering up to 7% of proceeds plus large bonuses to high earners.
read more →

Ink Dragon Uses European Government Servers as Relays

🔍 A prolific China-linked group known as Ink Dragon is exploiting misconfigured public-facing servers in European government networks to create relay nodes, Check Point reports. After probing IIS, SharePoint and other web services for configuration flaws, operators quietly harvest credentials, reuse administrator and service accounts, and move laterally using Remote Desktop to blend into normal traffic. They install backdoors and credential-stealing implants, and deploy a customized module and a new FinalDraft backdoor to maintain long-term access and obfuscate command channels.
read more →

GhostPoster campaign hides malware in 17 Firefox add‑ons

🚨 Koi Security uncovered the GhostPoster campaign that hid malicious JavaScript inside PNG logo files used by 17 Firefox add‑ons, collectively downloaded more than 50,000 times. The steganographic loader fetches secondary payloads from attacker-controlled servers only intermittently and uses long delays to avoid detection. Affected extensions — advertised as VPNs, ad blockers, translators, and utilities — have been removed from distribution.
read more →

Russian APT Shifts to Network Edge Device Misconfigurations

🔍 A Russian state-sponsored cyberespionage group has shifted to exploiting misconfigurations in network-edge devices to target energy companies and critical infrastructure. Amazon Threat Intelligence found the actor, active since at least 2021, pivoted from known CVEs to passive credential harvesting via compromised routers, VPN concentrators and management appliances. Telemetry shows overlaps with GRU-linked Sandworm and Bitdefender’s Curly COMrades, with attackers intercepting traffic to replay credentials. Amazon urges audits of edge devices, isolation of management interfaces, enforcement of MFA and monitoring for anomalous authentication.
read more →

GhostPoster: Malicious JavaScript Hidden in Firefox Add-ons

🕵️ Koi Security identified the GhostPoster campaign that hides JavaScript inside PNG logo images of malicious Firefox extensions, impacting more than 50,000 downloads. The dormant loader waits 48 hours, contacts hardcoded attacker domains and only fetches its payload about 10% of the time to evade detection. The decoded payload provides persistent, high-privilege access and enables affiliate hijacks, analytics injection, header stripping, CAPTCHA bypass and ad/click fraud. Users of flagged extensions should remove them and consider resetting critical account passwords.
read more →

Crypto-mining Campaign Targets Amazon EC2 and ECS Resources

⚠️ Amazon GuardDuty and AWS automated monitoring identified a coordinated crypto‑mining campaign beginning November 2, 2025, that used compromised IAM credentials to deploy miners on Amazon EC2 and Amazon ECS. Attackers enumerated quotas and permissions, launched large EC2 fleets and ECS Fargate tasks from a malicious Docker Hub image, and used persistence techniques such as disabling API termination and creating public Lambda URLs. GuardDuty Extended Threat Detection correlated signals to surface critical attack sequences and AWS provides IoCs and mitigation guidance including strong identity controls, CloudTrail logging, Runtime Monitoring, and remediation playbooks.
read more →

Amazon Disrupts GRU Hackers Targeting Edge Devices

🔒 Amazon Threat Intelligence disrupted active operations attributed to GRU-linked hackers who targeted customer cloud infrastructure by abusing misconfigured edge devices. The multi-year campaign, observed since 2021 and focused on Western critical infrastructure and the energy sector, shifted in 2025 from zero-day exploitation to targeting exposed management interfaces on routers, VPN gateways, and network management appliances. Amazon isolated compromised EC2 instances, shared indicators, and advised audits, credential monitoring, and AWS controls like isolating management interfaces, restricting security groups, and enabling CloudTrail, GuardDuty, and VPC Flow Logs.
read more →

Typosquatted NuGet Package Steals Stratis Wallets Silently

🔒 A malicious NuGet package named "Tracer.Fody.NLog" was published on February 26, 2020 and impersonates the legitimate Tracer.Fody maintainer to deliver a cryptocurrency wallet stealer. The embedded Tracer.Fody.dll scans the default Stratis wallet directory (%APPDATA%\StratisNode\stratis\StratisMain), reads *.wallet.json files and in-memory passwords, and exfiltrates data to 176.113.82[.]163. Socket researcher Kirill Boychenko highlighted multiple evasion tactics — a typosquatted publisher name, Cyrillic lookalikes in code, and a hidden routine inside a helper method that runs during normal execution while suppressing exceptions.
read more →