Third US Security Expert Admits Helping Ransomware Gang
A third cybersecurity expert admitted helping ransomware gangs, signaling a dangerous trend. Attackers now recruit certified insiders for access instead of relying on exploits.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
A third cybersecurity expert admitted helping ransomware gangs, signaling a dangerous trend. Attackers now recruit certified insiders for access instead of relying on exploits.
Bomgar RMM is facing a surge in exploitation, exposing critical supply chain risk. When MSP platforms are compromised, attackers gain access to thousands of downstream customer networks, amplifying impact across entire sectors.
Researchers discovered Windows Defender vulnerabilities allowing attackers to execute system-level code, disable monitoring, and maintain persistence by exploiting the tool's deep OS integration. This converts initial access into a durable, privileged compromise—turning the primary security tool int
Lotus, a newly discovered data-wiping malware, targeted Venezuelan energy infrastructure in purely destructive attacks aligned with geopolitical tensions—not traditional ransomware seeking financial gain.
Siemens disclosed CVE-2025-2884 in TPM 2.0 firmware affecting 23+ industrial control systems. Local attackers can exploit improper input validation to leak cryptographic data or crash systems.
CVE-2026-27668 in Siemens RUGGEDCOM allows authenticated users to escalate privileges and gain unrestricted admin access (CVSS 8.8). The network-accessible flaw affects critical infrastructure and manufacturing facilities worldwide by breaking role-based access controls.
Silex disclosed 13 critical vulnerabilities (CVSS 9.8) in device servers and management software, enabling unauthenticated remote code execution through buffer overflows and missing authentication. Multiple attack paths compound the risk.
Tyler Buchanan, a Scottish hacker (aka "Tylerb"), pleaded guilty for orchestrating Scattered Spider's phishing attacks on tech firms like Twilio and LastPass, stealing millions in cryptocurrency from US investors. His guilty plea marks a major law enforcement victory against one of the past five yea
The Gentlemen RaaS controls 1,570+ systems via proxy malware for persistent access before encryption. The discovery shows how modern ransomware gangs build multi-layered infrastructure.
A Florida-based negotiator pleaded guilty to negotiating ransoms for BlackCat, one of the world's most prolific ransomware-as-a-service operations. The case reveals how criminal enterprises rely on specialized operatives—not just coders—to extract maximum payments from victims through psychological
22 vulnerabilities in Lantronix/Silex converters expose ~20,000 industrial devices. These legacy connectivity bridges are security blind spots—rarely patched despite controlling critical systems.
IPQS demonstrates that intelligent multi-signal fraud detection can balance security and user experience. Organizations can deploy sophisticated anti-fraud controls without the high friction that blocks legitimate transactions, using strategic signal deployment throughout the customer journey.
600,000 patient records were breached in Illinois and Texas healthcare organizations, exposing personal, medical, and financial data. The incidents highlight persistent security vulnerabilities in the healthcare sector amid rising cybercriminal threats.
Progress Software released patches for critical vulnerabilities in MOVEit WAF and LoadMaster, widely used in enterprises. The flaws enable authentication bypass, code execution, and privilege escalation (CVSS 5.3–8.8).
Threat actors actively exploit critical vulnerabilities in Cisco, Kentico, and Zimbra platforms. Public proof-of-concept code drives coordinated attacks on government, financial institutions, and critical infrastructure globally.
Unsecured Perforce servers expose source code, credentials, and intellectual property to attackers across tech, gaming, and aerospace firms. This critical vulnerability is preventable with proper authentication controls.
Dozens of malicious crypto apps breached the Apple App Store, using credential harvesting and fake exchange interfaces to defraud users. The incident reveals persistent vulnerabilities in Apple's security review process despite the platform's curated marketplace reputation.
Serial-to-IP converters enable network access to legacy equipment but harbor thousands of unpatched vulnerabilities—including default credentials, buffer overflows, and authentication bypasses. Most critical infrastructure organizations lack proper inventory of these devices, creating a shadow attac
Chinese APT groups are escalating attacks on Indian banks and South Korean policymakers via phishing and malware, aiming to gather intelligence on economic systems and regional security. The campaigns demonstrate state-level coordination and reflect broader strategic competition in South Asia and Ea
CISA added a critical SD-WAN vulnerability to its exploited flaws catalog after threat actors began weaponizing it in real-world attacks. The flaw enables unauthorized network access, lateral movement into core infrastructure, data exfiltration, and persistent compromises of branch office and cloud-
Mature SOCs respond to threats faster by centralizing threat context, not through superior tools or staff. This structural advantage cuts MTTR significantly, reducing incident damage, compliance risk, and team burnout.
Ofcom is investigating Telegram for failing to prevent child sexual abuse material distribution. The inquiry reflects growing pressure on platforms to balance privacy with child safety obligations.
Google patched a critical prompt injection vulnerability in Antigravity IDE that allowed arbitrary code execution through insufficient input sanitization. The flaw exploited file-creation capabilities, potentially compromising developer systems.
NGate Android malware resurfaces in Brazil via a trojanized HandyPay app, using AI-generated code to intercept NFC payment data and steal PINs. The campaign represents a major escalation in mobile payment threats targeting Latin America, with attackers embedding malicious code into legitimate apps.