$3.6 Million Stolen in Bitcoin Depot Hack
Bitcoin Depot lost $3.6M in a cryptocurrency theft exploiting weak account security. The hack exposes systemic vulnerabilities in Bitcoin ATM networks.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Bitcoin Depot lost $3.6M in a cryptocurrency theft exploiting weak account security. The hack exposes systemic vulnerabilities in Bitcoin ATM networks.
Eurail's December 2025 breach exposed 300,000 travelers' names and passport numbers, marking another major security failure in the travel sector. The stolen identity documents pose significant risks for identity theft and fraudulent bookings.
A critical unpatched zero-day vulnerability in Adobe Reader has been under active exploitation for months. Researcher Haifei Li discovered evidence of targeted attacks using malicious PDFs.
Adobe Reader zero-day exploited since December 2025 enables remote code execution via malicious PDFs sent by email. Critical due to Reader's widespread use and users' tendency to trust PDF documents.
Cybercriminals stole $3.6 million from Bitcoin Depot through vulnerabilities in its crypto ATM network's physical and digital security. The breach exposed weaknesses in access control and fund transfer systems, highlighting growing risks in the cryptocurrency ATM sector.
Iranian hackers vow to resume cyberattacks on US targets when conditions permit. Digital warfare now integrates with traditional conflict, with state actors maintaining persistent infrastructure access.
APT28 exploits unsecured SOHO routers by hijacking DNS to redirect users to phishing pages and steal credentials. This malwareless campaign has compromised thousands of organizations globally.
Google revealed UNC6783, a financially-motivated threat group targeting Zendesk support tickets to steal credentials and system configurations. Support tickets are high-value targets because they expose sensitive technical details and access tokens that enable infrastructure compromise.
LinkedIn secretly scans users' 6,000+ browser extensions without consent to infer sensitive personal information like job-hunting status and medical conditions. This undisclosed surveillance operation reveals a significant privacy violation and raises critical questions about corporate transparency
Threat actors are encoding illicit communications in emojis—🤖 for bots, 🧰 for attack tools, 💰💰💰 for ransom—to evade security filters. The approach exploits detection systems' difficulty with Unicode characters versus traditional text-based obfuscation.
Approximately 100 Magento stores were compromised by a credit card stealer hidden in pixel-sized (1×1) SVG images, exploiting a visual blind spot that evades both security tools and manual audits. The JavaScript-based skimming code captures customer payment data while remaining effectively invisible
A critical OpenSSL vulnerability allows sensitive data leakage from encrypted connections without detection. Affecting billions of daily transactions across web servers, email, VPNs, and IoT devices, organizations must patch immediately to protect cryptographic keys and credentials.
Critical RCE in Apache ActiveMQ Classic hidden 13 years enables unauthenticated code execution. Affects all versions through 5.18.2, threatening financial services, healthcare, and government sectors.
**Summary:** New macOS malware exploits native Script Editor via ClickFix fake notifications to deploy credential-stealing malware. The attack abuses legitimate Apple tools to harvest passwords and browsing data while evading traditional security detection.
Chaos malware has shifted to exploit misconfigured cloud infrastructure, adding SOCKS proxy capabilities for covert tunneling. The evolution shows malware operators adapting to modern deployment targets.
Attackers accelerate Latin America fraud by executing account takeovers in hours before detection systems respond. This speed exploits mobile-first financial infrastructure with slower defenses.
APT28 deployed PRISMEX, a sophisticated multi-stage malware, in spear-phishing attacks against Ukraine and NATO nations using steganography and cloud-based command-and-control to evade detection. The campaign represents an escalation in state-sponsored cyber threats targeting critical infrastructure
**Masjesu is a DDoS-for-hire botnet marketed via Telegram that compromises IoT devices globally. Since 2023, it democratizes distributed attacks through low cost and accessibility, threatening consumer, enterprise, and critical infrastructure.**
Apache ActiveMQ's critical RCE vulnerability, undetected for 13 years, allows unauthenticated remote code execution. Currently exploited, it threatens countless enterprise systems worldwide.
CISA ordered federal agencies to patch a critical Ivanti EPMM vulnerability in four days due to active exploitation since January. The flaw enables unauthenticated remote code execution on mobile device management infrastructure, putting millions of managed endpoints at risk. Non-compliance threaten
Pluralsight launched SecureReady to combat the global cybersecurity skills gap of 700,000+ unfilled positions. The platform provides structured, enterprise-grade training to rapidly develop job-ready security teams while addressing the challenges of expensive external hiring and slow internal develo
Full Sail University opened an IBM Cyber Defense Range powered by AWS to provide hands-on cybersecurity training and address industry skills gaps. The facility enables students to practice threat detection, incident response, and defensive operations in realistic, safe cloud-based scenarios.
Enterprise AI GPUs surprisingly underperform at password cracking vs. consumer GPUs due to architectural mismatch—they're optimized for machine learning, not simple hashing operations. Weak passwords, not hardware cost, pose the real security threat.
A cyberattack forced a Massachusetts hospital to divert ambulances, disrupting emergency care. The incident underscores healthcare's critical vulnerability—hospitals face approximately 1.2 cyberattacks daily, making them the most-targeted sector for digital threats targeting both patient data and li