October 20, 2025

Microsoft pins latest GoAnywhere MFT exploitation campaign on Medusa ransomware group

Microsoft has identified a cybercriminal group tracked as Storm-1175 as responsible for actively exploiting a critical deserialization vulnerability (CVE-2025-10035) in Fortra’s GoAnywhere Managed File Transfer (MFT) software. This vulnerability affects the License Servlet component and allows unauthenticated remote code execution (RCE) by processing attacker-controlled serialized data. The attackers leveraged this zero-day flaw to gain initial access to targeted networks by […]
October 5, 2025

Allianz Life reveals almost 1.5m impacted by July data breach

Allianz Life Insurance Company of North America suffered a significant data breach impacting nearly 1.5 million individuals, including customers, financial professionals, and select employees. The breach occurred on July 16, 2025, when a malicious threat actor gained unauthorized access to a third-party, cloud based Customer Relationship Management (CRM) system used by Allianz Life via a social engineering attack, specifically a […]
October 1, 2025

Homebuyers shrug off cybersecurity risks, even as scammers target property deposits

Many home buyers remain surprisingly unconcerned about cybersecurity risks despite a rise in scammers targeting property deposits. A recent report from InfoTrack shows that around half of Australians have little to no worry about sharing personal information during property transactions, even though the average deposit is now approximately $160,000. This complacency is alarming given the increasing number of cybercriminals exploiting […]
September 29, 2025

Personal data potentially stolen in Asahi cyber-attack

Asahi Group Holdings, Japan’s largest brewer, was hit by a major ransomware attack, which forced the immediate shutdown of its domestic order placement, shipment, and customer service systems. The attack, attributed to the Russia-linked Qilin ransomware group, encrypted key IT infrastructure and disrupted nearly all digital business operations for Asahi’s beer and beverage products across Japan. As a consequence, the […]
September 22, 2025

Collins Aerospace/European airport systems hit by ransomware

A ransomware attack targeting Collins Aerospace’s vMUSE check-in and boarding software in September created widespread disruption at several major European airports, including London Heathrow, Brussels, Berlin Brandenburg, and Dublin. The assault began late Friday and rendered automated check-in kiosks and bag-drop systems inoperable, forcing airline staff to revert to manual paper-based processes. This rapid shift caused severe delays, extensive queues, […]
August 29, 2025

WhatsApp Cloud Ransomware Campaign

WhatsApp faced a significant cybersecurity incident after researchers uncovered a zero-day vulnerability (CVE-2025-55177) affecting its iOS and macOS applications. The flaw was tied to the linked devices feature, which synchronizes data across a user’s phone and secondary devices. Exploiting this weakness, threat actors could inject malicious content from unauthorized URLs, effectively bypassing normal security restrictions. Investigations revealed that the vulnerability […]
July 17, 2025

BigONE Cryptocurrency Exchange Hot Wallet Exploit

Seychelles-based cryptocurrency exchange BigONE suffered a significant hot-wallet exploit resulting in losses estimated at $27 million across multiple blockchains, including Bitcoin, Ethereum, BNB Chain, Solana, and TRON. The exchange confirmed the incident on 16 July, reporting that abnormal withdrawals had been detected and that hot-wallet operations were immediately suspended. Importantly, BigONE emphasized that its cold storage reserves remained secure and […]
June 20, 2025

WestJet Cyber Attack Causes Travel Disruption

WestJet confirmed it had been the target of a sophisticated cyberattack that caused significant disruption for customers. The incident was first detected on June 13, when suspicious activity was identified across the airline’s digital systems. Although flight operations and aircraft safety were not compromised, customers encountered service interruptions, particularly when attempting to access bookings through the airline’s website and mobile […]
June 18, 2025

Lee Enterprises says cybersecurity incident cost millions

Lee Enterprises, a major U.S. regional newspaper publisher, continued to grapple with the aftermath of a ransomware attack attributed to the Qilin gang that disrupted operations across more than 75 newspapers and exfiltrated nearly 350 GB of sensitive data. The breach compromised information of about 39,779 individuals, including names, Social Security numbers, driver’s license details, financial and medical records, and […]