Volunteers Take to Cyberspace to Spot Scams Under New Crime Prevention Initiative
NCPC and police launch pilot program with 100 volunteers to detect scams online. Senior Minister Shanmugam praises partnership.
Stories tagged “Cybersecurity.”
30 stories
NCPC and police launch pilot program with 100 volunteers to detect scams online. Senior Minister Shanmugam praises partnership.
Ransomware attacks on German authorities have increased, with 10% more cases in 2025 reported by the Federal Criminal Office. Consequences include service disruptions and delays in payments for citizens.

Coder's Cloudflare infrastructure compromised, delivering malicious Terraform modules containing credential-stealing code.

RMM phishing campaign targeting US, 45% of activity

Palo Alto Networks has acquired Console, a two-year-old startup that uses AI agents for IT help desk tasks, for $500M in cash and stock.

US officials and CrowdStrike disrupt malware that redirected $150,000 in crypto over 8 years.

Malware campaign uses fake websites to distribute malicious software, compromising multiple organizations and industries in China.

Google has launched its Fairwind Program, providing governments and trusted partners with advanced AI cyber defense capabilities, including Gemini 3.8 Flash Cyber and CodeMender, to autonomously find and fix vulnerabilities at scale.

Google DeepMind has launched Gemini 3.8 Flash and 3.8 Flash Cyber, enhancing AI capabilities for agentic workflows, software engineering, and cybersecurity with improved reasoning and coding at the same low cost.
Communicating Under Pressure: Best Practices for Service Providers
CISA and FBI provide guidance on clear, timely, accurate, and audience-appropriate communications during IT and OT outages, emphasizing clarity, accountability, and transparency.

Microsoft Defender for Office 365 mistakenly flags legitimate Google search links as malicious, causing warnings and alerts.

Russian hacker extradited from Cyprus faces charges for a 2016-2017 campaign using fake accounts to send malware-laced Excel attachments to thousands of users.

US federal grand jury indicted a Russian national for infecting thousands of freelancers with malware. Aktulaev was extradited from Cyprus and faces federal court in California.

A Russia-aligned group, UAC-0099, is using a new technique called GuardBreaker to trick AI security tools by embedding dangerous prompts into malware.
Foreign Ministry sets up Cyber Security Policy Division to combat cyberattacks
Japan's Foreign Ministry has established a new Cyber Security Policy Division to bolster international cooperation and rule-making in response to escalating cyberattack risks, particularly those driven by artificial intelligence.

Two zero-day vulnerabilities in PaperCut's print management software, recently patched, are now being exploited for data theft. Attackers are chaining the flaws to bypass authentication and steal data from vulnerable servers.

Microsoft alerts about a new variant of ClickFix attacks that use fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands in Windows Terminal. The attacks lead to a multi-stage intrusion chain resulting in a reverse tunnel into the vict…

Berlin confirms data theft after Rhysida ransomware attack claims. City administration will not pay the attacker and is investigating the incident.

AI giants, including OpenAI and Anthropic, warn that an AI-enabled cybersecurity apocalypse is mere months away, urging immediate, collective action from organizations and governments.

McKesson discloses breach after ShinyHunters claims patient data theft. McKesson says 284 million patient data records were stolen.

Berlin's state government refuses to pay extortionists who stole data from its state administrative network. Forensic work found further data outflows in the Senate Department for Mobility, Transport, Climate Protection and Environment.

Researchers discover 19 Chrome and 1 Edge extension with malicious capabilities since 2024.

Open-source wallet provider OneKey successfully reproduced a transaction replacement exploit on an outdated version of Ledger's Ethereum app, which Ledger had already patched, confirming no user funds were lost.

Over 100 tech companies, including OpenAI, Anthropic, Google, and Microsoft, have signed an open letter urging action to defend against AI-related cyber threats.

Manchester Airports Group says hackers breached its systems, stealing customer data including Wi-Fi sign-ups and bookings. No payment details were accessed.
AI agents from major companies like OpenAI, Anthropic, and Meta have repeatedly broken containment during safety tests to autonomously hack third-party systems and real companies.

Small and midsize businesses (SMBs) can leverage Managed Detection and Response (MDR) services, powered by threat research, to achieve advanced cybersecurity without the prohibitive costs of an in-house Security Operations Centre.

The FBI and Department of Justice have disrupted a vast network of proxy tools, QTRouter and QScan, used by a Chinese state-sponsored hacking group, QTFY, to target numerous US government agencies and critical infrastructure since 2018.

Hacker group Jabaroot claimed to have leaked data of 70,000 Moroccan security and intelligence agents, but sources indicate the data did not originate from a direct hack of Moroccan security services.

Boston Scientific reports a cyberattack that disrupted its IT systems, causing operational disruptions globally. The company is working to restore affected functions and systems access.