Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. GeekFeed learned of the campaign from a reader, who told us threat actors are creating random Steam accounts to post what appears to be helpful fixes for people’s posts about games […]
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America. A filtering system ensures that only real […]
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases. However, the messages appear to be sent […]
OpenAI confirms ChatGPT is down worldwide
ChatGPT is experiencing a major outage, and users are unable to load chats, including previous conversations. The outage started at approximately 5 AM ET and is affecting users worldwide, including those in the US and Europe. If you are affected, ChatGPT will get stuck at loading animations for the sidebar, and you won’t be able […]
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22. Apart from names, it is unclear what type of information […]
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. The activity was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko after they discovered several exposed web directories containing hundreds of files associated with the operation. […]
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail. Cybersecurity company ReliaQuest identified compromised Wi-Fi […]
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. The outage began at 10:44 AM ET on Thursday, July 23, and mostly affected customers accessing Microsoft 365 services through network infrastructure connected to […]
Chick-fil-A data breach affects more than 13,000 customers
American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks. As GeekFeed first reported, the company revealed in data breach notification letters filed with multiple attorney general’s offices that it detected attacks targeting its website and mobile app between June 17 […]
Europol flags 4,340 URLs for removal in ‘The Com’ crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to “The Com,” a loosely organized network of nihilistic violent extremist groups. Investigators from nine countries (i.e., Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden) took part in what Europol called “Referral Action Days” between June and […]