02 Oct, 2026

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. The threat actors told GeekFeed the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally […]

6 mins read

US takes down NightmareStresser DDoS-for-hire platform

On Tuesday, the U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world’s longest-running distributed denial-of-service (DDoS) platforms. “Booter services” like NightmareStresser are DDoS-for-hire services that let anyone rent large botnets of compromised routers and a wide range of IoT devices to launch massive DDoS attacks targeting online platforms […]

2 mins read

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio. The threat actor primarily targeted individuals in the U.S., U.K., and […]

2 mins read

IDScan confirms breach tied to 153 million stolen driver’s licenses

Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver’s license scans. IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data […]

3 mins read

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses. Several law firms, including Markovits, Stock & DeMarco, and Hall Attorneys, have also launched investigations into potential class-action litigation related to the reported security incident at IDScan. Brian Krebs originally reported on […]

2 mins read

FBI disrupts proxy network enabling Chinese espionage operations

The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. According to the Department of Justice, a threat actor known as QTFY/QT/QTCYBER utilized two “hacking platforms known as ‘QScan’ and ‘QTRouter,’” in attacks targeting U.S. critical infrastructure and other sensitive networks. Among QTFY’s […]

4 mins read

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

The Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. This was revealed in a joint advisory in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI). “As of April […]

2 mins read

FBI: Hackers target online accounts to steal nude photos

The FBI warns that cybercriminals are targeting adults’ and children’s social media and other online accounts to steal sexually explicit images or videos. As the law enforcement agency explained in a public service announcement published this week, the attackers may use the stolen content to blackmail the victims or try to sell it on criminal […]

3 mins read

US and South Korea warn of Gunra ransomware targeting govt agencies

U.S. federal agencies and South Korea’s National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. In a Monday joint advisory, they said the ransomware group uses a malware variant based on the Conti ransomware source code leaked in February 2022, in attacks targeting a wide range of industry sectors, from […]

2 mins read

FBI: Russian hackers now target Signal backup recovery keys

The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims’ historical messages. The updated public service announcement is an update to a March 2026 advisory that warned the threat actors were targeting users of commercial messaging […]

4 mins read