OpenAI bans accounts linked to Russian and Chinese threat actors exploiting ChatGPT for cyber ops
Russian threat actors exploited ChatGPT to develop Windows-based malware, set up command-and-control (C2) infrastructure, and debug multi-language code.
June 9, 2025
Qilin exploits Fortinet flaws in new ransomware campaign
Qilin began a coordinated campaign between May and June 2025 using Fortinet vulnerabilities CVE-2024-21762 and CVE-2024-55591.
June 9, 2025
Cyber Security Week in Review: June 6, 2025
In brief: a critical vBulletin bug is being exploited in the wild, new destructive PathWiper malware targets Ukraine, and more.
June 6, 2025
New PathWiper malware targets critical infrastructure in Ukraine
PathWiper shares several characteristics with Sandworm's HermeticWiper, which was used in attacks against Ukraine in 2022.
June 5, 2025
US seizes 145 domains linked to BidenCash carding forum
It is estimated that the operation generated more than $17 million in revenue since launching in March 2022.
June 5, 2025
Hackers target multinational firms in Salesforce data breach scheme
The attackers contact English-speaking employees while impersonating IT support personnel.
June 5, 2025
Hacker targets GitHub users with trojanized code laced with backdoors
The GitHub account ‘ischhfd83,’ which published Sakura RAT, was linked to a broader malware distribution network spanning 141 repos.
June 4, 2025
New malware campaign exploits fake Gitcode and DocuSign sites to deliver NetSupport RAT
Some of the fake DocuSign pages deploy a deceptive CAPTCHA verification process.
June 4, 2025
Coinbase data breach linked to bribed Indian support staff at TaskUs
The breach came to light when a TaskUs employee was caught photographing her computer screen with a personal device.
June 4, 2025
Meta and Yandex caught using tracking technique that de-anonymizes Android users
The researchers found that native Android apps silently listen on fixed local ports for tracking purposes.
June 4, 2025