Widespread Campaign Targets Cybercriminals and Gamers | #cybercrime | #infosec

A large-scale operation planting malicious code in open-source projects on GitHub has been uncovered by cybersecurity researchers. The scheme, centered on a developer using the alias ischhfd83, involves over 130 backdoored repositories disguised as malware tools or game cheats. A Booby-Trapped Malware Toolkit The investigation began when a Sophos customer queried the safety of a […]

Qualcomm fixes 3 critical chip vulnerabilities exploited by hackers: List of chipsets affected | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker

Qualcomm has announced that it has released patches for a series of vulnerabilities affecting dozens of its chips, including three zero-day flaws that the chipmaker says may be under active exploitation by hackers. Qualcomm cited Google’s Threat Analysis Group (TAG), which focuses on government-backed cyberattacks, indicating that these three flaws “may be under limited, targeted […]

Investigation ongoing into Liberty Twp. ransomware attack | #ransomware | #cybercrime

ExploreKettering Health cyberattack latest: Internal health records back, MyChart work continues “There’s no impact on services and communications to residents,’’ said Caroline McKinney, township administrator. The public can still communicate with township officials via the phone, email, social media platforms and website. Portals for submission of planning and other documents are operational but developers “got […]

Fake IT support calls hit 20 orgs, end in stolen data • The Register | #cybercrime | #infosec

A group of financially motivated cyberscammers who specialize in Scattered-Spider-like fake IT support phone calls managed to trick employees at about 20 organizations into installing a modified version of Salesforce’s Data Loader that allows the crims to steal sensitive data. Google Threat Intelligence Group (GTIG) tracks this crew as UNC6040, and in research published today […]

Aembit Named to Rising in Cyber 2025 List of Top Cybersecurity Startups | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware

Aembit, the workload identity and access management (IAM) company, today announced its inclusion in Rising in Cyber 2025, an independent list launched by Notable Capital to spotlight the 30 most promising cybersecurity startups shaping the future of security. Unlike traditional rankings, Rising in Cyber 2025 honorees were selected through a multi-stage process grounded in real-world validation. […]

Media giant Lee Enterprises says data breach affects 39,000 people | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware

Publishing giant Lee Enterprises is notifying over 39,000 people whose personal information was stolen in a February 2025 ransomware attack. As one of the largest newspaper groups in the United States, Lee Enterprises publishes 77 daily newspapers and 350 weekly and specialty publications across 26 states. The local news provider’s newspapers have a daily circulation […]

Lee Enterprises cyberattack compromised 40K people’s data • The Register | #cybercrime | #infosec

Regional newspaper publisher Lee Enterprises says data belonging to around 40,000 people was stolen during an attack on its network earlier this year. The Iowa-based company confirmed first and last names, as well as social security numbers, were among the data types potentially accessed, although it does not think any of it has been misused. […]