Cybersecurity researchers have discovered a new data extortion group called Helix that has been targeting companies by using user credentials rather than software vulnerabilities. Helix has been employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Abbott Investigates Two Cyber Incidents Following Extortion Claims
Two separate cybersecurity incidents are being investigated by Abbott Laboratories after threat actors reportedly gained access to the company’s systems and accessed sensitive information. While one incident has been linked to the ShinyHunters extortion group, the other involves claims…
Nearly 7 Million Driver’s License Numbers Exposed After AssuranceAmerica Data Breach
Nearly seven million people are being notified after a cyberattack on Atlanta-based auto insurer AssuranceAmerica exposed highly sensitive personal information, including driver’s license numbers, Social Security numbers and insurance records, raising concerns about long-term identity theft risks. According to…
AI Agent Runs First End-to-End Ransomware Attack
Security researchers have long warned that AI would lower the barrier to cybercrime, but the latest case makes that threat tangible. In the operation described by Sysdig and covered by Forbes, an autonomous agent carried out the technical steps…
AssuranceAmerica Data Breach Exposes Personal Information of Nearly 7 Million Individuals
Auto insurance company AssuranceAmerica is notifying almost 6.99 million people of the possible exposure of their private information after experiencing a data breach. The company appeared on the state attorney generals earlier this month to reveal the cyberattack occurred…
Group-IB Uncovers ClickLock macOS Malware Targeting Passwords and Crypto Wallets
An aggressive social engineering technique has been used by ClickLock, an information-stealing macOS malware, to obtain victims’ information about their system login passwords. Security researchers at Group-IB report that the malware disables normal system functionality, leaving users with little interaction…
Bitdefender Uncovers Windows Bind Link Technique That Evades EDR Detection
Researchers at Bitdefender have discovered a new technique for hiding malware from Endpoint Detection and Response (EDR) solutions by utilizing bind links, a valid Windows feature. Despite Microsoft’s classification of this issue as low severity due to the fact…
Deepfake Cyber Fraud Costs Capillary Technologies Over ₹32 Crore
Capillary Technologies’ recent deepfake-enabled cyber fraud incident highlights how rapidly evolving AI tools are transforming from business enablers into serious security threats for global enterprises. The Bengaluru-based SaaS company disclosed that an overseas step-down subsidiary lost around €3 million,…
UK Court Sentences Two Hackers to 5.5 Years for Transport for London Cyberattack That Caused £29 Million in Damages
Two hackers have been sentenced to five and a half years in prison each for carrying out the 2024 cyberattack on Transport for London (TfL), in what the UK’s National Crime Agency (NCA) has described as the country’s largest…
TRAI Seeks IT Act Powers to Act Against Spam-Tagging Apps Like Truecaller
The Telecom Regulatory Authority of India (TRAI) seeks new powers in the Information Technology (IT) Act to take action against call management apps, including Truecaller, Hiya, and Whoscall, for marking or blocking legitimate commercial calls as spam. The regulator…
Coca-Cola says ransomware attack disrupts Fairlife operations, temporarily suspends U.S. dairy production
The Coca-Cola Company has revealed that a ransomware attack targeting its Fairlife dairy business has temporarily disrupted production across the United States after threat actors gained unauthorized access to company systems, including those supporting manufacturing operations. The incident was…
Dutch Authorities Arrest Multiple Suspects in Global Investment Fraud Investigation
Dutch authorities have arrested multiple suspects as part of an international investigation into an alleged investment fraud network that investigators believe defrauded victims worldwide through fake online investment schemes, with the operation at one point generating more than €100…
Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned
The Centre has attempted to reassure the public that the data breach incident involving electronic files of the Kudankulam Nuclear Power Plant (KKNPP) has no implication on the nation’s nuclear security or reactor operations. Union Minister of State for…
Bengaluru Housewife’s WhatsApp Hacked; Morphed Obscene Videos Shared Online
A 42-year-old housewife in Bengaluru has fallen victim to a disturbing cybercrime after her WhatsApp account was hacked and morphed obscene videos were shared online, triggering widespread outrage and highlighting the growing threat of digital harassment against women. The…
Windows 11 KB5101650 and KB5099414 Updates Released With Security Fixes and New Features
A cumulative update for Windows 11 based on Patch Tuesday July 2026 is now available, with KB5101650 for versions 25H2 and 24H2 and KB5099414 for version 23H2. As well as addressing 571 security vulnerabilities, the mandatory updates also improve…
Pentagon Pauses CMMC Phase Two Rollout for 60-Day Review of Cybersecurity Program
The US Department of Defense (DoD) has decided to suspend the implementation of the cybersecurity maturity model certification (CMMC) second phase on a temporary basis. The DoD will conduct a 60-day review before continuing with the implementation of the…
Researchers Find Claude for Chrome Flaws That Could Let Malicious Extensions Trigger Sensitive Google Tasks
Researchers at Manifold Security have disclosed two security weaknesses in Anthropic’s Claude for Chrome extension that could allow another browser extension with access to the Claude website to trigger predefined AI-powered actions involving a user’s Gmail, Google Docs and Google…
RabbitMQ Flaw Exposes OAuth Secrets, Risks Full Broker Takeover
A serious vulnerability in RabbitMQ is threatening enterprise messaging systems by allowing attackers to steal OAuth secrets and take full control of brokers. Tracked as CVE-2026-57219, the flaw has a CVSS score of 8.7 and affects popular RabbitMQ versions…
Japan’s Largest Taxi Service Goes Offline After Cyberattack
Nihon Kotsu, Japan’s largest taxi operator, said that its systems were impacted in a cyberattack, causing the company to close down some of its infrastructure. The incident happened last week and impacted business operations such as the company’s taxi dispatch…
CrashStealer macOS Malware Uses Apple-Notarized App to Evade Security Checks
CrashStealer, a new macOS information-stealing malware named for Apple’s Mac operating system, bypasses built-in security protections by using an Apple notarized application, demonstrating a growing trend of malicious actors utilizing legitimate software verification mechanisms in order to target Apple users. …