Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Spread Fickle Stealer Malware

A Russian-linked cybercrime group known as EncryptHub has recently been exposed for using a serious Windows flaw called MSC EvilTwin to deliver malware. Security researchers revealed that the attackers are exploiting the vulnerability, identified as CVE-2025-26633, to spread a data-stealing tool named Fickle Stealer. The vulnerability allows malicious Microsoft Console (.msc) files to run in … Continued

CISA Flags Two Actively Exploited N-central Vulnerabilities: CVE-2025-8875 and CVE-2025-8876

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in N-able’s N-central software to its Known Exploited Vulnerabilities (KEV) Catalog. This listing confirms that the flaws are being actively targeted by attackers and require urgent attention from organizations using the platform. N-able N-central is a popular remote monitoring and management (RMM) tool … Continued

Charon Ransomware Targets Middle East with Nation-State Level Tactics

A new ransomware strain called Charon has been making headlines after targeting organizations in the Middle East. The main victims are from the public sector and aviation industry. What makes this attack more dangerous than usual is that the hackers are using techniques normally seen in nation-state cyber espionage groups. This makes the ransomware much … Continued

Manpower Data Breach Exposes Nearly 145,000 Individuals’ Personal Information

Manpower, the international staffing and workforce solutions company, has announced a data breach that may have affected 144,189 people. The company sent formal notifications after completing its investigation, confirming that sensitive personal information might have been accessed by unauthorized parties. The breach involved Manpower and associated staffing operations. It started when staff in Lansing, Michigan, … Continued

Connex Credit Union Data Breach Exposes 172,000 Members’ Personal Information

Connex Credit Union has confirmed that a major cyberattack exposed the personal information of approximately 172,000 individuals. The affected group includes current and former members, along with others connected to the credit union. The organization has called this one of the most serious security incidents in its history. The breach occurred in early June 2025 … Continued

Win-DDoS Flaws Let Attackers Weaponize Public Domain Controllers

Security researchers from SafeBreach Labs have discovered a new set of denial-of-service (DoS) vulnerabilities in Windows, known as Win-DoS and Win-DDoS. These flaws allow attackers to abuse publicly accessible Windows domain controllers to generate massive amounts of traffic, turning them into a large-scale distributed denial-of-service (DDoS) botnet without the need for malware. The team identified … Continued

Columbia University Data Breach Exposes 870,000 Records

Columbia University has confirmed a major data breach that impacted nearly 870,000 people. Those affected include current and former students, job applicants, staff members, and even some of their family members. The incident is one of the largest security breaches reported by a U.S. university in recent years. The first signs of trouble appeared on … Continued

Newsletter line