Russian Hackers Hijack IP Cameras to Spy on NATO Military Supply Routes

Russian intelligence agencies have been accused of hacking internet-connected IP cameras across several NATO countries and Ukraine to secretly monitor military logistics and the movement of aid. According to a joint advisory released by Dutch intelligence and international security partners, the campaign focused on watching transportation routes used to deliver military equipment to Ukraine. Officials … Continued

EU Orders Google to Open Android to Rival AI Assistants

The European Union has issued legally binding instructions requiring Google to give rival AI assistants deeper access to Android devices under the Digital Markets Act (DMA). The decision is aimed at increasing competition by allowing competing AI services to use important Android features that are currently more accessible to Google’s own Gemini assistant. Officials say … Continued

New GoSerpent Malware Spies on Southeast Asian Governments and Diplomats

Security researchers have uncovered a sophisticated cyber espionage campaign that uses a newly documented malware family called GoSerpent to target government agencies and diplomatic organizations across Southeast Asia. The operation has been active since late 2025, although researchers found earlier versions of the malware dating back to 2021. The campaign is designed to quietly collect … Continued

Dutch Police Bust €100 Million-a-Month Investment Fraud Ring in Major International Crackdown

Dutch police have arrested multiple suspects linked to a large international investment fraud network that allegedly stole more than €100 million every month from victims across several countries. Authorities say the criminal organization operated with over 700 people working in around 20 call centers, where employees pretended to be professional financial advisers. Investigators believe the … Continued

Russian Hackers Use Fake Zoom and WebEx Apps to Spread New Starland RAT Malware

A financially motivated Russian threat group tracked as UAT-11795 has been found distributing fake versions of trusted software, including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT, to infect Windows systems with a newly discovered malware called Starland RAT. According to Cisco Talos, the campaign has been active since at least June 2025 and has mainly targeted … Continued

SonicWall Warns of Two Active Zero-Day Attacks on SMA 1000 Devices, Urges Immediate Patching

SonicWall has issued an urgent security warning after confirming that two previously unknown zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances are being actively exploited by attackers. The company said it investigated multiple real-world incidents that confirmed the flaws are already being used in attacks. Organizations using these devices have been advised … Continued

Cursor Security Flaw Lets Malicious Git Repositories Execute Code on Windows

Cursor, a popular AI-powered coding editor, has been found to contain a serious security flaw that could allow attackers to run malicious code on Windows computers. The issue is triggered when a developer opens or clones a specially crafted repository. Security researchers warned that the attack requires very little user interaction, making it a significant … Continued

SAP Fixes Critical Security Flaws in NetWeaver and Commerce Cloud, Urges Immediate Patching

SAP has released new security updates to fix several serious vulnerabilities affecting its enterprise software products. As part of its latest Security Patch Day, the company addressed 16 security issues, including three critical vulnerabilities in SAP NetWeaver, SAP Commerce Cloud, and SAP AppRouter. These flaws could expose organizations to serious security risks if they are … Continued

148 Fake npm Packages Turn Browsers Into a Hidden DDoS Botnet

A new cybersecurity investigation has uncovered a large campaign involving 148 malicious npm packages that pretended to be harmless student web proxy tools. Security researchers at JFrog found that these packages were not designed to attack developers who downloaded them. Instead, they targeted students and other users who opened the proxy websites, secretly turning their … Continued

Newsletter line