Ukrainian extradited from Ireland on Conti ransomware charges

A Ukrainian national linked to the Conti ransomware group has been extradited to the U.S. and faces serious charges for controlling stolen data and orchestrating cyber extortion. The Conti operation, responsible for over 1,000 attacks worldwide, has evolved into smaller groups since its shutdown, continuing to threaten critical infrastructure and organizations. #Conti #TrickBot

Read More
AL25-016 Internet-accessible industrial control systems (ICS) abused by hacktivists

This alert raises awareness about recent cyber threats targeting internet-connected Industrial Control Systems (ICS) in Canada, affecting critical infrastructure such as water facilities, oil and gas companies, and farms. It emphasizes the importance of comprehensive security measures, collaboration, and timely reporting to law enforcement. #ICS #CriticalInfrastructure #CyberCentre #RCMP #Canada…

Read More
Cyberpunks mess with Canada’s water, energy, farm systems

Hacktivists have targeted Canadian industrial control systems to cause disruptions and generate media attention, rather than for financial gain. These opportunistic attacks have affected critical infrastructure such as water facilities, oil companies, and farms, highlighting vulnerabilities in operational technology. #CanadianCyberSecurity #IndustrialControlSystems…

Read More
Middle East Cybersecurity Market to Double by 2030, Fueled by AI and Cloud Adoption

The Middle East Cybersecurity Market is rapidly expanding, driven by increased digital transformation, cyber threats, and government initiatives. The market is expected to double in size by 2030, with significant investments in cloud security, AI, and national resilience strategies. #MiddleEastCybersecurity #GCC #SaudiVision2030 #UAEVision2021…

Read More
Defense Contractor Manager Pleads Guilty for Selling Cyber Exploits to Russian Broker

Peter Williams, a former U.S. defense contractor executive, pleaded guilty to stealing and selling sensitive cyber exploit components to Russian brokers, risking national security. This case highlights the dangers of insider threats in cybersecurity and the potential for stolen data to empower foreign cyber actors. #TradeSecretsTheft #RussianCyberBrokers…

Read More
Cybersecurity News | Daily Recap [30 Oct 2025]

Daily Recap, The latest security alerts cover a broad sweep of breaches, from a Vinomofo data protection ruling and a major Conduent breach to widespread misinformation around Gmail and a surge in NPM credential theft campaigns. The report also highlights tools and flaws enabling rapid credential harvesting, patching gaps, botnet attacks on PHP/IoT, AI misuse in executive-targeted campaigns, and notable industry moves like Reflectiz funding and Spektrum Labs’ market entry. #Vinomofo #Conduent #GmailHoax #WPPluginLeak #PhantomRaven #NPM #LoginsZip #Dovecot #TotalJS #Copilot #DNSOutage #Mirai #Gafgyt #Mozi #BlueNoroff #AICloking #MaliciousSEO #ThreatsDay #ExploitsSold #M&SImpact #Reflectiz #SpektrumLabs #Herodotus

Read More
Hacktivist ICS Attacks Target Canadian Critical Infrastructure

Canadian cybersecurity officials warn of increasing hacktivist attacks on critical infrastructure, including water, energy, and agriculture sectors. Russia-linked hacktivists, particularly since the fall of 2024, have been prominent in targeting internet-accessible ICS devices to discredit organizations and undermine Canada’s reputation. #Z-Pentest #ICSgaps…

Read More
Silent Push Unearths AdaptixC2’s Ties to Russian Criminal Underworld, Tracks Threat Actors Harnessing Open-Source Tool for Malicious Payloads

Silent Push analysts discovered threat actors abusing the open-source AdaptixC2 post-exploitation framework to deliver malicious payloads, including via the CountLoader loader, and observed a surge in its use within global ransomware campaigns. The report highlights a likely developer/maintainer using the handle “RalfHacker” with Russian-language channels and ties to the Russian criminal…

Read More
Salty Much: Darktrace’s view on a recent Salt Typhoon intrusion

Salt Typhoon (aka Earth Estries / GhostEmperor / UNC2286) is a state-linked APT active since at least 2019 that has targeted telecoms, energy, and government systems worldwide using zero-day exploits, DLL sideloading, custom backdoors (SNAPPYBEE/Deed RAT), and obfuscated C2 channels. Darktrace observed a July 2025 intrusion against a European telco exploiting CVE-2025-5777 on Citrix NetScaler, delivering SNAPPYBEE via DLL side-loading and communicating with C2 domains such as aar.gandhibludtric[.]com. #SaltTyphoon #SNAPPYBEE

Read More