Diplomatic entities in Belgium and Hungary hacked in China-linked spy campaign

A Chinese hacking group, UNC6384, targeted Hungarian and Belgian diplomatic entities along with other European nations, utilizing spearphishing and exploiting recent Windows vulnerabilities to conduct cyber espionage. The campaign involved malware like PlugX and indicated a strategic focus on NATO, EU policies, and international diplomacy efforts. #UNC6384 #PlugX #MustangPanda #EuropeanDiplomacy #CyberEspionage…

Read More
Baohuo Android Malware Hijacks Telegram Accounts via Fake Telegram X

A new Android backdoor named Android.Backdoor.Baohuo.1.origin is rapidly infecting devices through fake versions of Telegram X, allowing attackers full control over user accounts. The malware, using the Redis database for command and control, has impacted over 58,000 devices worldwide, mainly in India, Brazil, and Indonesia. #Android.Backdoor.Baohuo #TelegramMalware…

Read More
ThreatsDay Bulletin: 6M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More

Cybercriminals continue to exploit weak points such as misconfigurations, stale components, and trusted systems like OAuth to gain unauthorized access. Recent threats include sophisticated malware like Lumma Stealer and Vidar Stealer 2.0, as well as large-scale scams leveraging fake ads and open-source supply chain attacks. #LummaStealer #VidarStealer #OAuth #SupplyChainRisks…

Read More
September 2025 Security Issues in Korean & Global Financial Sector

The report details multiple cyber incidents affecting financial institutions worldwide, including database leaks, large-scale ransomware attacks (notably by Qilin), and statistics on malware and leaked account credentials targeting the finance sector. It highlights supply-chain infection vectors, data sale attempts on cybercrime forums, and recommends stronger data integrity verification and response strategies….

Read More
Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals

Operation Endgame (May 2024–May 2025) triggered multinational takedowns targeting loaders, botnets, and cash-out services, prompting selective Russian domestic enforcement that dismantled monetization nodes (e.g., Cryptex, UAPS) while higher-value ransomware operators with alleged intelligence ties (e.g., Conti, Trickbot) largely remained insulated. The resulting trust erosion in the underground drove tighter OPSEC, closed affiliate recruitment, rebrands, and decentralization as attackers adapted to sustained Western pressure and a conditional Russian “politics of protection.” #OperationEndgame #Cryptex #Conti #Trickbot

Read More
Ransom! Kumwell

Incransom has claimed a ransomware attack targeting Kumwell, a company dedicated to providing safety and security systems such as grounding, lightning, and surge protection across various critical infrastructure sectors. The attack potentially jeopardizes safety systems in countries including Thailand, China, India, Saudi Arabia, United Arab Emirates, Malaysia, Philippines, Vietnam, and Indonesia.

Read More