Cybersecurity Weekly Recap PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more

In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped usernames, emails, and encrypted passwords from over 1.2 million accounts, underscoring the persistent risks of adult platforms as lucrative targets for credential stuffing and phishing campaigns. As […]
100+ Cisco Secure Email Devices Exposed to ZeroDay Exploited in the Wild

Security researchers have identified at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that attackers are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-20393, currently has no available patch, leaving organizations exposed to potential compromise. According to threat intelligence from Shadowserver […]
Claude Opus 4.5 Now Integrated with GitHub Copilot

GitHub has announced the general availability of Claude Opus 4.5, Anthropic’s advanced AI model, across its Copilot platform. This integration enhances AI capabilities for developers using GitHub’s code assistance tools. The Claude Opus 4.5 model is now accessible to users with Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+ subscriptions. Developers can leverage this […]
Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra

Microsoft has begun deploying Baseline Security Mode across Microsoft 365 tenants, a new dashboard in the M365 Admin Center that centralizes recommended security configurations for Office, SharePoint, Exchange, Teams, and Entra. Announced at Ignite 2025, this opt-in feature helps administrators quickly assess vulnerabilities, run impact reports, and apply risk-based hardening without immediate user disruptions. As […]
Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks

In a shocking betrayal of industry trust, two former cybersecurity professionals have pleaded guilty to federal charges for launching ransomware attacks against U.S. businesses. The pair, whose day jobs involved helping companies respond to hacks and negotiate ransoms, admitted to moonlighting as cybercriminals in a plot to extort millions of dollars from victims. Ryan Clifford […]
Hackers Weaponize SVG Files and Office Documents to Target Windows Users

Cybersecurity researchers have uncovered a sophisticated email campaign deploying a commodity loader to distribute Remote Access Trojans and information stealers. The operation primarily targets manufacturing and government organizations across Italy, Finland, and Saudi Arabia, using highly evasive techniques. Infection chain Multi-Vector Attack Strategy The campaign employs multiple infection methods to compromise Windows systems. Threat actors […]
Microsoft Teams Down Users Face Messaging Delays and Service Disruptions Worldwide

In a major disruption to remote work and collaboration, Microsoft Teams experienced a significant outage on Friday, affecting thousands of users across multiple regions. Reports of messaging delays, failed message deliveries, and issues with other service functions began surging around 2:30 PM ET (7:30 PM GMT), bringing productivity to a halt for businesses and individuals […]
Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code

The Cloud Atlas advanced persistent threat group has continued its sophisticated campaign targeting organizations across Eastern Europe and Central Asia during the first half of 2025, leveraging outdated Microsoft Office vulnerabilities to deliver multiple backdoor implants. This campaign reveals a coordinated effort to establish persistent access and extract sensitive data from high-value targets. Cloud Atlas, […]
University of Sydney Hacked Students and Staff Data Exposed

The University of Sydney has confirmed a significant data breach affecting thousands of current and former staff members, as well as students and alums. In a message to the university community, Vice-President (Operations) Nicole Gower revealed that suspicious activity was detected in an online IT code library last week. While this digital storage space was […]
New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector

A newly identified botnet malware family, dubbed “Udados,” has emerged as a significant threat to the Technology and Telecommunications sectors, orchestrating high-volume HTTP flood Distributed Denial-of-Service (DDoS) attacks. According to ANY.RUN sandbox analysis, the botnet leverages infected hosts to execute sustained denial-of-service campaigns designed to disrupt business continuity by overwhelming target servers with legitimate-looking traffic. […]