Tag: hacker
-
Leading members of Scattered Spider sentenced in UK to 66 months in jail
Thalha Jubair and Owen Flowers led and directed many attacks attributed to the hacker subset of The Com. U.S. authorities previously accused Jubair of participating in at least 120 attacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/scattered-spider-leaders-sentenced-united-kingdom/
-
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake Keylogger variants. The campaign impersonates legitimate businesses and brands in email lures, often using payment-themed…
-
Passwort”‘Spray”‘Kampagne – Hacker starten 81 Millionen Login-Versuche gegen Microsoft 365
First seen on security-insider.de Jump to article: www.security-insider.de/passwort-spraying-81-mio-angriffe-microsoft-365-rocp-mfa-a-429ec8a48b72ec905e4e2cfb85f19fb1/
-
Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign reflects a fast-paced, hands-on-keyboard intrusion combined with automated lateral movement, signaling a threat actor capable…
-
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan’s Zvartnots airport, held up a phone with a…
-
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/
-
GoSerpent Silently Steals Government Files for Weeks Before Sending Them to Hackers
A sophisticated cyber espionage campaign targeting government and diplomatic organizations across Southeast Asia has used a Go-based remote access Trojan, dubbed GoSerpent, to collect sensitive documents for weeks before exfiltrating them via network shares. Researchers first identified the activity in February 2026, although evidence indicates the operation began in late 2025. The attackers deployed GoSerpent…
-
Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution
Two alleged leading members of the Scattered Spider cybercrime collective have been sentenced to five years and six months in prison each for their involvement in the 2024 cyberattack on Transport for London (TfL). The National Crime Agency (NCA) described this case as the largest cybercrime prosecution in the UK. Thalha Jubair, 20, from East…
-
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London.The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority’s employees into an office to get their passwords…
-
2 Young Hackers Jailed for Disrupting London Underground
Police Say Arrests ‘Effectively Halted’ Scattered Spider Cybercrime Collective. Two leaders of the Scattered Spider hacking group received 66-month jail sentences in Britain’s biggest cybercrime prosecution to date, after they disrupted London’s transport authority, causing $39 million in losses and recovery costs. How to deter young hackers remains an ongoing challenge. First seen on govinfosecurity.com…
-
Hacker missbraucht Googles Gemini CLI zur Botnetz-Steuerung
Ein russischsprachiger Cyberkrimineller hat Googles KI-Tool Gemini CLI als autonomen Hacking-Agenten zur Steuerung eines Botnetzes missbraucht. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hacker-missbraucht-gemini
-
UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
Owen Flowers and Thalha Jubair, two members of the prolific Scattered Spider hacking group, pleaded guilty and were sentenced to five years and six months in jail for hacking London’s metropolitan transit system. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/16/uk-cops-say-arrest-of-two-young-hackers-disrupted-the-operations-of-an-infamous-hacking-group/
-
Scattered Spider hackers sentenced over TfL attack
Owen Flowers and Thalha Jubair, the hackers behind the 2024 TfL cyber attack, have been sentenced to five-year prison terms at Woolwich Crown Court First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645859/Scattered-Spider-hackers-sentenced-over-TfL-attack
-
Sandworm hackers have a CAPTCHA trick for Ukrainians
Rather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers. First seen on therecord.media Jump to article: therecord.media/ukraine-sandworm-hacks-captcha-powershell
-
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities and the results showed how effective a frontier LLM can be for hackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chatgpt55-to-execute-full/
-
Hacker können BindFunktion in Windows zum Erstellen virtueller Pfade in Datensystemen missbrauchen
Legitime Tools und Dienste bieten Hackern eine effektive Möglichkeit, ihre Living-off-the-Land (LOTL)- oder Living-off the-Services (LOTS)-Angriffe zu verbergen. Mit der Tarnkappe einer legitimen Funktion wie auch eines Dienstes oder Tools unterlaufen solche Angriffe die Erkennung von Endpoint-Detection and Response (EDR) oder anderer Analysetools. Weitere Beispiele für ein solches Mimikri haben die Experten der […] First…
-
Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileges. Rapid7’s Managed Detection and Response team detected targeted attacks before SonicWall publicly disclosed these vulnerabilities on July 14,…
-
Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack
Two leading members of the Scattered Spider cybercrime collective have been sentenced to more than five years in prison for carrying out the 2024 cyberattack against Transport for London (TfL). First seen on therecord.media Jump to article: therecord.media/scattered-spider-hackers-tfl-sentenced
-
‘Keys to the kingdom’: hackers who gained access to heart of London transport network jailed
Thalha Jubair, 20, and Owen Flowers, 19, sentenced to five and a half years each for cyber-attack that cost Transport for London £39mThe data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords.Over four days in 2024 a pair of…
-
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data collection rather than a single targeted objective. Its collection scope includes macOS Keychain files, Safari…
-
Australian Enterprises At Risk as Anthropic Finds Hackers In Claude Code
A Claude Code-powered cyberattack exposed AI governance gaps common among Australian businesses, where oversight continues to lag adoption. The post Australian Enterprises At Risk as Anthropic Finds Hackers In Claude Code appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/apac/
-
Finland issues wanted notice for hacker behind massive psychotherapy data breach
The defendant’s lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland. First seen on therecord.media Jump to article: therecord.media/finland-issues-wanted-notice-for-hacker-vastaamo-breach
-
Hackers steal Lidl customer data from external service provider
The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According to notifications sent to Lidl’s German, Belgian and Dutch customers on Friday, the attackers briefly accessed the file and exfiltrated part of its contents. First seen on therecord.media Jump…
-
ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data
A series of high-impact campaigns linked by overlapping tradecraft to ShinyHunters, in which attackers abused trusted Salesforce OAuth relationships to bypass conventional MFA protections, establish persistence, and exfiltrate CRM data at scale. The activity, observed from mid-202520252025 through mid-202620262026, affected organizations in retail, education, and manufacturing. Microsoft emphasized that the campaigns did not exploit an…
-
NSA Warns Russian State-Sponsored Hackers Exploiting Vulnerable Routers to Target Critical Infrastructure
Tags: access, advisory, cyber, cybersecurity, exploit, hacker, infrastructure, international, network, router, russia, threat, vulnerabilityThe U.S. National Security Agency (NSA) and international cybersecurity partners have issued a warning that Russian state-sponsored threat actors are actively exploiting vulnerable and poorly configured network routers to access organizations in critical infrastructure sectors. In a joint Cybersecurity Advisory (CSA) titled >>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,<< released on July 13,…
-
The US government warns that Russia state hackers are coming after your router
With residential proxies all the rage, CISA urges router users to be vigilant. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router/
-
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/

