Featured
U.S. Allocates $3 Billion to Remove Chinese Telecom Equipment Over Security Concerns
The U.S. government is investing $3 billion to remove Chinese telecommunications equipment from American networks amid escalating cybersecurity threats. The initiative, part of the 2025 National Defense Authorization Act, aims to help telecom companies replace technology from manufacturers like Huawei and ZTE while protecting critical infrastructure.
Iranian Hackers Evolve: New C++ Variant of BellaCiao Malware Discovered
Kaspersky researchers have identified BellaCPP, a new C++ variant of Iranian state-sponsored malware targeting organizations across multiple regions. The discovery reveals how Iran's Charming Kitten hacking group continues to advance their cyber capabilities while streamlining their tools.
Critical Cloud Platform Vulnerabilities Put 50,000 Ruijie Network Devices at Risk
Security researchers discovered multiple critical flaws in Ruijie Networks' cloud platform that could enable remote control of network devices. The vulnerabilities, including a novel 'Open Sesame' attack method, exposed severe weaknesses in device authentication and command execution capabilities.
Educational Institutions Warned Against Microsoft 365 Copilot Over Privacy Risks
SURF's recent assessment reveals significant privacy concerns with Microsoft 365 Copilot, including data handling transparency issues and accuracy problems. The organization strongly advises educational institutions to avoid using the AI tool until adequate protective measures are implemented.
UN Adopts Historic Global Treaty to Combat Rising Cybercrime Threats
The United Nations General Assembly has approved a landmark cybercrime treaty, the first international criminal justice agreement in over 20 years. The comprehensive framework aims to enhance global cooperation in fighting digital threats while protecting human rights and providing tools for gathering electronic evidence.
OpenAI Hit with €15M Fine by Italian Regulators Over ChatGPT Privacy Violations
Italy's privacy watchdog Garante has fined OpenAI €15 million for multiple GDPR violations related to ChatGPT's data collection practices. The ruling mandates a public awareness campaign while highlighting growing tensions between AI advancement and privacy regulations in the EU.
Builder.ai Data Breach Exposes 1.29TB of Confidential User Information
A major security incident at Builder.ai has exposed over 3 million user records containing sensitive business documents and credentials. The British no-code platform's unprotected database revealed NDAs, financial records, and cloud storage access keys, raising concerns about potential cybercrime risks.
North Korean Hackers Orchestrate $308M Bitcoin Heist from Japanese Exchange
A sophisticated social engineering attack by North Korean hacking group TraderTraitor resulted in the theft of $308 million in Bitcoin from DMM Bitcoin exchange. The attack, which began with targeting an employee at crypto wallet company Ginco, marks one of the largest cryptocurrency heists of 2024.
Malicious PyPI Packages Found Stealing User Data and Hijacking Social Media Accounts
Security researchers discovered two dangerous packages on PyPI repository that accumulated 300 downloads before removal. The malware captured keystrokes, screenshots, and sensitive data from major social platforms while employing sophisticated concealment techniques to avoid detection.