Ticker feed
A phishing email in September 2020 gave attackers a foothold in South Staffordshire Water that went undetected for 20 months. Between August and November 2022, more than 4.1 terabytes of data belonging to 633,887 people appeared on the dark web — customers' bank details and staff National Insurance numbers among it.
Chris Durham, 53, from Halesowen, had two phone contracts taken out in his name, including an expensive iPhone shipped to north-east London. His £14-a-month PAYG account started being debited £60, and it took months to get the money back. "I was frustrated, stressed and violated. I was robbed," he said. Nigel Calladine, 75, changed his email address and bank accounts entirely after six months of phishing.
The ICO fined South Staffordshire £963,900 under a voluntary settlement, reduced by 40% after the company admitted liability early and agreed not to appeal. The firm says it placed dedicated advisors during the incident, offered free credit monitoring, and has since invested significantly in its cyber resilience. Calladine isn't convinced: "The people who pay the fine are the people who were hacked, so the customer loses out twice."
Source: BBC News
A phishing email in September 2020 gave attackers a foothold in South Staffordshire Water that went undetected for 20 months. Between August and November 2022, more than 4.1 terabytes of data belonging to 633,887 people appeared on the dark web — customers' bank details and staff National Insurance numbers among it.
Chris Durham, 53, from Halesowen, had two phone contracts taken out in his name, including an expensive iPhone shipped to north-east London. His £14-a-month PAYG account started being debited £60, and it took months to get the money back. "I was frustrated, stressed and violated. I was robbed," he said. Nigel Calladine, 75, changed his email address and bank accounts entirely after six months of phishing.
The ICO fined South Staffordshire £963,900 under a voluntary settlement, reduced by 40% after the company admitted liability early and agreed not to appeal. The firm says it placed dedicated advisors during the incident, offered free credit monitoring, and has since invested significantly in its cyber resilience. Calladine isn't convinced: "The people who pay the fine are the people who were hacked, so the customer loses out twice."
Source: BBC News
A self-replicating worm called Shai-Hulud has infected over 100 packages across NPM and PyPI since September 2025, with attacks sharply escalating in recent weeks. After hacking group TeamPCP released the worm's source code in mid-May, clones emerged fast — Socket, Snyk, Sonatype, Ox Security and others have been tracking the fallout since.
The latest variants — Miasma and Hades — harvest credentials, API keys and tokens, then spread by infecting packages the victim can access. Miasma drops via weaponized binding.gyp files during npm install; Hades uses -setup.pth files to run at Python startup, pulling in the Bun runtime to execute. Red Hat's Hybrid Cloud Console lost 32 JavaScript packages, alongside the Vapi server SDK and wrangler-deploy, with Hades leaning on bioinformatics, graph ML and MCP-themed packages.
In total, 471 malicious artifacts have been identified. If you've installed anything from these ecosystems recently, rotate your npm, PyPI and cloud credentials — the worm spreads using what it steals.
Source: SecurityWeek
A self-replicating worm called Shai-Hulud has infected over 100 packages across NPM and PyPI since September 2025, with attacks sharply escalating in recent weeks. After hacking group TeamPCP released the worm's source code in mid-May, clones emerged fast — Socket, Snyk, Sonatype, Ox Security and others have been tracking the fallout since.
The latest variants — Miasma and Hades — harvest credentials, API keys and tokens, then spread by infecting packages the victim can access. Miasma drops via weaponized binding.gyp files during npm install; Hades uses -setup.pth files to run at Python startup, pulling in the Bun runtime to execute. Red Hat's Hybrid Cloud Console lost 32 JavaScript packages, alongside the Vapi server SDK and wrangler-deploy, with Hades leaning on bioinformatics, graph ML and MCP-themed packages.
In total, 471 malicious artifacts have been identified. If you've installed anything from these ecosystems recently, rotate your npm, PyPI and cloud credentials — the worm spreads using what it steals.
Source: SecurityWeek
A threat group called Silent Ransom (also tracked as UNC3753, Luna Moth and Chatty Spider) has been hitting US law, financial and professional services firms with a slick social engineering campaign between January and May 2026, according to Google's Mandiant division.
The attacks start with a clean invoice email — no malicious attachment — followed by a phone call from someone posing as internal IT or security. Victims are talked into a Zoom or Teams screen-share and into installing AnyDesk, Zoho Assist or similar remote access tools. The FBI warned separately in May that group members have also shown up at offices in person, posing as IT staff to reimage machines while plugging in USB drives to take data directly.
Once inside, the group moves fast — sometimes from initial contact to extortion demand in under an hour, with demands arriving within 30 minutes of the data being taken. Ransom notes come with a three-day deadline and threats to notify employees, partners and customers, and to go public.
Mandiant's advice: train staff on vishing, tighten conditional access for remote sessions, and lock down which RMM and screen-sharing tools can run at all.
Source: Dark Reading
A threat group called Silent Ransom (also tracked as UNC3753, Luna Moth and Chatty Spider) has been hitting US law, financial and professional services firms with a slick social engineering campaign between January and May 2026, according to Google's Mandiant division.
The attacks start with a clean invoice email — no malicious attachment — followed by a phone call from someone posing as internal IT or security. Victims are talked into a Zoom or Teams screen-share and into installing AnyDesk, Zoho Assist or similar remote access tools. The FBI warned separately in May that group members have also shown up at offices in person, posing as IT staff to reimage machines while plugging in USB drives to take data directly.
Once inside, the group moves fast — sometimes from initial contact to extortion demand in under an hour, with demands arriving within 30 minutes of the data being taken. Ransom notes come with a three-day deadline and threats to notify employees, partners and customers, and to go public.
Mandiant's advice: train staff on vishing, tighten conditional access for remote sessions, and lock down which RMM and screen-sharing tools can run at all.
Source: Dark Reading
A ransomware attack has forced Evanston Township High School to close its campus, canceling summer school, sports camps and all on-campus activities. The attack, discovered on the night of Sunday 7 June, knocked out phone lines, internet, computers, email and student accounts, and even the school's emergency notification and PA systems.
The FBI is investigating alongside cybersecurity attorneys and forensic experts. No ransom demand has been received. Staff were told to work from home Monday, with the campus shut through Tuesday and due to reopen Wednesday 10 June. Google passwords for employees have already been reset as a precaution.
District leadership says it is still working out what information the attackers may have accessed.
Source: CBS News Chicago
A ransomware attack has forced Evanston Township High School to close its campus, canceling summer school, sports camps and all on-campus activities. The attack, discovered on the night of Sunday 7 June, knocked out phone lines, internet, computers, email and student accounts, and even the school's emergency notification and PA systems.
The FBI is investigating alongside cybersecurity attorneys and forensic experts. No ransom demand has been received. Staff were told to work from home Monday, with the campus shut through Tuesday and due to reopen Wednesday 10 June. Google passwords for employees have already been reset as a precaution.
District leadership says it is still working out what information the attackers may have accessed.
Source: CBS News Chicago
Lansing Community College is only now notifying 174,307 people that their personal data was exposed in a February 2025 breach — more than a year after the fact. The college spotted the intrusion within about a week, but the letters have taken until now. Hackers used compromised credentials to get in, reaching names, addresses, dates of birth, driver's license details and Social Security numbers.
LCC says there's no evidence the data was removed or misused, that other information it holds may also have been caught up, and that what was exposed varies by individual. The Michigan college is offering 24 months of free credit monitoring and identity protection, and says it has tightened its security practices since. No ransomware group has claimed responsibility.
Source: SecurityWeek
Lansing Community College is only now notifying 174,307 people that their personal data was exposed in a February 2025 breach — more than a year after the fact. The college spotted the intrusion within about a week, but the letters have taken until now. Hackers used compromised credentials to get in, reaching names, addresses, dates of birth, driver's license details and Social Security numbers.
LCC says there's no evidence the data was removed or misused, that other information it holds may also have been caught up, and that what was exposed varies by individual. The Michigan college is offering 24 months of free credit monitoring and identity protection, and says it has tightened its security practices since. No ransomware group has claimed responsibility.
Source: SecurityWeek
CISA added CVE-2022-0492 to its Known Exploited Vulnerabilities catalog on 2 June after confirming active exploitation in the wild — a four-year-old Linux kernel privilege escalation flaw, public for roughly three years, that attackers have only now started using. Kaspersky reported the exploitation a day before CISA's alert, without naming the attackers or victims.
The flaw (CVSS 7.8) targets the cgroups v1 release_agent feature, allowing attackers to execute arbitrary commands with root-level access — and potentially break out of containerized environments entirely. It's especially dangerous in cloud-native setups where containers rely on cgroups for resource isolation.
The federal remediation deadline was 5 June. Everyone else should move fast too: update the kernel, disable unprivileged user namespaces where you can, and audit container configurations for suspicious cgroup activity.
Source: Cybersecurity News
CISA added CVE-2022-0492 to its Known Exploited Vulnerabilities catalog on 2 June after confirming active exploitation in the wild — a four-year-old Linux kernel privilege escalation flaw, public for roughly three years, that attackers have only now started using. Kaspersky reported the exploitation a day before CISA's alert, without naming the attackers or victims.
The flaw (CVSS 7.8) targets the cgroups v1 release_agent feature, allowing attackers to execute arbitrary commands with root-level access — and potentially break out of containerized environments entirely. It's especially dangerous in cloud-native setups where containers rely on cgroups for resource isolation.
The federal remediation deadline was 5 June. Everyone else should move fast too: update the kernel, disable unprivileged user namespaces where you can, and audit container configurations for suspicious cgroup activity.
Source: Cybersecurity News
CISA added a critical vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 to its Known Exploited Vulnerabilities catalog on 3 June, giving federal agencies until 6 June to patch. The flaw, CVE-2026-45247, carries a near-perfect CVSS score of 9.8 and requires no authentication to exploit.
Attackers inject malicious PHP objects through the CacheWarmer cookie, which deserializes them without class restrictions and escalates to full remote code execution on Magento and Adobe Commerce servers. Imperva reports active exploitation began shortly after public disclosure on May 26.
Thousands of stores are at risk — any running a version before 1.11.12 should update immediately. Given exploitation started over a week ago, also check your logs for CacheWarmer cookies carrying base64-encoded serialized objects, which typically begin with "Tz," "Qz" or "YT."
Source: SecurityWeek
CISA added a critical vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 to its Known Exploited Vulnerabilities catalog on 3 June, giving federal agencies until 6 June to patch. The flaw, CVE-2026-45247, carries a near-perfect CVSS score of 9.8 and requires no authentication to exploit.
Attackers inject malicious PHP objects through the CacheWarmer cookie, which deserializes them without class restrictions and escalates to full remote code execution on Magento and Adobe Commerce servers. Imperva reports active exploitation began shortly after public disclosure on May 26.
Thousands of stores are at risk — any running a version before 1.11.12 should update immediately. Given exploitation started over a week ago, also check your logs for CacheWarmer cookies carrying base64-encoded serialized objects, which typically begin with "Tz," "Qz" or "YT."
Source: SecurityWeek
CISA added a high-severity SolarWinds Serv-U flaw, CVE-2026-28318 (CVSS 7.5), to its Known Exploited Vulnerabilities catalog on June 5, 2026 — the same day SolarWinds shipped the fix — with a remediation deadline of June 19 for federal agencies.
The vulnerability lets unauthenticated attackers crash Serv-U file transfer software remotely by sending a malicious POST request with a Content-Encoding: deflate header — no credentials required. That zero-privilege, network-accessible attack path makes it especially dangerous for organizations with Serv-U exposed to the internet. SolarWinds' own advisory made no mention of exploitation, and it's still unclear whether the flaw was used as a zero-day.
The fix is Serv-U 15.5.4 Hotfix 1, and the affected releases — 15.4.2, 15.5 and 15.5.1 — have already reached end of life, so some organisations will need an upgrade rather than a patch. Restrict Serv-U exposure behind a firewall or VPN, and monitor logs for suspicious POST requests.
Source: Cybersecurity News
CISA added a high-severity SolarWinds Serv-U flaw, CVE-2026-28318 (CVSS 7.5), to its Known Exploited Vulnerabilities catalog on June 5, 2026 — the same day SolarWinds shipped the fix — with a remediation deadline of June 19 for federal agencies.
The vulnerability lets unauthenticated attackers crash Serv-U file transfer software remotely by sending a malicious POST request with a Content-Encoding: deflate header — no credentials required. That zero-privilege, network-accessible attack path makes it especially dangerous for organizations with Serv-U exposed to the internet. SolarWinds' own advisory made no mention of exploitation, and it's still unclear whether the flaw was used as a zero-day.
The fix is Serv-U 15.5.4 Hotfix 1, and the affected releases — 15.4.2, 15.5 and 15.5.1 — have already reached end of life, so some organisations will need an upgrade rather than a patch. Restrict Serv-U exposure behind a firewall or VPN, and monitor logs for suspicious POST requests.
Source: Cybersecurity News
A critical vulnerability in the Everest Forms Pro WordPress plugin is under active attack, with Wordfence blocking over 29,300 exploitation attempts since April 13, 2026 — 17,900 of them on a single day, May 16. The flaw, CVE-2026-3300, scores a near-perfect 9.8 on the CVSS scale and affects all versions up to 1.9.12.
The bug lives in the plugin's "Complex Calculation" feature, where user inputs are concatenated into PHP code and passed to eval() without the single quotes being escaped. Attackers don't need credentials — they just submit a crafted form field. Sites that don't use Complex Calculation aren't exposed.
Most attacks aim to create rogue admin accounts via WordPress's own wp_insert_user() function, with one common payload creating a user named "diksimarina" — the foothold for uploading webshells and planting backdoors.
A patch (version 1.9.13) has been available since March 18. Update immediately.
Source: Cybersecurity News
A critical vulnerability in the Everest Forms Pro WordPress plugin is under active attack, with Wordfence blocking over 29,300 exploitation attempts since April 13, 2026 — 17,900 of them on a single day, May 16. The flaw, CVE-2026-3300, scores a near-perfect 9.8 on the CVSS scale and affects all versions up to 1.9.12.
The bug lives in the plugin's "Complex Calculation" feature, where user inputs are concatenated into PHP code and passed to eval() without the single quotes being escaped. Attackers don't need credentials — they just submit a crafted form field. Sites that don't use Complex Calculation aren't exposed.
Most attacks aim to create rogue admin accounts via WordPress's own wp_insert_user() function, with one common payload creating a user named "diksimarina" — the foothold for uploading webshells and planting backdoors.
A patch (version 1.9.13) has been available since March 18. Update immediately.
Source: Cybersecurity News
A debug setting accidentally left enabled in production releases of six Microsoft Android apps — Word, Excel, PowerPoint, OneNote, Loop and 365 Copilot — exposed billions of users to potential account takeover. Researchers at Enclave, who named the issue FlagLeft, found the flaw disabled a security check that prevents untrusted apps from grabbing Microsoft authentication tokens.
Any malicious Android app could silently request and receive login tokens, giving attackers access to emails, Teams messages and files. Worse, the stolen tokens were long-lived FOCI (Family of Client IDs) tokens that can be refreshed indefinitely and look identical to legitimate activity in logs, making detection nearly impossible.
Microsoft has patched all six apps, assigning CVE-2026-41100, CVE-2026-41101, CVE-2026-41102 and CVE-2026-42832. There's no confirmation the flaw was exploited before it was found — but if you have any of these apps installed, update them now.
Source: Dark Reading
A debug setting accidentally left enabled in production releases of six Microsoft Android apps — Word, Excel, PowerPoint, OneNote, Loop and 365 Copilot — exposed billions of users to potential account takeover. Researchers at Enclave, who named the issue FlagLeft, found the flaw disabled a security check that prevents untrusted apps from grabbing Microsoft authentication tokens.
Any malicious Android app could silently request and receive login tokens, giving attackers access to emails, Teams messages and files. Worse, the stolen tokens were long-lived FOCI (Family of Client IDs) tokens that can be refreshed indefinitely and look identical to legitimate activity in logs, making detection nearly impossible.
Microsoft has patched all six apps, assigning CVE-2026-41100, CVE-2026-41101, CVE-2026-41102 and CVE-2026-42832. There's no confirmation the flaw was exploited before it was found — but if you have any of these apps installed, update them now.
Source: Dark Reading