FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks

WhatsApp told SecurityWeek that it linked the exploited FreeType vulnerability CVE-2025-27363 to a Paragon exploit.

The post FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

Cloudflare Tunnels Abused in New Malware Campaign

A threat actor is abusing Cloudflare Tunnels for the delivery of a Python loader as part of a complex infection chain.

The post Cloudflare Tunnels Abused in New Malware Campaign appeared first on SecurityWeek.

SecurityWeek – ​Read More

161,000 People Impacted by Krispy Kreme Data Breach

Krispy Kreme is sharing more information on the data breach resulting from the ransomware attack targeting the company in 2024. 

The post 161,000 People Impacted by Krispy Kreme Data Breach appeared first on SecurityWeek.

SecurityWeek – ​Read More

67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers

Cybersecurity researchers have uncovered a new campaign in which the threat actors have published more than 67 GitHub repositories that claim to offer Python-based hacking tools, but deliver trojanized payloads instead.
The activity, codenamed Banana Squad by ReversingLabs, is assessed to be a continuation of a rogue Python campaign that was identified in 2023 as targeting the Python Package

The Hacker News – ​Read More

Hackers Access Legacy Systems in Oxford City Council Cyberattack

Personal data of former and current council workers, including election staff, may have been accessed by hackers.

The post Hackers Access Legacy Systems in Oxford City Council Cyberattack appeared first on SecurityWeek.

SecurityWeek – ​Read More

Banana Squad Hides Data-Stealing Malware in Fake GitHub Repositories

Banana Squad hid data-stealing malware in fake GitHub repos posing as Python tools, tricking users and targeting sensitive info like browser and wallet data.

Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – ​Read More

New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft

Cybersecurity researchers have exposed the inner workings of an Android malware called AntiDot that has compromised over 3,775 devices as part of 273 unique campaigns.
“Operated by the financially motivated threat actor LARVA-398, AntiDot is actively sold as a Malware-as-a-Service (MaaS) on underground forums and has been linked to a wide range of mobile campaigns,” PRODAFT said in a report

The Hacker News – ​Read More

Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War

Israel-linked Predatory Sparrow hackers torched more than $90 million at Iran’s largest cryptobank as Israel-Iran cyberwar escalates.

The post Predatory Sparrow Burns $90 Million on Iranian Crypto Exchange in Cyber Shadow War appeared first on SecurityWeek.

SecurityWeek – ​Read More

Scammers Insert Fake Support Numbers on Real Apple, Netflix, PayPal Pages

Cybercriminals are injecting fake support phone numbers onto official sites like Bank of America and Netflix. Learn how ‘search parameter injection’ scams work and protect yourself now.

Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – ​Read More

DOJ moves to seize $225 million in crypto stolen by scammers

A civil forfeiture complaint was filed in U.S. District Court for the District of Columbia this week, where investigators from the FBI and U.S. Secret Service said they used blockchain analysis to trace the funds back to fraud schemes perpetrated by actors in the Philippines.

The Record from Recorded Future News – ​Read More