- G7 tells businesses to get ready for quantum cybersecurity threats
September 7, 2026
The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors. Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data ...
- Dissecting a PHP web server rootkit
September 7, 2026
SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side ...
- Ransomware hackers dump 1.4 million stolen records from German government
September 7, 2026
A cybercriminal group known as Rhysida allegedly broke into the network of Berlin’s state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web. According to multiple sources, the group first claimed responsibility for the attack on an ...
- US military disabled ad tracking on troops’ devices following reports of targeted attacks
September 4, 2026
The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, ...
- Angry Birds: Toy Ghouls’ new toys
September 4, 2026
Kaspersky continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In ...
- Free streaming boxes may be routing criminal traffic through your home
September 4, 2026
“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. An earlier report identified CyberFlix ...
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
September 3, 2026
We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. Read more… Source: Palo Alto Unit 42 Sign up for the Cyber Security Review Newsletter The latest cyber security news and insights delivered ...
- 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm
September 3, 2026
Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people – both patients and employees. In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. ...
- SonicWall’s SMA1000 boxes under active attack again
September 2, 2026
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no ...
- 153M+ driver’s licenses for sale on new dark web platform
September 2, 2026
A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports. The trove of driver’s license scans reported by ...
