news
Breaking Cyber News From Cyberint
Breaking news feed of the latest cyber incidents, breaches, vulnerabilities, malware, ransomware and so much more.
- All Items
- Middle East
- Israel
- Data Encrypted For Impact
- Business Services
- Handala
- Asia
- Jobinfo
- Shelter Locations In Israel
- Saudi Games
- Retail
- Cyber Fattah Team
- Saudi Arabia
- Ben Horin & Alexandrovitz
- Zachary Levi And Sons - Construction
- Sivim It
- Government
- Kibbutz Almog
- Saban Brands Israel
- Manufacturing
- Mprest
- Digitalghost
- The Knesset
- Evil_Byte
- Nobitex
- Gonjeshke Darande
- exclusive
- South-Eastern Asia
- Kimia Farma
- Sentap
- Chemicals And Allied Products
- Indonesia
- Transportation
- Northern Europe
- Scania
- Sweden
- Europe
- Hensi
- Media
- Tbn Israel
- Weizmann Institute Of Science
- Education
- Resistancetrench
- Israeli Air Force
- Israel Antiquities Authority
- Dienet
- North America
- CVE-2025-24016
- Wazuh
- United States
- Cve-2025-24016
- Mirai
- Clayoxtymus1337
- Epsilor Electric Fuel
- Technology
- Southern Asia
- Advanced Weapons And Equipment India
- India
- More_Eggs
- Fin6
- Cryptocurrency
- Alex Lab
- Critical Infrastructures
- Edf Energy
- United Kingdom
- Zoldyck
- Unix Shell
- Credentials In Files
- Spectrum
- Amos
- Disable Or Modify Tools
- Spearphishing Link
- Ingress Tool Transfer
- Match Legitimate Name Or Location
- Sudo And Sudo Caching
- Telecommunications
- Israel Defense Forces
- Food And Kindred Products
- Ghna
- Coca-Cola Europacific Partners
- Southern Europe
- Automotive
- Italy
- Locauto
- Spain
- Whitecoat
- Mercadona
- Wow Health Solutions
- Healthcare
- Ups
- Rip_Real_World
- Cyprus Airways
- Netsupport Rat
- Illeak
- Tel Aviv University
- Desec0X
- Cyberlock
- Lucky_Gh0$T
- Yashma
- Unc6032
- Numero
- Chaos
- Deloitte
- 303
- Gucci
- Command And Scripting Interpreter
- Windows Credential Manager
- Virtualization/Sandbox Evasion
- Credentials From Web Browsers
- Input Capture
- System Information Discovery
- Credentials From Password Stores
- User Execution
- Phishing
- Obfuscated Files Or Information
- Data From Local System
- File And Directory Discovery
- Drive-By Compromise
- Exfiltration Over C2 Channel
- Password Managers
- Eddiestealer
- Screen Capture
- W_Tchdogs
- Australia And New Zealand
- Superloop
- Australia
- Network Service Discovery
- Smb/Windows Admin Shares
- Deploy Container
- Resource Hijacking
- Remote System Discovery
- Escape To Host
- Exploitation For Client Execution
- Change Default File Association
- Web Protocols
- Exploit Public-Facing Application
- Lateral Tool Transfer
- External Remote Services
- Docker
- Eastern Europe
- Cameleon
- Venom Rat
- Romania
- Financial Theft
- Bitdefender
- Cisco
- Macao Special Administrative Region
- Cve-2023-20118
- CVE-2023-20118
- Eastern Asia
- Vicioustrap
- Uat-6382
- Trimble
- Tetraloader
- CVE-2025-0944
- Cve-2025-0944
- China
- Reflective Code Loading
- Obfuscated Files Or Information: Encrypted Or Encoded Data
- Scheduled Task
- Rundll32
- Masquerade Task Or Service
- File Deletion
- Dynamic-Link Library Injection
- Powershell
- Valleyrat
- Regsvr32
- Silver Fox
- Process Discovery
- Malicious File
- Trickbot
- Bumblebee
- Warmcookie
- Danabot
- Qakbot
- Cetus
- Purehvnc
- Bytebreaker
- Latin America And The Caribbean
- Viralgod
- Telcel
- Mexico
- Peter Green Chilled
- Cellcom
-
Jun 22, 2025
Surveillance Firm Saban Systems Alleged Breached by Handala
On June 19, 2025, the pro-Palestinian hacktivist group Handala claimed responsibility for a breach targeting Israeli surveillance technology provider Saban Systems. The group alleges to have exfiltrated 254GB of confidential data and has released over 50,000 internal documents as proof of compromise.
-
Jun 16, 2025
Data Breach Exposes Over 1 Million Records from Indonesian Pharmacy Giant Kimia Farma
A threat actor named "sentap" is offering a 40GB dataset stolen from "Kimia Farma," Indonesia’s leading state-owned pharmacy network, on the dark forum "darkforumes.me." The leak includes over 1 million records containing detailed pharmaceutical inventory, sales transactions, discount schemes, and high-risk stock information collected between March and July 2024. Validated against Kimia Farma’s ERP system, the data reveals sensitive national-level supply chain and market insights valuable for market analysis, cyber intelligence, and social engineering. The dataset is sold for $10,000 USD in Bitcoin or Monero, with an escrow service ensuring transaction security.
-
Jun 11, 2025
Fin6 Leverages Fake Resumes for Malware Delivery
The financially motivated threat actor Fin6 has been observed using fake resumes hosted on Amazon Web Services (AWS) to deliver the malware family known as More_Eggs. By posing as job seekers on platforms like LinkedIn and Indeed, Fin6 builds rapport with recruiters and sends phishing messages that lead to malware downloads. More_Eggs, developed by another cybercrime group called Golden Chickens, is a JavaScript-based backdoor capable of credential theft and system access. Fin6 has a history of targeting e-commerce sites to steal payment card data and has been operational since 2012.
-
May 22, 2025
Malware Campaign Exploiting Kling AI to Target Users
A new malware campaign has been identified that uses counterfeit Facebook pages and sponsored ads to lure users to fake websites impersonating Kling AI, an AI-powered platform. The campaign, first detected in early 2025, tricks victims into downloading a malicious file that installs a remote access trojan (RAT) on their systems, allowing attackers to steal sensitive data. The operation is linked to Vietnamese threat actors, who have been increasingly using social engineering tactics to exploit the popularity of generative AI tools. The campaign highlights the growing trend of sophisticated social media-based attacks targeting unsuspecting users.
-
May 21, 2025
Threat Actor Claims to Have Scraped Hundreds of Millions of Facebook Records
In May 2025, a threat actor named ByteBreaker claimed to have scraped accounts from Facebook. According to the threat actor, hundreds of millions of records belonging to Facebook's users were taken, including various types of data scraped by abusing one of their APIs.