• Three well-known threat groups have consolidated into a unified cybercriminal entity that represents a significant shift in underground tactics.

    Scattered LAPSUS$ Hunters (SLH) emerged in early August 2025 as a federated alliance combining Scattered Spider, ShinyHunters, and LAPSUS$, creating what researchers describe as the first consolidated alliance among mature cybercriminal clusters.

    Channel announcement referencing ‘Sh1nySp1d3r’ as a proposed ransomware offering (Source – Trustwave)

    This consolidation marks a deliberate strategic move within the cybercriminal underground, where established threat actors are merging reputational assets and operational capabilities to create a more formidable collective.

    The alliance entered the threat landscape through Telegram, leveraging the platform as its primary operational base and marketing channel.

    Telegram channels and activity periods (Source – Trustwave)

    Unlike traditional cybercriminal actors who maintain minimal visibility, SLH adopted a highly performative approach, combining sensationalist messaging with proof-of-compromise announcements and public engagement strategies.

    The group’s first verified channel appeared on August 8, 2025, establishing what would become a consistent pattern of theatrical branding and coordinated communication that blurs the line between attention-driven hacktivism and financially motivated cybercrime.

    Since its inception, Trustwave analysts have noted that the group has demonstrated remarkable operational persistence despite repeated platform disruptions.

    Telegram channels have been removed and recreated at least sixteen times under varying name iterations, yet SLH consistently re-established its presence within hours, signaling extraordinary determination to maintain public visibility and control over narrative construction.

    Trustwave researchers identified sophisticated technical capabilities underlying SLH’s operations.

    Technical Infrastructure and Exploitation Capabilities

    The collective exhibits genuine exploit development and acquisition competencies, particularly targeting high-value enterprise systems including CRM platforms, Database Management Systems, and SaaS infrastructure.

    Members leverage AI-automated vishing campaigns combined with credential harvesting techniques, followed by systematic lateral movement for privilege escalation and rapid data exfiltration.

    Notable vulnerabilities tied to SLH operations include CVE-2025-61882 (Oracle E-Business Suite) and claims of exploitation targeting CVE-2025-31324 (SAP NetWeaver), suggesting capability development or code acquisition from external sources.

    Code snippets circulated within channels demonstrate legitimate exploit proof-of-concepts, while documented local privilege escalation techniques show command execution access to sensitive system files.

    This technical arsenal reflects convergence of skills drawn from the three merged organizations, enabling simultaneous deployment of social engineering, exploitation, and extortion methodologies that amplify operational impact across their targets and enhance their market positioning within the cybercriminal ecosystem.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Three Infamous Cybercriminal Groups Form a New Alliance Dubbed ‘Scattered LAPSUS$ Hunters’ appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated Remote Access Trojan (RAT) is actively targeting North Korean Human Rights Defenders (HRDs) through a campaign leveraging stolen code-signing certificates to evade antivirus detection. The newly discovered “EndClient RAT,” delivered via a malicious Microsoft Installer package disguised as “StressClear.msi,” represents a significant escalation in threats against civil society organizations working on North Korean […]

    The post EndClient RAT Leverages Compromised Code-Signing to Slip Past Antivirus appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  •  Authorities across nine countries executed a coordinated crackdown on one of the largest credit card fraud networks ever dismantled. Operation Chargeback, led by German prosecutors and the Bundeskriminalamt, brought down criminal organizations responsible for defrauding over 4.3 million cardholders globally. The investigation, which began in December 2020, resulted in 18 arrest warrants and more than […]

    The post Authorities Dismantle Large-Scale Credit Card Fraud Scheme Affecting 4.3 Million Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hyundai AutoEver America has disclosed a significant data breach that compromised sensitive personal information of customers, including Social Security numbers and driver’s license details.

    The cybersecurity incident highlights growing concerns about data protection in the automotive technology sector.​

    Hyundai AutoEver America discovered the cyber incident on March 1, 2025, when unauthorized activity was detected within its information technology environment.

    The company immediately launched an investigation with external cybersecurity experts to assess the full scope of the breach.

    Forensic analysis revealed that unauthorized access began on February 22, 2025, and the last observed malicious activity occurred on March 2, 2025, spanning approximately 9 days of potential data exposure.​

    Compromised Personal Information

    The breach exposed a range of sensitive personal data belonging to affected individuals. According to the official breach notification, compromised information included full names along with additional data elements that could enable identity theft.

    While the notice template does not specify exact numbers, the company confirmed that Rhode Island residents were among those impacted.

    The exposed data includes Social Security numbers, driver’s license information, and other personally identifiable information that could be exploited for fraudulent purposes.​

    Upon discovering the intrusion, Hyundai AutoEver immediately terminated the unauthorized third party’s access to affected systems and engaged specialized cybersecurity firms to conduct a comprehensive investigation.

    The company also coordinated with law enforcement agencies throughout the response process. The extensive nature of the incident required significant time and resources to analyze forensic data and determine which information was accessed.​

    Hyundai AutoEver is offering affected customers complimentary two-year credit monitoring services through Epiq Privacy Solutions, including three-bureau credit monitoring and identity protection.

    Affected individuals are encouraged to remain vigilant by monitoring account statements, reviewing credit reports regularly, and considering fraud alerts or security freezes to prevent unauthorized credit applications.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hyundai AutoEver Confirms Data Breach Exposing Users’ Personal Information and SSNs appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity landscape stands at a critical inflection point as organizations prepare for unprecedented challenges in 2026.

    Google Cloud researchers have released their annual Cybersecurity Forecast, revealing a stark reality: threat actors are transitioning from experimenting with advanced technologies to embedding them as standard operational tools.

    This shift represents a fundamental change in how attacks are orchestrated, detected, and defended against across enterprise networks.

    The upcoming year will be defined by rapid evolution on both sides of the security equation. While defenders prepare their defenses, adversaries are actively reshaping their tactics with emerging technologies.

    Google Cloud analysts identified multiple threat vectors that will dominate the threat landscape, ranging from enterprise-targeted attacks to nation-state operations designed for long-term espionage and strategic advantage.

    Google Cloud analysts and researchers noted that threat actors have moved decisively from using advanced technologies as occasional tactical advantages to employing them as the foundation of their operations.

    This normalization of sophisticated attack methodologies signals a maturation in the threat ecosystem, where scale and speed define success. Organizations must fundamentally rethink their defensive postures to address this reality.

    The most immediate concern centers on how threat actors are weaponizing modern technologies. Prompt injection attacks represent a critical emerging threat that manipulates systems to bypass security restrictions and execute hidden attacker commands.

    These targeted assaults on enterprise AI systems will accelerate significantly, exploiting the growing reliance on machine learning-driven platforms.

    Additionally, voice cloning technology enables hyperrealistic impersonations of executives and IT personnel, making traditional social engineering far more convincing and difficult to identify.

    Infrastructure vulnerabilities compound these concerns. Virtualization layers, historically overlooked by mature security programs, have become critical blind spots.

    Adversaries are systematically pivoting toward underlying virtualization infrastructure, where a single successful compromise grants complete control over an entire digital estate and can render hundreds of systems inoperable within hours.

    The Multi-Layered Threat Landscape

    The convergence of ransomware, data theft, and extortion continues to represent the most financially damaging cybercrime category.

    Organizations face pressure from threat actors exploiting zero-day vulnerabilities to exfiltrate massive datasets and hold systems hostage.

    Third-party providers remain prime targets, as compromising supply chain partners grants attackers access to numerous downstream customers with a single successful breach.

    Beyond cybercrime, nation-state operations are intensifying. China’s cyber operations maintain unprecedented volume and sophistication, targeting edge devices and exploiting zero-day vulnerabilities with strategic precision.

    Russian cyber operations are undergoing fundamental restructuring, shifting from tactical Ukraine-focused activities toward long-term strategic capability development.

    North Korean groups continue financing regime activities through targeted financial operations, while Iranian actors maintain resilience across espionage, disruption, and semi-deniable hacktivist activities.

    Organizations must adopt proactive threat intelligence frameworks to stay ahead of these evolving challenges and implement multi-layered defense strategies that address both conventional and emerging attack vectors.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Cybersecurity Forecast 2026 – Google Warns Threat Actors Use AI to Enhance Speed and Effectiveness appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The threat actor known as Curly COMrades has been observed exploiting virtualization technologies as a way to bypass security solutions and execute custom malware. According to a new report from Bitdefender, the adversary is said to have enabled the Hyper-V role on selected victim systems to deploy a minimalistic, Alpine Linux-based virtual machine. “This hidden environment, with its lightweight

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Google Threat Intelligence Group (GTIG) have identified a significant shift in how threat actors are leveraging artificial intelligence in their operations. The discovery of experimental malware called PROMPTFLUX marks a watershed moment in cyber threats, demonstrating that attackers are no longer using AI merely to boost productivity they are now deploying AI-enabled […]

    The post Google Warns of PROMPTFLUX Malware That Uses Gemini API for Self-Rewriting Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated Android-based NFC relay attack dubbed NGate has emerged as a serious threat to banking security across Poland, targeting financial institutions and their customers through coordinated social engineering and technical exploitation.

    Cert.PL analysts identified new malware samples in recent months that orchestrate unauthorized ATM cash withdrawals without requiring physical theft of payment cards.

    Rather than stealing cards directly, threat actors employ a relay mechanism that captures NFC communication from victims’ Android phones and forwards it to attacker-controlled devices positioned at ATMs.

    The attack chain combines multiple deception tactics to succeed. Victims initially receive phishing messages via email or SMS claiming technical problems or security incidents, directing them to install a fake banking application.

    Following installation, scammers impersonate bank employees through phone calls requesting identity verification, further legitimizing the fraudulent application.

    The victim is then prompted to tap their physical payment card against the phone for verification purposes while entering their PIN through an on-screen keypad.

    Cert.PL analysts noted the sophisticated technical architecture underlying NGate’s operations.

    Once the victim taps their card, the malware captures all NFC exchanges identical to legitimate terminal communications and transmits them to the attacker’s C2 server operating at IP 91.84.97.13:5653.

    Payment verification (Source - Cert.PL)
    Payment verification (Source – Cert.PL)

    The attacker’s device then replays this data to the ATM, and with both the card information and PIN already compromised, they execute unauthorized cash withdrawals.

    Infection mechanism

    The infection mechanism reveals advanced evasion techniques. The application registers itself as a Host Card Emulation (HCE) payment service on Android, enabling it to function as a virtual card.

    Configuration data containing the C2 server address remains hidden in an encrypted asset bundled within the application.

    This encryption employs the SHA-256 hash of the APK signing certificate as an XOR key, derived through JNI function calls that retrieve certificate data from the Android PackageManager.

    Technical analysis shows the app establishes cleartext TCP connections using a framed protocol structure containing length markers and opcodes.

    The malware captures card data including PAN, expiration dates, AIDs, and APDUs before immediately exfiltrating PIN information through dedicated protocol messages.

    Users can protect themselves by downloading banking applications exclusively from official stores and verifying unexpected bank calls through direct contact with their financial institution.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency has issued a critical warning regarding a newly identified vulnerability affecting Gladinet CentreStack and Triofox platforms.

    The flaw, tracked as CVE-2025-11371, exposes sensitive system files and directories to unauthorized external access, potentially compromising organizations relying on these file-sharing solutions for business operations.

    These files or directories accessible to external parties allow attackers to discover and retrieve confidential system information without proper authentication.

    The vulnerability stems from improper access controls within the affected applications, classified under CWE-552, which specifically addresses issues where sensitive resources remain accessible to unintended actors.

    Security researchers have confirmed active exploitation attempts targeting vulnerable deployments, prompting immediate federal agency intervention.

    Understanding the Exposure and Risk

    The vulnerability CVE-2025-11371 creates a significant exposure window for attackers attempting to gather reconnaissance data or launch follow-up attacks.

    By accessing exposed directories, threat actors can identify system configurations, user information, and potentially hardcoded credentials information commonly leveraged in multi-stage attack chains.

    While the vulnerability has not yet been publicly linked to ransomware campaigns, cybersecurity experts warn that the accessible information could enable devastating ransomware deployments.

    CVE IDVulnerability TypeAffected Products
    CVE-2025-11371Files or Directories Accessible to External PartiesGladinet CentreStack, Triofox

    CISA has assigned this vulnerability a remediation deadline of November 25, 2025, providing organizations approximately three weeks to implement protective measures.

    The agency recommends three primary mitigation strategies depending on organizational capability and risk tolerance. First, organizations should immediately apply all vendor-supplied patches and security updates.

     Second, federal agencies managing cloud services should implement controls aligned with Binding Operational Directive 22-01, which mandates specific security baselines for government cloud infrastructure.

    Third, organizations unable to patch or implement equivalent protections are advised to discontinue using the product entirely.

    Organizations currently deploying Gladinet CentreStack or Triofox should prioritize verification of their current software versions and check vendor advisories for available patches.

    Network administrators should review access logs to identify any suspicious file access attempts or unusual data queries.

    Implementing network segmentation, restricting external access to administrative interfaces, and deploying enhanced monitoring solutions can provide interim protection while patches are applied.

    The vulnerability underscores ongoing challenges with cloud-based file-sharing platforms and the critical importance of maintaining updated security postures.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of Gladinet CentreStack and Triofox Files Vulnerability Exploited in Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hyundai AutoEver America, LLC has formally confirmed a significant data breach that compromised sensitive customer information. The automotive software provider disclosed the incident through official breach notification letters sent to affected individuals, revealing that attackers gained unauthorized access to names, Social Security numbers, and driver’s license information during a coordinated cyber attack.​ The unauthorized activity […]

    The post Hyundai AutoEver Confirms Data Breach Exposing Personal Data, Including SSNs and License Info appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶