The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. The
ShinyHunters Claims Council of Europe Hack
The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.
The post ShinyHunters Claims Council of Europe Hack appeared first on SecurityWeek.
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
When a site administrator was logged in as the file loaded, the code created an admin account under the attacker’s control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.
The post FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service appeared first on SecurityWeek.
Maine Disables Data Breach Portal Due to Fake Submissions
Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action.
The post Maine Disables Data Breach Portal Due to Fake Submissions appeared first on SecurityWeek.
Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
“These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs,” Group-IB
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad
FBI disrupts massive AI-powered phishing service using a million URLs
Ex-school district employee jailed for hacks on former employer
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.
The post NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks appeared first on SecurityWeek.
