Trend Micro researchers are warning that bad actors are exploiting the weakest points in S3 environments: misconfigurations, leaked access keys, and relaxed encryption controls. Their latest analysis tracks five emerging ransomware variants built specifically to break, lock, or wipe cloud storage. The playbook is different from traditional ransomware. Rather than dropping malware and encrypting files on a machine, attackers are weaponizing AWS’s features. Several variants use the Key Management Service or Server-Side Encryption to encrypt S3 objects at scale. One strain employs default AWS KMS keys to secure bucket data and then schedules the key for deletion, providing victims with…
Kirsten Doyle
A cluster of major websites (including X and ChatGPT) went down for large parts of Tuesday after Cloudflare, the backbone beneath much of the modern web, tripped over its own wiring. Shortly after 11:30 GMT, reports began to stack up on Downdetector. Thousands of users. Dozens of services. A quiet drumbeat turning into a roar. Pages froze. Apps hung. Routine clicks suddenly felt like walking through mud. Cloudflare later admitted the fault was theirs. A configuration file meant to sift hostile traffic misbehaved, triggering a crash in the software that keeps its wider network flowing. In the company’s words, it was…
Logitech has confirmed it suffered a data-theft breach tied to a zero-day in a third-party platform, days after the Clop extortion gang published almost 1.8 terabytes of data allegedly stolen from the company. In a Form 8-K filed with the U.S. Securities and Exchange Commission, the consumer-electronics maker said it “recently experienced a cybersecurity incident relating to the exfiltration of data,” adding that the attack did not impact products, business operations, or manufacturing. Logitech says the stolen data “likely included limited information about employees and consumers and data relating to customers and suppliers,” and that it does not believe national ID numbers or payment…
A new wave of phishing attacks is exploiting Microsoft Entra’s guest user invitation system, turning a legitimate collaboration tool into a weapon for social engineering and credential theft, Cyber Security News reports. Dubbed a TOAD (Telephone Oriented Attack Delivery) campaign, the attacks combine cloud-based account management with traditional phone scams, demonstrating a dangerous evolution in hybrid cybercrime tactics. Security researcher Michael Taggart uncovered the campaign after spotting multiple phishing operations abusing Entra’s guest invitation process. He said malefactors are weaponizing a trusted Microsoft service to bypass email security filters, combining cloud infrastructure abuse with classic phone scams, which makes detection extremely difficult. The campaign relies on Microsoft’s…
A Chinese state-sponsored cybercriminal group is believed to be behind what researchers say is the first documented cyber-espionage operation executed largely by AI rather than humans. The campaign, detected in mid-September, used Anthropic’s Claude Code tool to probe and infiltrate around thirty organisations across tech, finance, chemicals, and government. According to Anthropic, the attackers leaned heavily on AI’s “agentic” features, using the model not as an assistant but as the primary operator of the campaign. The group broke Claude’s guardrails by feeding it fragmented, context-free prompts and posing as a legitimate cybersecurity firm conducting defensive testing. Once jailbroken, the model performed reconnaissance, identified high-value data, wrote…
Notorious ransomware gang Clop is back with another bold claim, this time insisting it hacked “the NHS,” The Register reports. Which part of the sprawling UK healthcare system? The gang doesn’t say. It listed only the NHS.uk domain on its leak site on November 11 and published no data. For a system made up of hundreds of trusts, agencies, and regional bodies, that’s not much to go on. The extortion crew has spent recent months exploiting an Oracle E-Business Suite zero-day to hit private organizations. Adding “the NHS” to its victim roster sounds dramatic, but the lack of specifics raises a simple question: Does Clop…
Authorities have delivered another major hit to global cybercrime infrastructure, with more than 1,025 servers linked to three prolific malware operations taken down in the latest phase of Operation Endgame. Coordinated from Europol’s headquarters in The Hague between 10 and 13 November, the action targeted the infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium. All of these are key enablers behind large-scale international cyberattacks. A suspect tied to VenomRAT was arrested earlier this month in Greece. Millions of Stolen Credentials Officials say the dismantled infrastructure had infected hundreds of thousands worldwide and had siphoned millions of stolen credentials. Investigators believe the main…
OpenAI is fighting a court order that would force it to hand over 20 million anonymized ChatGPT conversations as part of the New York Times’ copyright lawsuit, Reuters reports. In a filing on Wednesday, the company warned that complying would expose private user chats that have nothing to do with the case, calling it a “speculative fishing expedition.” Reuters said OpenAI argued 99.99% of the requested logs bear no relevance to the copyright claims. The Times and other outlets say they need the chats to test whether their articles were reproduced and to counter OpenAI’s allegation that they “hacked” the model…
UK insurers paid out nearly £200 million to help businesses recover from cyber incidents last year, according to new figures from the Association of British Insurers (ABI). This is a steep increase that highlights the growing impact of digital threats on the UK economy. The ABI’s latest data shows £197 million was paid out in 2024, a 230% increase year-on-year, with payouts up £138 million from 2023. More than half of all claims (51%) were linked to malware and ransomware, compared with 32% a year earlier, evidence of how increasingly sophisticated attacks are inflicting greater operational and financial damage. The…
Cybercrooks are getting an upgrade. KnowBe4 Threat Lab has uncovered Quantum Route Redirect, a new phishing platform that’s upping the ante by making sophisticated attacks almost effortless to launch. The tool, now circulating globally, streamlines what was once a technically complex phishing setup into a single click. Attackers using it can automatically evade certain email security filters, impersonate trusted brands, and harvest Microsoft 365 credentials at scale. The Impact is Spreading Fast Analysts first detected Quantum Route Redirect in August through KnowBe4’s PhishER Plus and Defend platforms. Since then, it’s been linked to phishing campaigns spanning 90 countries. Most victims…
