The Berlin Commissioner for Data Protection has reported the AI app DeepSeek to Apple and Google for breaching European data protection laws. The watchdog says the app illegally transfers personal data from German users to servers in China, without the safeguards required under the GDPR. At the heart of the issue is DeepSeek, a multifunctional chatbot developed by Hangzhou DeepSeek Artificial Intelligence, based in Beijing. The company operates the service via German-language apps available on both the Google Play Store and Apple App Store. For all its penetration of the European market, DeepSeek does not have an EU physical presence. …
Kirsten Doyle
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), together with the FBI, NSA, and Defense Cyber Crime Center, have issued a joint alert urging U.S. critical infrastructure operators to be on guard. Despite the news of a Middle Eastern ceasefire and negotiations, Iranian-aligned cyberhackers and hacktivist groups remain active, and remain a threat. The warning is straightforward: Iranian cyber threat actors are highly likely to attack American networks in the very near future. Their preferred tactics remain the same, disruption, defacement, data leaks. What is new is that their focus is shifting to infrastructure and supply chains, particularly those linking…
Social media has become a daily part of life for billions worldwide. It connects us, informs us, and entertains us. Yet as artificial intelligence (AI) grows more advanced, the risks we face online have multiplied. Deepfakes, AI-generated scams, and new attack methods exploit our trust and carelessness. The importance of knowing about these threats and how they work and modifying our online habits accordingly cannot be overstated. We talked to cybersecurity experts and asked them how social media users can protect themselves in such an unpredictable and dynamic landscape. They shared practical advice on detecting AI trickery, securing accounts with…
A British national accused of operating under the alias “IntelBroker” has been charged in the U.S. with a sweeping cybercrime campaign that caused more than $25 million in damages worldwide. Kai West, 25, allegedly led a prolific hacking operation that targeted over 40 organizations, including a U.S. telecom provider, a municipal health agency, and an internet service company. The scheme, prosecutors say, ran from 2023 to 2025. West, who also used the name “Kyle Northern,” is said to have operated a hacking group known as CyberN[——], selling stolen data on an underground forum. Information for sale included customer records, marketing…
Cisco has released urgent security fixes for two vulnerabilities affecting its Identity Services Engine (ISE) and Passive Identity Connector (ISE-PIC). Both flaws, CVE-2025-20281 and CVE-2025-20282, carry a CVSS severity rating of 10.0. Through this exploit, an attacker could gain root access to systems that control identity and access management. Access would enable lateral movement, privilege elevation, and persistence for an extended duration. These two vulnerabilities are unrelated but as severe as each other. Both affect different API elements in ISE releases 3.3 and 3.4. (CVE-2025-20281 affects ISE and ISE-PIC releases 3.3 and later, while CVE-2025-20282 affects version 3.4 alone.) Cisco…
Ahold Delhaize USA has confirmed that personal, financial, and health information belonging to over 2.2 million individuals was compromised during a cybersecurity breach in November last year. Details of the breach were formally disclosed in a filing with the Maine Attorney General’s office on 26 June 2025. The incident, attributed to an external system intrusion, is now known to have affected exactly 2,242,521 individuals, including 95,463 residents of Maine. The breach happened on 5 November and was discovered the following day. While Ahold Delhaize acknowledged the attack at the time, this latest filing unveils the scale and sensitivity of the…
More than 2,000 government-issued laptops, phones and tablets were lost or stolen across Whitehall departments over the past year, as reported by The Guardian. The estimated replacement cost? £1.3 million. The broader cost to national security is a lot harder to calculate. Departments including the Ministry of Defence (MoD), the Department for Work and Pensions, and the Cabinet Office reported hundreds of missing devices in 2024 and early 2025. In just the first five months of this year, the MoD alone reported 103 laptops and 387 phones gone missing. The Home Office, Treasury, and Bank of England were among other…
A Canadian online gambling provider has fallen victim to a highly targeted cyberattack involving a fake Zoom support tool, part of a broader social engineering campaign orchestrated by BlueNoroff, a financially motivated North Korean APT subgroup tied to the Lazarus Group. Investigators from Field Effect Analysis revealed that the incident began on 28 May 2025, during what appeared to be a routine Zoom call between the victim and a known contact. When audio issues arose, the victim was urged to run a so-called Zoom audio repair script, actually a malicious payload disguised to blend seamlessly into the victim’s workflow. The…
Oxford City Council has confirmed it was the target of a cyberattack that led to the unauthorised access of personal information belonging to individuals involved in council-run elections over the past two decades. The breach was quickly detected by the council’s automated security systems. It triggered an immediate response that limited the threat attackers’ access. “Unfortunately, the attackers were able to access some historic data on legacy systems,” the Council said in a statement. “We have now identified that people who worked on Oxford City Council-administered elections between 2001 and 2022, including poll station workers and ballot counters, may…
American insurance giant Aflac has disclosed a cyberattack on its U.S. network, part of what it describes as a broader campaign targeting the insurance sector. The intrusion was detected on 12 June and stopped within hours, with no ransomware deployed and no disruption to operations. The company says it remains fully operational and continues to underwrite policies and process claims. However, preliminary findings suggest that a sophisticated cybercrime group used social engineering tactics to gain access. Aflac says it has engaged external cybersecurity experts to support its response and containment efforts. While the investigation is still in its early stages,…
