Google has warned that the bad actors linked to the recent cyberattack on British retailer Marks & Spencer (M&S) is now setting its sights on U.S. retail companies. The group, known as “Scattered Spider,” is described by cybersecurity analysts as a loosely connected network of hackers with varying levels of sophistication. Despite their decentralized structure, the group has proven highly effective at executing disruptive cyberattacks against major corporations. John Hultquist, Chief Analyst at Google Threat Intelligence Group, told BleepingComputer, that the US retail sector is currently in the crosshairs of ransomware and extortion operations that Google suspects are linked to…
Kirsten Doyle
SafetyDetectives’ cybersecurity team has discovered a forum post on the clear web where a threat actor claimed to be selling a database connected to The Epoch Times. The dataset reportedly includes 32 million records. The Epoch Times is a multilingual media company founded in 2000. It was launched to provide uncensored news, particularly for readers in China, where access to independent media has long been restricted. Its first English-language edition appeared in 2003. Today, the publication is accessible in 35 countries, though it remains blocked in mainland China. The data was advertised on a well-known, clear web forum that hosts…
Two serious security vulnerabilities have been discovered in TheGem, a premium WordPress theme used by more than 82,000 websites worldwide. Researchers warn that when exploited together, these flaws can lead to remote code execution (RCE), potentially giving attackers full control over affected websites. Security researchers at Wordfence identified the vulnerabilities in versions 5.10.3 and earlier of the TheGem theme. While each flaw poses a risk on its own, their combined use creates a dangerous attack chain. According to Wordfence, the downloaded file is copied to the WordPress uploads folder, which is publicly accessible by default. Bad actors could combine the…
Luxury fashion brand Dior has alerted customers to a data breach involving its Chinese customer database. The company revealed that an unauthorised external party had gained access to sensitive customer information, though financial data was not affected. The breach came to light after Dior sent an internal memo to affected consumers on 13 May. According to multiple Chinese media outlets, including Global Times, the memo stated that the company discovered the breach on 7 May. The compromised data includes customer names, gender, phone numbers, email addresses, mailing addresses, purchase histories, shopping preferences, and other user-related information collected by Dior. In…
Zoom Video Communications has disclosed several security vulnerabilities in its Workplace Apps for Windows, macOS, Linux, iOS, and Android platforms. These flaws, which range from medium to high severity, could lead to issues like unauthorized access, denial-of-service (DoS), or remote code execution if exploited. One of the more serious vulnerabilities (CVE-2025-30663) is a time-of-check to time-of-use (TOCTOU) issue caused by a race condition in the app. With a CVSS 4.0 score of 5.9, this flaw could let a local attacker exploit timing gaps to access sensitive data or increase their system privileges. Although it requires access to the affected device…
Marks & Spencer (M&S) has fessed up that personal customer data was stolen in the recent cyber-attack, and that it could include contact details and dates of birth. The company’s chief executive Stuart Machin said: “As we continue to manage the current cyber incident, we have written to customers to let them know that unfortunately some personal information has been taken.” He stressed that there is no reason to believe that the information has been shared and it does not include any useable card or payment details, or account passwords. “There is no need for customers to take any action.” …
The European Union Agency for Cybersecurity (ENISA) has officially launched the European Vulnerability Database (EUVD) to enhance cyber resilience. Developed in accordance with the NIS2 Directive, the platform is now live and will be maintained by ENISA. The EUVD is designed to provide aggregated, reliable, and actionable information about cybersecurity vulnerabilities affecting ICT (Information and Communication Technology) products and services. It includes details such as mitigation measures, exploitation status, and affected versions of ICT products. “The EU Vulnerability Database is a major step towards reinforcing Europe’s security and resilience,” said Henna Virkkunen, European Commission Executive Vice-President for Tech Sovereignty, Security…
A major data breach has exposed the personal information of over three million individuals, including high school student-athletes and college coaches, according to cybersecurity researcher Jeremiah Fowler. The unprotected database, which was discovered by Fowler and reported to vpnMentor, contained more than 3.1 million records and 135 GB of data, including sensitive personally identifiable information (PII) such as names, phone numbers, emails, addresses, and even passport data. The records appear to belong to PrepHero, a Chicago-based recruiting platform operated by EXACT Sports, which helps high school athletes connect with college programs. Among the exposed data were unencrypted .CSV files containing…
Once viewed as a safe digital playground for kids, Roblox is now in the spotlight for all the wrong reasons. A new class action lawsuit is accusing the company of violating children’s privacy by secretly tracking their activity without proper consent. Filed in a California federal court by plaintiffs Michael and Salena Garcia, the suit alleges that Roblox Corporation is in breach of federal privacy laws. The 45-page filing paints a troubling picture. It claims Roblox uses hidden tracking tools that effectively “wiretap” everything a player does on the platform, from keystrokes and mouse movements to private messages and search…
A sophisticated phishing campaign spoofing India’s Ministry of Defence has been uncovered. The operation, which mirrors tactics seen in previous ClickFix-style attacks, appears to be the work of the Pakistan-linked threat group APT36 (Transparent Tribe). It uses cloned government branding and cross-platform malware delivery to target unsuspecting users. Deceptive Infrastructure Mimics Official Government Portal Researchers at hunt.io discovered a fake domain (email.gov.in.drdosurvey[.]info) designed to closely resemble the official Ministry of Defence press release portal. The malicious site mimicked the layout and structure of the real press archive, but with a critical difference: only the link for March 2025 was active,…
