Chinese-Linked Cyberespionage Target U.S. Government; Mustang Panda

The Chinese-linked cyberespionage group ‘Mustang Panda’ targeted U.S. government and policy-related officials with phishing emails themed around Venezuela. The campaign, uncovered by Acronis, exploited geopolitical events to infect systems and steal data. The U.S. Department of Justice recognizes Mustang Panda as a hacker group backed by China.   Chinese-linked cyberespionage group, identified as ‘Mustang Panda,’…

Read More

45M French records leaked after suspected attacker exposed data trove

The exposed dataset contained numerous French records, from population registry data to car insurance information, totalling tens of millions of records. The Cybernews research team believes the database was likely compiled by malicious actors. Key takeaways: Over 45M French records were exposed in an open database likely compiled by malicious data collectors. The leaked data…

Read More

One of the largest US broadband providers investigates breach

Crimson Collective claims to have stolen PII on 1M+ Brightspeed customers, including names, emails, phone numbers, and partial payment data Brightspeed has not confirmed the breach, saying it is investigating reports of a cybersecurity event The company, headquartered in Charlotte, NC, operates fiber broadband across 20 states and serves millions of premises One of the…

Read More

Meta signs nuclear deals to power the next generation of AI

Meta revealed on Friday that it has signed agreements with three US nuclear energy companies as it aims to secure energy resources to power its expanding AI infrastructure. The tech giant inked agreements with retail electricity and power generation company Vistra, nuclear technology company TerraPower, and Sam Altman-backed nuclear technology startup Oklo. “Our agreements with…

Read More

Hackers claim to hack Resecurity, firm says it was a honeypot

Threat actors associated with the “Scattered Lapsus$ Hunters” (SLH) claim to have breached the systems of cybersecurity firm Resecurity and stolen internal data, while Resecurity says the attackers only accessed a deliberately deployed honeypot containing fake information used to monitor their activity. Today, threat actors published screenshots on Telegram of the alleged breach, claiming they stole…

Read More

Hackers Abuse Google Tasks Notifications in Sophisticated Phishing Attacks

Attackers abused Google Cloud Application Integration to send phishing emails from legitimate Google domains Emails mimicked Google notifications, redirecting victims through trusted services Nearly 3,200 businesses targeted; most victims in U.S. manufacturing, tech, and finance sectors Over 3,000 organizations fell victim to a sophisticated phishing campaign in December 2025 that weaponized Google’s legitimate application infrastructure…

Read More