Medical technology giant Medtronic is notifying more than 3.8 million individuals that their personal and medical information was compromised in a recent data breach. The incident occurred in April 2026, when the infamous extortion group ShinyHunters accessed the company’s corporate IT systems. Medtronic confirmed the attack in late April, noting that its products and manufacturing ..
Tag : Cybercrime
A dual US-Estonian citizen was extradited to the US to face charges for his alleged involvement in the activities of the infamous hacking group Scattered Spider. The individual, Peter Stokes, 19, also known as ‘Bouquet’, was arrested in Finland in April while boarding a flight to Japan. He was indicted with counts of conspiracy, computer ..
Google, the FBI, and other organizations coordinated in a joint effort to dismantle NetNut, a massive residential proxy network. Also known as Popa, NetNut is believed to consist of more than 2 million Android devices such as smart TVs and streaming boxes, that have been infected through trojanized applications and malware such as Badbox 2.0. ..
L’intelligence ucraina conferma e amplia l’allarme statunitense: i servizi russi non rompono la crittografia delle app di messaggistica, ma convincono le vittime a consegnare le chiavi che proteggono i loro backup. Il bersaglio sono funzionari, militari, politici e attivisti in Ucraina, Europa e Stati Uniti. La svolta operativa più recente riguarda in modo specifico Signal; ..
More than 200,000 websites are using investment scam templates built with the Chinese open source framework Uni-App, Infoblox reports. A cross-platform development toolkit, Uni-App allows developers to create Vue.js codebases that can be deployed as mobile and desktop applications, or as mobile-optimized websites simultaneously. Widely used in China and supported by a developer ecosystem, the ..
Google Threat Intelligence Group (GTIG) ha pubblicato l’analisi di STOCKSTAY, una backdoor modulare in .NET sviluppata dal gruppo russo Turla almeno dal dicembre 2022 e impiegata in operazioni dal 2023 per attività di spionaggio contro organizzazioni governative e militari in Ucraina. Il dettaglio che rende la ricerca rilevante per il pubblico italiano è esplicito nel ..
Il data breach Trenitalia, comunicato il 26 giugno, espone i dati di contatto e di viaggio di una parte dei passeggeri. La principale compagnia ferroviaria italiana ha inviato ai clienti interessati una email con oggetto “Comunicazione di violazione dei dati personali ai sensi dell’art. 34 del Regolamento UE 679/2016”, attribuendo l’accesso non autorizzato ai database ..
Microsoft, law enforcement, and several cybersecurity companies have collaborated to take down infrastructure shared by two widely used malware families: Amadey and StealC. The action, part of the long-running Operation Endgame, involved the use of AI, legal action, and the exploitation of a vulnerability in a malware control panel, and resulted in hundreds of domains ..
A third man charged for his role in a 2022 hacking attack on the sports and betting website DraftKings has been sentenced to prison, the Justice Department announced on Tuesday. The DOJ has not named the targeted site, describing it as a fantasy sports and betting website, but its description of the attack matches the ..
An initial access broker (IAB) linked to multiple ransomware families has been using a new remote access trojan (RAT) in recent attacks, Broadcom’s Symantec and Carbon Black threat hunter team reports. The threat actor, tracked as Woodgnat and KongTuke, and active since at least May 2024, is known to have ties to ransomware groups such ..


