Sploitlight macOS security flaw disclosed by Microsoft Threat Intelligence team because… of course.

Sploitlight macOS security flaw disclosed by Microsoft Threat Intelligence team because… of course.

A serious security flaw in macOS, identified as CVE-2025-31199 and dubbed “Sploitlight,” has been disclosed by Microsoft’s Threat Intelligence team. This vulnerability, now patched by Apple, targeted the Spotlight search engine’s plugin system and exposed sensitive user data, including information cached by the latest Apple Intelligence features.
Hackers penetrate Toptal’s GitHub account and leverage their privileged access to inject malicious code into the npm registry.

Hackers penetrate Toptal’s GitHub account and leverage their privileged access to inject malicious code into the npm registry.

In July 2025, prominent freelance talent platform Toptal grappled with a significant software supply chain breach after unknown threat actors penetrated its GitHub organization account. The repercussions of the attack extended far beyond source code exposure, as adversaries leveraged their privileged access to inject malicious components into the open-source ecosystem via the npm registry.
hacker holding money

Researchers Uncover Major Online Counterfeit Currency Operation in India.

Cybersecurity researchers at CloudSEK’s STRIKE team have revealed the existence of a large-scale fake currency operation exploiting digital platforms to circulate counterfeit Indian banknotes. The operation, running openly on channels such as Facebook and Instagram, is estimated to have moved fake currency worth over ₹17.5 crore (approximately $2 million) between December 2024 and June 2025.
CISA adds 3 vulnerabilities to KVE catalog. Urgent patching advised.

CISA adds 3 vulnerabilities to KVE catalog. Urgent patching advised.

Today, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding three recently discovered and actively exploited security flaws. The newly cataloged vulnerabilities affect widely used business software and network devices, underscoring the persistent threat landscape and the critical importance of rapid patch management for organizations in all sectors, especially those overseeing critical infrastructure.
Scattered Spider shifts gears and begins exploiting VMware’s ESXi to deploy ransomware on critical U.S. infrastructure.

Scattered Spider shifts gears and begins exploiting VMware’s ESXi to deploy ransomware on critical U.S. infrastructure.

A highly active and sophisticated cybercriminal collective known as Scattered Spider—also referred to as UNC3944, 0ktapus, Octo Tempest, and Muddled Libra—has escalated its attacks on critical U.S. infrastructure by targeting the VMware ESXi hypervisor, a core component of many enterprise data centers. By deploying ransomware on these systems, the group has successfully disrupted a range of sectors, highlighting the growing risks associated with virtualized environments.
hacker with navy military ship in the background

France categorically denies that hackers breached their leading defense contractor’s systems. Hackers then post code and architecture details for naval combat systems.

Naval Group, France’s leading defense contractor, has publicly denied claims of a significant cyber-attack after reports circulated online suggesting the firm’s internal systems had been breached. The company, which is majority-owned by the French government and recognized for its role in producing advanced naval vessels, including submarines and aircraft carriers, is at the center of a growing cybersecurity controversy.
In what could be the most significant cyberattack targeting Russian civil infrastructure, hackers say they took down Aeroflot, Russia’s largest airline.

In what could be the most significant cyberattack targeting Russian civil infrastructure, hackers say they took down Aeroflot, Russia’s largest airline.

Russia’s flagship carrier, Aeroflot, faced a widespread disruption on Monday morning as a catastrophic failure of its information technology systems forced the airline to cancel dozens of flights. The incident affected both domestic and international operations, leaving thousands of passengers stranded and triggering a criminal investigation.
Congress Targets AI-Driven “Surveillance Pricing” with Groundbreaking Legislation.

Congress Targets AI-Driven “Surveillance Pricing” with Groundbreaking Legislation.

In response to mounting concerns about the use of artificial intelligence (AI) to set individualized consumer prices and wages, lawmakers in Congress have unveiled a landmark proposal: the Stop AI Price Gouging and Wage Fixing Act of 2025. Sponsored by Rep. Greg Casar (D-Texas) and Rep. Rashida Tlaib (D-Mich.), the bill seeks to prohibit the use of personal data by companies to algorithmically determine prices and pay rates, a growing practice known as “surveillance pricing.”
Global Operation Disrupts BlackSuit Ransomware Group With Major Dark Web Seizures

Global Operation Disrupts BlackSuit Ransomware Group With Major Dark Web Seizures

In a coordinated international law enforcement effort dubbed Operation Checkmate, authorities have successfully seized the key dark web domains operated by BlackSuit, one of the world’s most prolific ransomware gangs. This operation marks a significant advance in the global battle against ransomware, crippling a network that extorted hundreds of organizations and garnered over half a billion dollars in ransom payments.