A forum that you joined in 2017 is breached in 2026. If you're still using that password anywhere else, that's the problem. Check your email address against 10B+ records now.
@LisaKeyerOnline Most people use the same email address everywhere. According to a survey conducted by Google in 2018, 66% of people reuse passwords for more than one account.
⚡️ Hardware wallets no longer save you — new malware OkoBot hits Ledger and Trezor from inside their own apps.
OkoBot infects the computer and injects a fake seed-phrase input form straight into the official client's UI. The user opens their Ledger Live or Trezor Suite, sees a "routine recovery prompt" in the native interface, types out the 24 words — and they land in the attacker's hands.
The whole point of a hardware wallet is that the seed phrase never touches the computer. OkoBot breaks exactly that rule — by getting the user to break it willingly.
Never type your seed into any app. Real Ledger and Trezor only ever ask for it on the device itself. If a prompt shows up on your computer screen — you're already infected.
📡 Weekly Cyber Digest (July 13 – July 18)
🔻 Microsoft new record — 622 CVEs. MS openly credits AI-assisted code auditing for the pace.
🔻 WordPress pre-auth RCE in core. Default installs with zero plugins are hittable. Fix — 6.9.5 and 7.0.2, details held back to buy patching time.
🔻 JetBrains — critical flaws in IntelliJ, TeamCity (CI/CD), and YouTrack.
🔻 TuxBot v3 — IoT botnet with LLM-generated exploits, mutating to dodge detection on its own.
🔻 Claude for Chrome. Malicious extensions could pivot through the AI agent into Gmail, Drive, Calendar.
🔻 Ernst & Young breached via a third-party ITSM contractor — a textbook supply chain hit on an audit giant.
🔻 D1R threatens Synopsys and Bosch. If the Synopsys leak is real, it lands across the entire semiconductor supply chain.
🔻 23andMe to pay $18M in the class action settlement over the massive breach.
🔻 Italy fines WINDTRE €1.7M over past data breaches.
🔻 Scattered Spider vs Transport for London. Thalha Jubair and Owen Flowers finally reached court over the 2024 attack.
🔻 LastPass and Bitwarden. Mass wave of fake "compliance" emails pushing an "urgent master password reset."
🛡️ — update WordPress and don't click compliance emails
⚡️ Meet ShinyHunters — the hackers group dominating headlines through 2025 and 2026.
Active since 2020, with 400+ breached companies and over 1.5 billion stolen records on their belt. Victims include Coinbase, Louis Vuitton, Gucci, Adidas, Jaguar Land Rover, Qantas, Adobe, Carnival, Vimeo, Canvas, ADT. In March this year they even tried to extort Salesforce itself.
Their signature move — they don't break the perimeter. No zero-days, no firewall exploits. They go straight for the SaaS layer: phishing OAuth tokens, fishing employees into handing over Okta SSO access, hunting for misconfigs in Salesforce Experience Cloud. The attack happens inside your cloud — exactly where traditional security isn't looking.
From first call to full data exfiltration, their subgroups need under an hour. By the time your SOC blinks, the data is already gone.
🪙 — some people collect Labubus, others collect companies
⚡️ Social engineering, level up - cybercriminals are now showing up at victims' offices in person.
The Silent Ransom Group (a.k.a. Luna Moth, UNC3753) has been hitting US law firms for three years. As of spring 2026, they've upgraded: instead of "IT support" phone calls, an actual person walks into the office, claims to be a technician, and plugs a USB drive into a workstation. From there - data theft and extortion under threat of public release.
No malware, no encryption, no traces in logs. IT systems keep humming along as usual, right up until a ransom email lands in someone's inbox.
The FBI issued a FLASH alert on May 26. The group's leak site already lists 38 law firms, including Orrick, Jones Day, and Wood Smith Henning & Berman. Researchers put the real number of attacks at 100+.
🪪 — next time, ask the IT guy for his badge.
🕵️ Find out about a data breach before the hackers do!
Imagine this: it’s a normal working day and you’re sitting at your computer checking your emails. A few weeks later, your company’s data is already up on a forum. Can you picture it? Well, Adobe doesn't need to imagine it. That’s exactly why you need Dark Web Monitoring.
Let's take a look at what it is and why it's essential.
It can take weeks, months or even years for an attacker to gain access to your data and for it to end up in a public dump. During this time, people are already trading access, verifying stolen credentials, and discussing who to sell the database to for the highest price on closed forums. Sometimes, databases are sold for next to nothing, purely to damage the reputation of the seller.
Dark Web Monitoring operates precisely within this timeframe. It is an automated intelligence service that scans forums, leak sites, dark web marketplaces and social media and messaging channels 24/7, flagging any mention of your company, domains, employees or customer data before it falls into the hands of malicious actors.
What does it cover? Everything — from personal emails containing supermarket vouchers to home addresses, bank passwords, and card details.
And now, a few figures to illustrate this:
- 425 million accounts were compromised globally in 2025.
- 16 billion login/password pairs were leaked in a single data dump in June 2025.
- The average cost of a single data breach to a business is $4.44 million.
- The average time from a breach to its detection is 241 days.
By the time you read this post, your data may already have been in the wrong hands for over six months.
🛡 Don't be like Adobe. Check your date now with LeakCheck.
⚡️ DHL lost a package — this time with 840 million customer records inside.
The dump has everything you need for picture-perfect phishing: full names, home addresses, photos of parcels, and drivers' personal data. The attacker knows not just who you are, but what you recently ordered — so it's no longer a generic "your package has arrived," it's a believable email with a tracking number and a photo of your actual box.
The drivers got the worst of it: their data ended up in the same dump as the customers', which is a personal safety issue, not just another spam wave.
📦 — package delivered. Sadly, not to you.
📡 Weekly Cyber Digest (May 04 – May 10)
🔻Linux "Dirty Frag". Copy Fail's successor that hands out root on Ubuntu, RHEL and Fedora out of the box – the PoC dropped before the patch, and the exploit is already in the wild.
🔻Canvas took down US schools. Attackers swapped the platform's login page for a ransom demand, halting classes across thousands of schools and universities for a day.
🔻DAEMON Tools shipped a backdoor straight from its official site – for a full month, signed with a valid developer certificate. Thousands of infections across 100+ countries, attribution points to a Chinese-speaking actor.
🔻Adobe leak – 13M support tickets plus every HackerOne report they had, after attackers came in through an Indian BPO contractor. The dump now holds unpatched bug bounty vulnerabilities.
🔻Palo Alto PAN-OS (CVE-2026-0300). Unauthenticated RCE as root, with exploitation attempts running since April 9, and the patch only promised for May 13.
🔻PCPJack – a cloud worm that steals credentials from Docker, Kubernetes, Redis and MongoDB, then spreads itself across the victim's network.
🔻CallPhantom: 28 Android apps with 7.3M downloads promised access to other people's calls and WhatsApp, but really just stole users' money. Google has already purged the store.
🔻Quasar Linux RAT – a new implant aimed at developer machines, with keylogging and credential theft from cloud services and password managers.
⚡️ The Canvas by https://t.co/weoNqFGuCu school platform was hacked — data on 275 million students, teachers, and staff from ~9,000 schools and universities worldwide is in the wrong hands.
A 3.65 TB archive is already circulating: names, emails, student IDs, and billions of private messages between students and teachers. Instructure's Salesforce instance was also breached — attackers got in through a vulnerability in the platform.
The leak itself isn't the worst part — it's what comes next. With real course names, teacher names and message context in hand, phishing becomes nearly indistinguishable from real school emails. "Your child has a new assignment" with the right details will fool any parent.
🎓 — your yearbook is now on the dark web.
⚡️ Scammers leaked themselves — carding marketplace Jerry's Store exposed 345,000 stolen credit cards thanks to a misconfigured server.
To cut costs, the crew decided to use an AI to write the backend. The end result was that the server went public — not just any server, but the exact one they used to verify stolen cards.
🦸 — AI Agents 1:0 Carders.
⚡️ https://t.co/VwJYWZdbEU got wrecked — ShinyHunters dumped 8.7M passenger records after the company refused to pay.
Names, emails, DOBs and loyalty statuses from Holland America's Mariner Society program. It all started with one phished employee account — a single click, millions of records gone.
🛳️ — bon voyage, your data is now on a separate cruise.
That's how Vercel got compromised... 🤦♂️
One employee gave https://t.co/7Rx4hxliTS full Google OAuth → attackers stole the token → got into Vercel → stole env vars (keys & creds). They also forgot to make these envs sensitive, meaning that they were left unencrypted.