ZeroHour

Search: “Cyber Toufan”

15 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Pro-Palestinian operation claims dozens of data breaches against Israeli firms

Hacktivist group Cyber Toufan claims 60 data breaches of Israeli and allied firms, wiping systems and erasing backups; Check Point links it to Iran.

The pro-Palestinian group Cyber Toufan said it released stolen data from 60 Israeli and foreign firms, including SpaceX, Toyota and IKEA, as part of a month-long leak operation launched in late November. Researchers at Check Point and SOC Radar assess the leaks are genuine, likely stemming partly from a major attack on Israeli hosting company Signature-IT, and attribute the group to Iran; researcher Kevin Beaumont said roughly a third of victims remain offline weeks later with backups erased. Google blocked the group's Telegram leak channel, while about 10 Iranian-backed hacking groups are assessed to be attacking Israel in the ongoing cyberwar.

The Record · 9d agoThreat actor in the wild

Sality, one of the longest

US and European authorities, with CrowdStrike and Shadowserver, disrupted the 20-year-old Sality peer-to-peer botnet, severing 15,000+ infected machines from operators.

US and European authorities disrupted the Sality botnet, active since at least 2003, in an operation involving the DOJ, CrowdStrike, the Shadowserver Foundation and agencies in Bulgaria, Hungary and Romania. Researchers reverse-engineered the botnet's peer-to-peer architecture and injected false data into infected machines' 'super peer' lists, cutting more than 15,000 systems off from their operators. For the past eight years Sality primarily distributed EggJagger, malware that replaces clipboard cryptocurrency addresses and is estimated to have netted the operator at least $150,000. No arrests were announced, and CrowdStrike assesses the operator works from Russia's Bashkortostan region.

The Record · 14d agoMalware in the wild

Local governments in four states dealing with cyberattacks that have shut down services

Ransomware and cyberattacks disrupted local governments in California, Oklahoma, South Dakota, Texas and Wisconsin, taking Suisun City's 911 offline.

Suisun City, California (population 30,000) shut down its IT network after malicious software hit 911 routing, police and fire dispatch; the city declared a state of emergency and the FBI is investigating. Coweta, Oklahoma confirmed a ransomware attack affecting all computers and digital services, with off-site backups slated for restoration. Mitchell (South Dakota), Coryell County (Texas) and Washburn County (Wisconsin) also disclosed cyberattacks that shut down networks and disrupted phone and payment systems.

The Record · Aug 11, 2026Ransomware in the wild

Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe

Cyberattack on Ceva Logistics disrupted eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ajax and exposing Steam hardware buyers' data.

A cyberattack on Ceva Logistics disrupted operations at eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ace & Tate, Ajax and Steam hardware customers. Attackers accessed two Ceva systems processing Bol orders, potentially exposing names, addresses, phone numbers, email addresses and order details. Valve began notifying European Steam customers whose hardware shipping data may have been compromised and is contacting data protection authorities. Ceva, with about 110,000 employees and over 1,700 facilities, has not disclosed the attackers or whether ransomware was involved.

The Record · Aug 11, 2026Data breach in the wild

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI

Bitdefender attributes the SilkParasite espionage campaign to China-linked actors using five new malware strains and AI-assisted development to target Central Asian governments.

Bitdefender researchers uncovered a nearly year-long espionage operation dubbed SilkParasite targeting government economic institutions in Central Asia and the South Caucasus. The campaign uses seven malware families, five previously undocumented, including DriveSilkRAT, which communicates through a shared Google Drive folder instead of a dedicated C2 server. The attackers gained access via malicious Microsoft Office documents delivered through spearphishing emails packaged in archives. Bitdefender found evidence of AI-generated lures and AI-assisted malware development, tied the campaign to China via infrastructure and malware overlaps, and observed 65 infections across targeted countries.

The Record · 27d agoThreat actor in the wild

Slovakia Warns of Cyber Risks in Road Speed Cameras

Slovakia's NBÚ warns that speed camera systems from SODASUS, Simicon and NEROline pose cyber risks including undocumented remote access.

Slovakia's National Security Authority (NBÚ) warned of a significant cyber threat tied to several road speed camera products: NERO R-ONE units sold by Cyprus-based SODASUS, and Cordon-series cameras made by Russia's Simicon and sold by Croatia's NEROline. A security analysis requested by the Interior Ministry found weak protections, mismatches between documented and actual communication settings and software versions, unclear hardware/software provenance, and pre-configured remote-access mechanisms outside operator control. NBÚ warned that compromised cameras could expose vehicle and licence-plate data, tamper with records, or serve as a foothold into public-sector networks lacking segmentation. The Interior Ministry reportedly removed the units from its pilot deployment and asked the supplier to replace them with equipment meeting Slovak and EU security requirements.

Security Affairs · 23d agoAdvisory

Large DDoS attack knocks Norwegian public services offline

A large DDoS attack on Norwegian IT partner Vivicta disrupted 10 government services, including ID-porten used by over 4.5 million users, for 30+ hours.

Norway's Digitalisation Agency (Digdir) said a distributed denial-of-service attack that began Monday targeted the infrastructure of its IT partner Vivicta and lasted around 30 hours at varying intensity, with some services still affected Tuesday. Disrupted services included ID-porten, a national digital identity gateway used by more than 4.5 million people, which many government services and parts of the health sector, such as online pharmacies and the electronic prescription system, rely on for authentication. Digdir said attackers did not gain access to sensitive information, and it was the third DDoS incident since June, reportedly two to three times larger than the previous one. Attribution and possible links between the incidents remain unclear.

The Record · 22d agoThreat actor

Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware

Huntress uncovered post-DEF CON phishing via X direct messages using a malicious Google Doc to deliver AMOS and NetSupport RAT malware.

Huntress uncovered a phishing campaign targeting attendees after Black Hat and DEF CON. Attackers used X direct messages pointing to a malicious Google Doc as the delivery vehicle. Payloads include AMOS, a macOS infostealer, and the NetSupport RAT, among other malware.

Huntress · 28d agoPhishing & fraud

A Cyber Range Evaluation of Autonomous Network Incident Response Agents

Cyber range evaluation shows reinforcement learning incident response agents defend emulated networks more efficiently than heuristic policies, depending heavily on adversary behavior.

The paper evaluates agents for automated network intrusion response in a cyber range designed for human operator training, featuring variable topology, red-team emulation, and simulated users. Alerts are generated by a SIEM platform and mapped to a data modeling language used by the agents, with reinforcement learning policies optimized to minimize combined defense and availability costs using a cyber attack simulator. Reinforcement learning agents defended the system more efficiently than heuristic policies, with performance highly dependent on the adversary policy and simulated user behavior.

arXiv cs.CR · 2d agoResearch

Cyberattack causes network outage at Boston Scientific, disrupts global operations

Boston Scientific disclosed a cyberattack that caused a network outage, disrupting global operations including order processing and shipping.

The medical device maker detected the incident on August 25, activated incident response protocols with third-party cybersecurity experts, and told the SEC that access to systems supporting operations, including order processing and shipping, was disrupted. Boston Scientific employs about 59,000 people across 127 countries and posted more than $20 billion in net sales in 2025; it has not determined whether the incident is material and no group has claimed responsibility. The company joins a recent run of medtech attacks including Stryker, iRhythm, Novo Nordisk and Xsolis.

Help Net Security · 21d agoData breach

The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

AI giants warn AI-armed cyberattacks are 'months' away; hackers target over 100 US water systems in WIRED's roundup.

WIRED's weekly security digest leads with AI giants warning that AI-armed cyberattacks could surge within months. It also reports hackers targeting more than 100 US water systems, ICE's order for robot dogs, and an arrest tied to the online alias 'MrChildPorn'. No single incident is analyzed in depth in the excerpt.

WIRED · Security · 18d agoThreat actor in the wild

Nebulon Enterprise Simulated Threats for Phishing Research (NEST-Phish): A Synthetic Enterprise Phishing Email Dataset for Behavioral and Machine-Learning Research

Researchers release NEST-Phish, a synthetic enterprise phishing email dataset with matched legitimate and phishing emails and cue annotations for detection research.

Academic researchers introduce NEST-Phish, a publicly released synthetic enterprise phishing email dataset built around a fictitious organization named Nebulon. It contains matched synthetic legitimate and phishing emails across a broad set of workplace communication themes, each with interpretable phishing-cue annotations. Human-subject categorizations and supervised classifier evaluations indicate the dataset supports meaningful variation in phishing judgments and provides learnable signal for detection models. It is intended to support work on phishing detection, human susceptibility, explainability, and benchmark development.

arXiv cs.CR · 13d agoResearch

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos tracks UAT-10147, a Chinese-speaking cybercrime group exploiting vulnerable web servers and using agentic AI in post-compromise operations.

Cisco Talos identified a Chinese-speaking cybercrime group tracked as UAT-10147 that targets a wide range of vulnerable web servers. The report maps affected countries and analyzes the impact of BadIIS infections on compromised servers. It also documents the attack chain and emerging use of agentic AI during post-compromise activities.

Cisco Talos · 27d agoThreat actor in the wild

The Collective Cyber Defense letter wrote your next vendor questionnaire

Op-ed argues the 200-company Collective Cyber Defense letter's three endorsed metrics should become standard vendor procurement questions.

More than 200 companies including Microsoft, Google, AWS, CrowdStrike, Anthropic and Okta signed an August 27 open letter calling for faster cyber defenses against AI-enabled attacks. The letter endorses three measurable metrics: coverage, containment speed, and verified remediation. The author turns those into five concrete procurement questions buyers should pose at vendor renewals, while noting the letter contains no deadlines, dollar figures or measurable targets.

CyberScoop · 15d agoIndustry