Cloudflare successfully mitigated a record-breaking distributed denial-of-service (DDoS) attack that peaked at 7.3 Tbps, delivering 37.4 terabytes of data in just 45 seconds against a hosting provider. This massive attack, which surpasses previous records, highlights the escalating scale and intensity of DDoS threats targeting internet infrastructure and service providers worldwide. Security teams should review their mitigation readiness as attackers increasingly pursue critical infrastructure with high-volume attacks.
Source: SecurityWeek
16 Billion Passwords Exposed in Historic Credential Leak
Researchers have identified what appears to be the largest recorded data breach, with 16 billion login credentials exposed, likely due to widespread infostealer campaigns. The sheer scale of this leak underscores the urgent need for robust credential hygiene, enforced password changes, and the rapid adoption of phishing-resistant multifactor authentication across organizations to limit downstream impacts from credential stuffing and account takeovers.
Source: Forbes Security
Aflac Hit in Wave of Insurance Sector Cyberattacks
Insurance giant Aflac confirmed a cybersecurity incident potentially affecting sensitive data, making it the latest target in a broader campaign—linked to the Scattered Spider group—against major US insurance providers. The attack comes on the heels of warnings and breaches across the sector, underscoring the persistent targeting of financial services and highlighting the need for improved detection and response protocols in high-value verticals.
Source: Bleeping Computer
Banana Squad Targets Developers with Trojanized GitHub Repositories
Researchers uncovered a sophisticated malware campaign dubbed “Banana Squad,” involving more than 67 trojanized GitHub repositories that masquerade as hacking tools but deploy Python-based stealer malware. The campaign, targeting both developers and gamers, exemplifies the ongoing risks of open-source supply chain attacks and emphasizes the importance of repository vetting and threat intelligence integration to prevent developer compromise.
Source: The Hacker News
Critical Linux Privilege Escalation Flaws Expose Major Distributions
Newly discovered local privilege escalation vulnerabilities (e.g., CVE-2025-6018) affect major Linux distributions and could let attackers gain root access. Organizations relying on Linux should urgently review advisories, patch systems, and reevaluate detection controls to mitigate the risk of privilege escalation on end-user and server devices.
Source: Security Affairs
Massive Data Breach Hits Krispy Kreme—Over 160,000 Impacted
A ransomware attack on Krispy Kreme has resulted in the exfiltration of data belonging to 161,676 individuals, including current and former employees and their family members. The breach is notable for its impact on sensitive data, further highlighting the risks ransomware groups pose to organizations with large employee and customer datasets.
Source: SecurityWeek
Qilin Ransomware Offers Legal 'Call a Lawyer' Button to Pressure Victims
The Qilin ransomware group has introduced a “Call a Lawyer” feature, providing affiliates with legal counsel during ransom negotiations to increase pressure on victims. This development signals the increasing sophistication and professionalization of ransomware operations, as threat actors adopt business-like tactics for extortion.
Source: The Hacker News
You May Also Be Interested In...