Researchers at Positive Technologies have uncovered that threat actors are compromising Microsoft Exchange servers worldwide by injecting browser-based keyloggers into Outlook on the Web (OWA) login pages. These attacks, targeting government organizations and enterprises, enable adversaries to harvest credentials and sensitive data, signaling an urgent need for immediate Exchange server patching and vigilance on login interfaces.
Source: Help Net Security
Global Financial Sector Hit by Sophisticated DDoS Campaigns
An FS-ISAC and Akamai report highlights a surge in advanced distributed denial-of-service (DDoS) attacks that have led to multi-day outages for leading banks and financial institutions worldwide. Attackers are using more complex and persistent tactics, underlining the necessity for upgraded defenses and incident response capabilities across the finance sector.
Source: HackRead
Iran Shuts Down Internet Amid Suspected Israeli Cyberattacks Targeting Critical Infrastructure
Iran confirmed instituting a near-total internet blackout as a defensive measure against what it claims were imminent Israeli cyberattacks on critical national infrastructure and to prevent the disruption of drone operations. The episode marks a heightened interplay between cyberattacks and geopolitical tensions, raising concerns about collateral impacts on civilian communications and broader regional stability.
Source: Security Affairs
16 Billion Login Credentials Leak: Widespread Risk for Internet Users
Security researchers have discovered databases containing an astonishing 16 billion stolen login credentials available to cybercriminals, underscoring the severity of global credential stuffing risks. This massive trove exposes both personal and organizational accounts, highlighting an urgent need for password security, multifactor authentication, and vigilance against credential reuse.
Source: SecurityBoulevard
Godfather Android Trojan Evolves to Hijack Banking and Crypto Apps via Virtualization
A major evolution of the Godfather Android trojan has been uncovered by Zimperium zLabs, indicating that the malware now uses on-device virtualization to compromise legitimate banking and crypto apps instead of relying on fake overlays. This approach enables more sophisticated and stealthy theft of funds, raising the stakes for mobile security in financial sectors.
Source: Security Affairs
Scattered Spider Group Behind Combined Cyberattacks on Major UK Retailers, $592M in Damages
The notorious Scattered Spider threat actor has been identified as responsible for coordinated cyberattacks on UK retailers Marks & Spencer and Co-op in April 2025, resulting in up to $592 million in damages. The Cyber Monitoring Centre's assessment reflects the increasing complexity and financial impact of supply chain and retail cyber incidents.
Source: TheHackerNews
Cloudflare Mitigates Record-Shattering 7.3 Tbps DDoS Attack
Cloudflare thwarted a record-breaking 7.3 Tbps DDoS attack in May 2025—surpassing all previous known volumetric attacks by a significant margin. The attack, targeting a hosting provider, demonstrates both the growing intensity of DDoS threats and the effectiveness of robust mitigation strategies.
Source: Security Affairs
You May Also Be Interested In...