The UK’s National Crime Agency has arrested four individuals—three teenagers and a 20-year-old woman—in connection with a series of ransomware attacks that disrupted major UK retailers Marks & Spencer, Harrods, and Co-op. These arrests represent a significant step in the fight against organized cybercrime, as the group allegedly extorted victims and laundered money, causing millions in damages. Investigations are ongoing, with UK law enforcement emphasizing continued vigilance against ransomware operations targeting national infrastructure and commerce.
Source: Security Week
Massive Data Breach at Qantas Affects 5.7 Million Customers
Australian airline Qantas confirmed that 5.7 million customers’ personal data—including names, contact details, and frequent-flyer numbers—were compromised after hackers accessed information via a third-party call center service. While Qantas stated the breach didn’t enable direct account access, the incident highlights ongoing risks in supply-chain security and follows a spate of similar attacks attributed to the Scattered Spider group. Organizations are urged to review data access protocols with external vendors and enhance supply-chain security posture.
Source: Security Week
Critical Bluetooth Vulnerabilities Leave Millions of Cars Exposed
Researchers uncovered “PerfektBlue,” a set of four exploitable vulnerabilities in the OpenSynergy BlueSDK Bluetooth stack. These flaws could enable remote code execution in cars manufactured by Mercedes-Benz, Volkswagen, Skoda, and others, potentially exposing infotainment and safety-critical systems to remote hacking. Car owners and manufacturers are advised to prioritize firmware updates and monitor official channels for security patches as attackers increasingly target automotive technology.
Source: Security Week
Ingram Micro Ransomware Attack Causes Global Disruption
Global tech distributor Ingram Micro suffered a sweeping ransomware attack (attributed to SafePay ransomware), causing major IT supply chain disruption. The company has since restored operations, but the disruption impacted managed service providers and downstream clients worldwide, underscoring the cascading risks posed by ransomware incidents in vital industry hubs. The event highlights the need for rapid threat detection, robust business continuity planning, and securing digital supply chains from third-party compromise.
Source: Heimdal Security
McDonald's McHire AI Chatbot Leak Exposes 64 Million Job Applications
A severe vulnerability in McDonald’s "McHire" AI-powered recruitment platform exposed data from over 64 million job applications worldwide. Security researchers found that, due to weak API protections (including use of the common password “123456”), unauthorized users could access applicants’ personal information. The incident illustrates widespread risks as AI and automation tools rapidly expand in HR and recruitment sectors, making API security and password hygiene critical priorities for organizations.
Source: Security Week
CitrixBleed 2: Actively Exploited Flaw Added to CISA KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Citrix NetScaler ADC and Gateway flaw CVE-2025-5777 (“CitrixBleed 2”) to its Known Exploited Vulnerabilities catalog, confirming widespread exploitation in the wild. Even as Citrix has downplayed the threat, independent researchers and now CISA warn of attacks resulting in session hijacking and unauthorized access. Urgent patching is advised for all affected systems, as the exploit’s ease and impact mirror last year’s headline-making vulnerabilities.
Source: Security Week
Hacktivist Attacks Surge on Critical Infrastructure Globally
Hacktivist groups are increasingly targeting industrial control systems and national infrastructure, with Russia-linked factions (such as Z-Pentest, Dark Engine, and Sector 16) responsible for dozens of ICS attacks in Q2 2025. The Energy, Utilities, and Government sectors are prime targets, and new groups leveraging more sophisticated, cross-border collaboration have emerged—often amplifying attacks with social media information operations. Experts urge immediate isolation of critical assets, network segmentation, and zero trust architecture to blunt this growing threat.
Source: Cyble
You May Also Be Interested In...
New ZuRu macOS Malware Discovered Targeting Developers
Details Emerge on UK Ransomware Arrests: M&S, Harrods, Co-op
UK Police Confirm Four Arrests Over Major Retail Cyberattacks