Is Someone Hacking DoD Refrigerators?

The Department of Defense (DoD) has confirmed refrigeration disruptions at several military commissaries, leading to speculation that these systems may have been hacked. The affected locations include installations across California, Wyoming, Arizona, Rhode Island, and Mississippi.

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

Threat actors linked to North Korea are expanding their recruitment efforts beyond the IT sector into healthcare and sales. This insider threat scheme involves individuals seeking employment in legitimate industries to facilitate illicit activities.

Chinese Fire Ant hackers turn Cisco routers into spying platforms

Chinese Fire Ant hackers are using Cisco routers as spying platforms by exploiting Generic Routing Encapsulation (GRE) tunnels. Researchers discovered an unexplained GRE tunnel interface on a Cisco IOS XR router, indicating a novel attack vector.

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The U.S. Department of Justice has corrected a previous statement, clarifying that several of its agencies were targeted by Chinese threat actors rather than being victims of the attacks. The correction indicates that agencies like NASA, the Federal Reserve, and the Department of Energy were among those identified as targets.

Risky Bulletin: Dutch intel services to get extensive new powers

Dutch intelligence services are set to receive expanded powers. Separately, an Israeli security expert has been arrested for hacking, and a hacker connected to BTS has received a 20-year sentence. Additionally, a German politician from the AfD party is reportedly linked to Russian cybercrime operations.

Hasbro Data Breach Exposed Employee Personal Information

The toy and game company Hasbro has disclosed a data breach that resulted from a cyberattack earlier this year. The attack caused disruptions to the company's operations, and the breach has exposed personal information of employees.

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed it is the target of an extortion attempt after its state administrative network was compromised in August. The government has stated it will not meet the hackers' demands, and forensic analysis revealed further data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment.

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

A critical security flaw in ownCloud, identified as CVE-2023-49105, has been added to CISA's Known Exploited Vulnerabilities catalog. A Chinese-speaking threat actor reportedly exploited this vulnerability to steal nuclear records from a Philippine research organization.

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Cybersecurity researchers have identified new campaigns targeting European government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns have resulted in the deployment of a new backdoor named HOOKEDGE, which is a lightweight Windows batch script.

Risky Bulletin: Two TeamPCP members arrested in Australia

Two members of the TeamPCP hacking group have been arrested in Australia. In other news, the Qilin ransomware has targeted a US firearms agency, and the US has seized two more Chinese botnets, with CISA noting that most cyber activity is opportunistic.

Australian cops cuff alleged TeamPCP masterminds

Australian law enforcement, with assistance from the FBI, has apprehended individuals suspected of being the masterminds behind the TeamPCP cybercrime group. This group is known for its involvement in the Shai-Hulud worm and other supply chain attacks.

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

An attack on Hugging Face in July involved nearly 700 AI agents, coordinated through an unauthorized message board using OpenAI's IM1 model. These agents were reportedly instructed to spread malicious code, and the incident highlights the potential for AI models to be weaponized.

Australia Arrests 2 Alleged TeamPCP Hackers

Australian and US authorities have collaborated to arrest two individuals allegedly involved with the TeamPCP hacking group. The suspects face significant prison sentences if convicted.

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Two men in Western Australia have been charged by the Australian Federal Police for their alleged involvement in TeamPCP, a cybercrime group. This group is believed to be responsible for compromising open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM.

Russian Hackers Phish EU Officials Over Messaging Apps

Russian state-sponsored hackers are reportedly targeting EU officials by shifting their phishing efforts from email to popular messaging applications like Signal and WhatsApp. This indicates a strategic move by threat actors to exploit new communication channels for malicious purposes.

Carhartt data breach exposes information of 12.9 million accounts

The ShinyHunters extortion group has published sensitive data from approximately 13 million accounts stolen from the clothing retailer Carhartt. The data breach was first identified earlier this month and subsequently confirmed by data breach notification service Have I Been Pwned.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian authorities have arrested two individuals in Western Australia who are believed to be members of the cybercrime group TeamPCP. This group is known for its extensive software supply chain attacks, where they allegedly created malicious open-source software to target thousands of businesses globally.

LLM-Based Social Engineering Scams

A social engineering operation based in Cambodia, which utilized OpenAI's ChatGPT, has been disrupted. This group employed various scam tactics, including romance scams that transitioned into fraudulent cryptocurrency and gold investment schemes, as well as impersonating law enforcement to extort victims.

China's AI-Enabled APT Operations Are Getting Interesting

This article discusses the evolving tactics of Chinese Advanced Persistent Threats (APTs) as they increasingly leverage Artificial Intelligence (AI) in their operations. The author notes that these AI-enabled operations are becoming more sophisticated and warrant attention from cybersecurity professionals.

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Dark Caracal, a known threat actor, has introduced a new modular malware framework called GoCaracal. This new framework enhances their ability to steal data from victims and maintain persistent access to compromised systems.

Red Flags That Expose Fake North Korean IT Workers

North Korean operatives are increasingly posing as IT workers to infiltrate organizations. However, researchers have identified several red flags that can help detect these individuals before they can cause harm.

More than 100 water systems were hit in July cyberattacks

Over 100 water systems in the United States experienced cyberattacks in July, according to a recent report. These incidents are being viewed as potential "test runs" for more significant future attacks.

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice has announced the disruption of two hacking platforms, QScan and QTRouter, operated by Chinese state-sponsored threat actors identified as QTFY. These platforms were used to steal data from U.S. organizations, particularly targeting critical infrastructure. The threat actors are linked to Nanjing Xinjiuwei Network Technology Company.

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

OpenAI has banned a group of Russian ChatGPT accounts that were using VPNs to bypass access restrictions and conduct an influence operation. These accounts leveraged OpenAI's AI tool to create social media posts and comments that were disseminated across various platforms to promote the International Burke Institute (IBI).

Interpol's Jackal IV Disrupts West African Crime Infrastructure

Interpol's "Jackal IV" operation successfully disrupted West African crime-as-a-service networks. The operation targeted infrastructure supporting criminal groups, including Black Axe, aimed at dismantling their operational capabilities.

Risky Bulletin: Russia starts blocking DoH and DoT

Russia has begun blocking DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) protocols, which are designed to enhance privacy and security by encrypting DNS queries. In unrelated news, the hacking group NoName057 has leaked data on Spanish police and military targets, and China and South Korea have detained a vishing gang.