Browsing: Cyber Incidents
Cybersecurity researchers have uncovered a coordinated abuse of the Google Chrome Web Store involving two browser extensions that were secretly designed to collect and exfiltrate user conversations from artificial intelligence platforms such as ChatGPT and DeepSeek, along with detailed browsing information. The extensions appeared as legitimate AI productivity tools and were marketed as helpers that integrate multiple AI models into the browser. However, behind the scenes, they operated as surveillance tools that quietly harvested sensitive data and transmitted it to servers controlled by unknown threat actors. Investigators confirmed that the two extensions together had been installed by more than 900,000…
The first days of 2026 have already shown that cyber threats didn’t reset with the new year. Instead of dramatic headline-grabbing attacks, most incidents this week followed a familiar pattern — quiet abuse of trusted systems that people use every day. Browser extensions, software updates, login notifications, and even AI tools were misused in ways that felt normal to users, but harmful in reality. That is what made these attacks effective. Below is a summary of the most important cybersecurity developments from this week, explained in simple terms. A Silent Botnet Campaign Is Still Growing Security researchers confirmed that a…
Leduc County, a local government authority in Alberta, Canada, has confirmed that it was the victim of a ransomware cyberattack that disrupted its internal IT systems. The incident was detected on December 25, 2025, when officials noticed unusual activity and partial system outages. A forensic investigation later confirmed that the disruption was caused by a malicious ransomware attack. What Happened? According to county officials, attackers attempted to compromise internal digital systems and restrict access to critical services. As a precaution, several systems were taken offline to prevent further damage and to secure sensitive information. The county immediately engaged a professional…
A cyber espionage group tracked as Transparent Tribe has been linked to a new wave of targeted attacks against Indian government agencies, academic institutions, and strategic research organizations. The campaign uses socially engineered delivery mechanisms and living-off-the-land binaries to deploy a remote access trojan (RAT) that enables long-term access and data collection from compromised systems. Initial Access The attack chain begins with spear-phishing emails carrying compressed archives that contain Windows shortcut (LNK) files disguised as legitimate PDF documents. The LNK files are crafted to execute hidden commands while simultaneously displaying a decoy document to avoid raising suspicion. When opened, the…
What happened? Initial investigation indicates that approximately 6–7% of registered users — estimated at about 108,000 to 126,000 people — may have been affected by this breach. Data at risk Response and investigation Extortion and threat activity
The European Space Agency (ESA) has publicly confirmed a cybersecurity breach that affected a limited number of servers outside its core corporate network, marking one of the most significant data security incidents in the aerospace sector this year. According to official statements released by ESA and corroborated by independent cybersecurity reporting, an unauthorized actor gained access to servers supporting collaborative science projects. The agency clarified that the affected systems were not part of mission-critical infrastructure and that there is no current indication of impact on active space missions. Preliminary forensic analysis suggests that the breach was detected following unusual activity…
A data breach affecting a subcontractor linked to South Korean airline Korean Air has been disclosed, involving unauthorized access to internal employee records. According to company statements and regulatory disclosures, the incident occurred after attackers exploited vulnerabilities in systems operated by KC&D Service, a former in-flight catering subsidiary now owned by a private equity firm. Preliminary investigations indicate that approximately 30,000 employee records were accessed, including names, bank account details, and internal employment identifiers. Korean Air said that no customer data was affected and the exposure was limited to internal employee information. The airline confirmed that cybersecurity specialists and forensic…
A data security incident involving South Korean e-commerce company Coupang was disclosed on December 29, 2025, after a former employee admitted to accessing internal customer records without authorization. According to the company’s statement and ongoing legal filings, the individual accessed internal systems after leaving the organization and viewed or copied data linked to approximately 33 million customer accounts. Authorities confirmed that the access was not part of any approved internal activity and is being treated as a criminal violation under South Korean data protection laws. Coupang stated that the unauthorized access was limited to customer profile information and did not…
A major cybersecurity incident disrupted a globally popular online gaming platform on December 28, 2025, causing widespread service outages and unauthorized changes to internal systems. According to incident disclosures and user reports, attackers gained unauthorized access to backend infrastructure by exploiting a vulnerability in the platform’s server environment. This access allowed them to manipulate internal digital assets, temporarily disable moderation controls, and interfere with account management systems. As a result, the platform experienced instability across multiple regions, with users reporting sudden account changes, abnormal digital balances, and service interruptions. The company temporarily suspended its services to contain the incident and…