Cybersecurity & Privacy
Scammers try to trick LastPass users into giving up credentials by telling them they’re dead | CSO Online Scammers are using a creative phishing campaign targeting LastPass users, posing as the company and sending emails with the subject line “Legacy Request Opened (URGENT IF YOU ARE NOT DECEASED)” to trick victims into clicking a malicious link and revealing their master passwords. The attackers, linked to the CryptoChameleon group, aim to steal credentials and potentially drain cryptocurrency wallets, with LastPass warning users that it never asks for master passwords and advising the use of MFA to combat such threats.
Dissecting YouTube’s Malware Distribution Network - Check Point Research Check Point Research has uncovered a Ghost Network on YouTube that uses over 3,000 malicious videos to distribute malware, primarily infostealers like Lumma and Rhadamanthys. This network, active since 2021, saw a tripling of malicious videos in 2025, employing compromised accounts, fake engagement, and targeted content like game hacks and software cracks to deceive users into downloading malicious software.
Data breach in 42 Latvian municipalities: DVI imposes 300,000 euro fine on ZZ Dats - Baltic News Network The Data State Inspectorate (DVI) has fined SIA ZZ Dats 300,000 euros for a municipal data breach affecting 42 Latvian municipalities, a decision the company is appealing. This breach, which exposed personal data of employees and residents, occurred due to ZZ Dats failing to fulfill its obligations under the General Data Protection Regulation (GDPR).
Over 180 million email accounts have been leaked — check to see if yours is on the list | Tom’s Guide The Have I Been Pwned website has added over 180 million email accounts to its database, containing leaked login details. Users can check if their email addresses have been compromised and are advised to change passwords and enable two-factor authentication for safety.
Marlink: Over 40% of maritime systems remain on Windows 10 ahead of end-of-support, heightening cyber risk - Industrial Cyber A recent report indicates that over 40% of maritime systems are still running on Windows 10, which has reached its end-of-support, significantly increasing cyber risk. While Windows 11 adoption is higher, the continued reliance on unsupported Windows 10 poses a threat to IT and OT environments due to the cessation of critical security updates.
Cyber Risk is the Weak Link in Data Center Construction The rapid growth of data center construction presents significant cyber risks, including attacks on subcontractors, manipulation of design data, and vulnerabilities in building management systems. These threats can lead to costly downtime, project delays, and physical damage, making cyber resilience a strategic imperative.
Global Survey Finds Cyber Incidents Cost Organizations $3.7M on Average in the Past Year | INN A recent Red Canary report, based on a survey of 550 security leaders, reveals that cyber incidents cost organizations an average of $3.7 million in the past year, with 46% experiencing service disruptions. The report also highlights the increasing reliance on AI in cybersecurity, with 85% of leaders concerned about being overwhelmed by missed threats if automation isn’t adopted, though they also cite AI-generated attacks as a top concern.
Former L3Harris cyber director charged with selling secrets • The Register A former general manager of L3Harris’s cyber arm, Peter Williams, has been charged with selling seven trade secrets to an unidentified Russian buyer for $1.3 million. Prosecutors are seeking to forfeit Williams’ lavish assets, including his home, multiple luxury watches, designer clothing, jewelry, and cryptocurrency.
APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign The APT36 hacking group, also known as Transparent Tribe, is targeting Indian government entities with a Golang-based malware called DeskRAT. The campaign employs spear-phishing emails with malicious attachments or links, aiming to compromise BOSS Linux systems and exfiltrate data.
UN agreement on cybercrime criticized over risks to cybersecurity researchers | CSO Online Critics argue that the new UN Convention against Cybercrime, set for ratification, contains vague language that could criminalize cybersecurity researchers and hinder cyber defense efforts. While some experts acknowledge improvements in defining malicious intent, others advocate for the established Budapest Convention as a superior alternative that better protects human rights.