• Polish authorities have arrested a Russian citizen suspected of conducting unauthorized cyberattacks against the computer networks of local organizations.

    The arrest marks a significant development in the country’s efforts to combat cybercrime targeting Polish and European businesses.

    On November 16, 2025, officers from the Central Bureau for Combating Cybercrime, operating under the Krakow District Prosecutor’s Office, detained the suspect.

    According to authorities, the individual illegally entered Poland in 2022 and obtained refugee status in 2023. The suspect has since been accused of carrying out sophisticated cyberattacks against multiple targets.

    Unauthorized Network Access

    Investigators confirmed that the suspect gained unauthorized access to IT systems operated by a local online store. The attack involved breaching security measures to access sensitive databases and tampering with their structure.

    This attack is a serious threat to business systems and customer data. After questioning and filing charges, prosecutors asked for the suspect to be held until trial.

    The District Court for Kraków-Śródmieście approved this request, ordering the suspect to remain in custody for three months.

    Authorities believe the suspect may be part of a larger network of cybercriminals targeting organizations across Poland and the European Union.

    Investigators are currently working to identify additional victims and determine the full extent of the damage caused by these cyberattacks.

    The investigation remains ongoing as prosecutors work to determine the scope of the suspect’s criminal activities and any potential connections to organized cybercrime groups operating in the region.

    This case highlights the growing threat posed by state-sponsored or internationally based cybercriminals targeting European infrastructure.

    Polish authorities continue to strengthen their cybersecurity defenses and international cooperation to combat such threats.

    The arrest demonstrates Poland’s commitment to investigating and prosecuting cybercriminals, regardless of their national origin.

    As cyber threats continue to evolve, law enforcement agencies across Europe are enhancing their capabilities to identify and apprehend individuals responsible for network intrusions and data breaches.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Poland Arrested Suspected Russian Citizen Hacking for Local Organizations Computer Networks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has announced a significant security upgrade to its Microsoft Entra ID authentication process, as part of the company’s broader Secure Future Initiative.

    Microsoft is updating its Content Security Policy (CSP) to block the execution of external scripts during user sign-ins.

    This proactive measure is designed to shield organizations from evolving cyber threats, specifically cross-site scripting (XSS) attacks, where hackers attempt to inject malicious code into legitimate websites.

    What Is Changing?

    Currently, some browser extensions or tools may inject scripts into the sign-in page to modify its behavior or appearance. Starting in mid-to-late October 2026, Microsoft will enforce a stricter policy on login.microsoftonline.com.

    Under this new rule, only scripts from trusted Microsoft domains will be allowed to run. Any unauthorized or external code attempting to execute during the login process will be automatically blocked.

    This change ensures that the sign-in experience remains a closed, secure environment, preventing attackers from exploiting vulnerabilities in third-party scripts.

    It is important to note that this update applies only to browser-based sign-ins on the specific Microsoft login URL; Microsoft Entra External ID will not be affected.

    Microsoft advises organisations to stop using any browser extensions or custom tools that modify the Entra ID sign-in page via script injection.

    While the login process itself will continue to function for users, any tools relying on injecting code will stop working once the update is enforced.

    To get ready, IT administrators should test their sign-in flows ahead of the 2026 deadline. You can identify potential issues now by opening the developer console in your browser while signing in.

    If your organization uses tools that violate the new policy, error messages will appear in red text in the console.

    Megna Kokkalera, Product Manager II at Microsoft, emphasized that this update adds a critical layer of defense for user identities.

    By eliminating the risk of unverified scripts, Microsoft ensures that organizations stay ahead of emerging security threats while maintaining a seamless, secure sign-in experience.

    Administrators are encouraged to assess their environments early to ensure a smooth transition when the policy goes into effect globally next year.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft to Block External Scripts  in Entra ID Logins to Enhance Protections appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a significant escalation of the global cyber threat landscape, the notorious threat group ShinyHunters appears to be transitioning from data theft to full-scale ransomware operations. Cybersecurity researchers have identified an early build of a new Ransomware-as-a-Service (RaaS) platform dubbed “ShinySp1d3r,” marking the first instance in which the group has eschewed external encryption tools in […]

    The post ShinyHunters Develop Sophisticated New Ransomware-as-a-Service Tool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Three West London councils are struggling with significant disruption to IT systems and phone lines after a cyberattack on a shared services provider, which officials are publicly describing only as an “IT incident”.

    The Royal Borough of Kensington and Chelsea (RBKC), Westminster City Council (WCC), and Hammersmith and Fulham Council have all been affected.

    According to statements from RBKC, the issue was first acknowledged on Tuesday evening, November 25.

    When the council confirmed it was “responding to a cyber security issue” and working with its partners to investigate and restore services.

    Cyberattack Disrupts IT and Phone Services

    According to cyberplace, the attack disrupted key back-office systems provided through their shared services setup, affecting online services and making it harder for residents to reach the councils.

    Local reports say some phone lines and customer services have been going down or running slowly, forcing residents to use limited options or visit council offices in person for urgent needs.

    Although the councils haven’t confirmed it as ransomware, experts say the signs point to a ransomware attack affecting a shared IT provider used by several London authorities.

    Commentators have noted that describing it as an “IT incident” is a common tactic used early in serious cyber events while investigations and containment are still underway.

    The councils say they are working with external cybersecurity specialists and national agencies to understand the scope of the breach, protect data, and bring systems back online safely.

    Critical services, such as social care and emergency support, are being prioritised, with manual workarounds in place where digital systems are unavailable.

    Residents are being asked to check council websites and official social media for updates, expect delays on phone lines, and use online forms or email when possible.

    The full extent of the impact, including any potential data compromise, has not yet been confirmed as the investigation continues.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post London Councils’ IT Systems Impacted by CyberAttack, Including Phone Lines appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Shai Hulud 2.0 worm, first detected on November 24, 2025, has compromised nearly 1,200 organizations, including major banks, government bodies, and Fortune 500 technology firms.

    While initial reports described it as a simple npm supply chain attack that flooded GitHub with spam repositories, new analysis reveals a far more sophisticated operation.

    Entro Security researchers observed that the malware did not just create noise; it successfully exfiltrated sensitive runtime memory and credentials from deep within corporate CI/CD pipelines.

    Early analysis focused on the thousands of attacker-controlled GitHub repositories generated by the worm. However, researchers at Entro Security have confirmed that these repositories were merely the “collection layer” for a much larger heist.

    The true damage occurred inside the victim environments, developer endpoints, cloud build servers, and self-hosted GitHub runners, where the malware executed payload scripts during the “preinstall” phase of compromised npm packages.

    Instead of just scraping static files, Shai Hulud 2.0 captured full runtime environments. Entro Security analysis found that the generated artifacts, like environment.json, contained double-base64-encoded memory snapshots.

    Shai Hulud 2.0 Double-encoded memory Snapshots
    Shai Hulud 2.0 Double-encoded memory Snapshots

    These snapshots allowed attackers to reconstruct the exact state of compromised machines, granting them access to in-memory secrets that never appeared in code repositories.

    The scale of the compromise is staggering. Entro researchers identified 1,195 distinct organizations by analyzing email domains, internal hostnames, and tenant identifiers found in the exfiltrated data.

    organizations Impacted
    organizations Impacted (Credits: Entro)

    Technology and SaaS companies suffered the most from the attack, representing over half of the identified victims.

    Industry SectorNumber of Compromised Orgs
    Technology / SaaS647
    Financial Services & Banking53
    Healthcare38
    Insurance26
    Media21
    Telecom20
    Logistics15

    Two specific examples highlight the severity of the breach. The first involved one of the world’s largest semiconductor companies, where a self-hosted GitHub Actions runner was compromised.

    The decoded memory dump exposed active GitHub Personal Access Tokens and internal hostnames, proving the attackers had valid entry points into the company’s internal infrastructure.

    The second victim was a Tier-1 digital asset custody provider. In this case, the malware struck a GitLab CI pipeline. The exfiltrated data included live AWS secret keys, blockchain production tokens, and Slack API keys.

    Critically, scans conducted on November 27, three days after the initial disclosure, revealed that some of these high-value credentials, including Google Cloud Service Account keys, were still valid and had not been revoked.

    The GitHub repositories associated with Shai Hulud 2.0 are being removed, but the stolen credentials remain in the attacker’s hands. The campaign demonstrates that any environment where code is executed, whether a local laptop or a cloud-based CI runner, is a potential target for memory scraping.

    With valid secrets circulating days after the attack, organizations are urged to rotate all non-human identities and treat their runtime environments as fully compromised.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity firm GreyNoise has launched a new, free utility designed to answer a question most internet users never think to ask: Is my home router secretly attacking other computers? The newly released GreyNoise IP Check is a simple, web-based tool that allows anyone to instantly verify whether their internet connection is being used by a […]

    The post New GreyNoise IP Checker Helps Users Identify Botnet Activity appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated, complex new cyber offensive has emerged from the “Scattered Lapsus$ Hunters,” a threat collective that has aggressively shifted toward exploiting supply-chain vulnerabilities.

    This latest campaign targets Zendesk, a critical customer support platform, effectively turning a trusted business tool into a launchpad for corporate spying.

    The attackers have successfully registered over 40 typosquatted domains, including deceptive examples like znedesk[.]com and vpn-zendesk[.]com.

    These sites are meticulously designed to mimic legitimate login environments, hosting fraudulent Single Sign-On (SSO) portals that capture credentials from unsuspecting users.

    The campaign’s infrastructure reveals a coordinated effort to bypass standard detection protocols. The domains were consistently registered through NiceNic and use Cloudflare-masked nameservers to hide their true hosting origins.

    By using these hiding techniques, the actors ensure their phishing pages remain active long enough to harvest significant volumes of high-privilege credentials before defenders can react.

    This demonstrates a clear, strategic evolution in their capabilities, allowing them to maintain operational secrecy while targeting widespread platforms used by global enterprises.

    The impact of this targeted approach extends far beyond simple credential theft. Reliaquest security analysts identified the malware and noted that the campaign shares distinct domain registry characteristics with the group’s previous attacks on Salesforce in August 2025.

    Once attackers bypass the initial authentication layer, they establish a persistent foothold that facilitates lateral movement across the corporate network.

    This access allows them to steal highly sensitive customer data, including billing information and government IDs, mirroring the massive data theft seen in their September 2025 breach of Discord.

    Weaponizing Support Tickets

    The group’s most dangerous tactic involves the direct weaponization of legitimate support tickets to bypass traditional perimeter defenses.

    Instead of relying solely on external phishing emails, they submit fraudulent tickets directly into an organization’s Zendesk portal.

    These tickets typically masquerade as urgent system administration requests or password reset inquiries, creating a fabricated sense of urgency that compels support agents to act without verification.

    Embedded within these tickets are links to the typosquatted domains or malicious payloads designed to compromise the endpoint.

    When a help-desk employee interacts with the ticket, they accidentally trigger the download of Remote Access Trojans (RATs).

    This grants the attackers persistent remote control, allowing them to execute commands and monitor activity.

    Scattered Lapsus$ Hunters Telegram post (Source – Reliaquest)

    The group has brazenly boasted about these complex operations, specifically warning incident response teams to watch their logs closely as they prepare to collect vital customer databases through the upcoming 2026 holiday season.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Scattered Lapsus$ Hunters Registered 40+ Domains Mimicking Zendesk Environments appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Comcast has agreed to a $1.5 million settlement with the Federal Communications Commission (FCC) following a data breach at a third-party vendor that exposed the personal information of hundreds of thousands of its customers. The breach has raised concerns about the security of customer data when handled by external companies. The incident originated with Financial […]

    The post Comcast Fined $1.5 Million to Settle FCC Probe Tied to Vendor Data Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has announced a significant security change to the Microsoft Entra ID sign-in experience that will block external scripts from running during user logins. The update is designed to stop unauthorized or injected code from executing on the login page. It is part of Microsoft’s broader Secure Future Initiative to harden its cloud identity platform. […]

    The post Microsoft Blocks External Scripts in Entra ID Logins to Boost Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Royal Borough of Kensington and Chelsea (RBKC), Westminster City Council, and Hammersmith and Fulham Council confirmed they were targeted in the incident that began on Monday, November 24. The attack has forced officials to shut down systems as a precautionary measure while they work to restore services and investigate potential data compromise. The first […]

    The post London Councils Hit by Cyberattack, Disrupts IT and Telephone Lines appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶