NSA selects new leads for key cybersecurity posts

David Imbordino, an NSA senior executive who most recently led its cybersecurity directorate in an acting capacity, has been named as its new chief. Bruce Jones, a career NSA technical and operational leader, as the new head of its Cybersecurity Collaboration Center. | Continue reading


@therecord.media | 16 days ago

Microsoft says it will not pursue security researchers after zero-day backlash

Microsoft said it is taking the feedback seriously, adding: “To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.” | Continue reading


@therecord.media | 17 days ago

Afghan finance officials targeted by suspected Pakistani cyberespionage campaign

A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found. | Continue reading


@therecord.media | 17 days ago

Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years

More than half of the attacks observed over the past year targeted educational institutions, particularly maritime universities and schools that train personnel for Russia's shipping, inland waterway and fishing industries. | Continue reading


@therecord.media | 17 days ago

Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more

Each vulnerability was published with working proof-of-concept code to the Microsoft-owned code repository GitHub, making them immediately available to both attackers and security professionals. | Continue reading


@therecord.media | 20 days ago

Cruise giant Carnival confirms data breach affecting nearly 6 million people

The company said the threat actor gained access to a limited portion of its IT environment last month after compromising an employee account. By the end of April, Carnival determined that the attacker had copied personal information from its systems. | Continue reading


@therecord.media | 21 days ago

Canadian man gets 33 years for using social media to coerce US children into sending sexual content

Prosecutors said the man spent years using fake online identities to contact children and manipulate them into sending sexually explicit images and videos. | Continue reading


@therecord.media | 21 days ago

Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans

Cybercriminals have registered more than 4,300 fraudulent domains impersonating FIFA's official web presence since August 2025. | Continue reading


@therecord.media | 21 days ago

Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns

Anne Keast-Butler, director of GCHQ, said Russia's actions have prompted the agency to defend subsea cables and energy pipelines in British waters, disrupt Russian networks smuggling sanctioned technology and countering “reckless sabotage and assassination attempts.” | Continue reading


@therecord.media | 21 days ago

Romanian national sentenced to more than 4 years for hacking Oregon government systems

Dragomir was arrested in Romania in November 2024 and brought to the U.S. last year to face charges for hacking into the network belonging to Oregon’s Office of Emergency Management. | Continue reading


@therecord.media | 21 days ago

Rudd orders Cyber Command reviews as Pentagon presses reform agenda

Army Gen. Joshua Rudd, who took the twin-leadership reins of Cyber Command and the NSA in March, recently tapped MITRE to conduct a potentially wide-ranging review into the organization, according to three people familiar with the matter. | Continue reading


@therecord.media | 22 days ago

FBI warns extortion hackers are visiting US law firms to steal data

In a public advisory issued Tuesday the FBI said a hacking group has targeted law firms using social engineering schemes to gain remote access to corporate systems and exfiltrate data. | Continue reading


@therecord.media | 22 days ago

Dutch police arrest man over cyber breach at Ajax football club

The suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch National Police. | Continue reading


@therecord.media | 22 days ago

Iranian intelligence service behind hack of LA transit system, researchers say

The hacking group claimed to be a standalone hacktivist crew but actually has ties to the Ministry of Intelligence of the Islamic Republic of Iran (MOIS), researchers at Gambit Security said in a report published Tuesday. | Continue reading


@therecord.media | 22 days ago

Lithuania investigates theft of 600,000 state registry records by foreign actor

The Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency responsible for handling property and legal entity records. | Continue reading


@therecord.media | 23 days ago

Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations

Investigators seized more than 800 servers as they arrested two men suspected of violating European sanctions and assisting pro-Russian cyberattacks and disinformation campaigns. | Continue reading


@therecord.media | 23 days ago

Kremlin appoints cyber executive with alleged GRU ties to Security Council role

Andrei Kozlov, the former head of a cybersecurity center within Russia’s state-owned defense conglomerate Rostec, was named an aide to Security Council Secretary Sergei Shoigu on Friday. | Continue reading


@therecord.media | 23 days ago

FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks

The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments. | Continue reading


@therecord.media | 26 days ago

Meta settles school district lawsuit claiming addictive design harmed students' mental health

The bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not yet been tried. | Continue reading


@therecord.media | 26 days ago

Why the Supreme Court's Chatrie case could change the meaning of privacy in America

Lawyer Adam Unikowsky spoke with Recorded Future News about why he believes geofence searches are problematic and why the way the court rules could have a dramatic impact on Americans’ right to privacy. | Continue reading


@therecord.media | 27 days ago

Canadian man arrested, charged for running KimWolf DDos botnet

In court documents unsealed on Thursday, the Justice Department said Jacob Butler ran KimWolf as a DDoS-for-hire service that infected over a million devices worldwide. | Continue reading


@therecord.media | 27 days ago

CISA to allow researchers to report vulnerabilities to exploited bugs catalog

The Cybersecurity and Infrastructure Security Agency (CISA) announced the creation of a nomination form on Thursday that they said enables “researchers, vendors, and industry partners” to report bugs that need to be added to the Known Exploited Vulnerabilities catalog. | Continue reading


@therecord.media | 27 days ago

Hackers steal patient and billing data from German hospitals via third-party provider

The large-scale data breach reportedly hit Unimed, a company that handles billing services for privately insured and self-paying patients on behalf of numerous German hospitals. | Continue reading


@therecord.media | 27 days ago

Belarus-linked hackers use fake training certificates to target Ukrainian officials

A Belarus-linked hacking group known as GhostWriter has launched a new espionage campaign against Ukrainian government officials using fake emails disguised as messages from a popular online learning platform to deliver malware. | Continue reading


@therecord.media | 27 days ago

Tech giants promise British regulator they will tweak platforms to protect kids online

The regulator, Ofcom, had required Roblox, Snapchat, Instagram, Facebook, YouTube and TikTok to answer questions about their efforts to remove harmful algorithms, check kids’ ages and protect them from sexual predators by the end of April. | Continue reading


@therecord.media | 27 days ago

Two Americans plead guilty to assisting India-based tech support scam centers

Adam Young, 42, and Harrison Gevirtz, 33, pleaded guilty to misprision of a felony after they were accused of offering phone numbers, call routing services, call tracking tools and call forwarding services to India-based telemarketing fraudsters. | Continue reading


@therecord.media | 27 days ago

UK plans for cybercrime law reform would protect almost no one, experts warn

The proposals would require researchers to cease activity the moment a vulnerability is identified, meaning they could not confirm it was real, assess its severity or determine its exploitability. | Continue reading


@therecord.media | 28 days ago

Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems

In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — part of a broader effort to reduce reliance on Western technology and build a more independent techn … | Continue reading


@therecord.media | 28 days ago

Europe dismantles VPN service used by cybercriminals to hide ransomware attacks

The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way for criminals to evade law enforcement. | Continue reading


@therecord.media | 28 days ago

FTC warns 12 major tech firms of violating Take It Down Act

The law mandates that platforms make it easy for people to ask that nonconsensual intimate images be removed and to delete them within 48 hours of a request. | Continue reading


@therecord.media | 28 days ago

Ukraine probes teen suspect in cyber theft scheme targeting California online shoppers

The investigation began after U.S. authorities informed their Ukrainian counterparts that hackers operating from Ukraine could be involved in attacks targeting users of American e-commerce platforms, Ukraine's Prosecutor General said. | Continue reading


@therecord.media | 29 days ago

Discord migrates all users to end-to-end encryption by default

The move comes as other major social media platforms are killing end-to-end encryption for messaging. In recent months, Instagram and TikTok both announced they will no longer offer the feature. | Continue reading


@therecord.media | 29 days ago

7-Eleven confirms breach after ShinyHunters claims

The breach notification letters say 7-Eleven discovered the breach on April 8 and, after an investigation, determined that the cybercriminals gained access to “certain 7-Eleven systems used to store franchisee documents.” | Continue reading


@therecord.media | 29 days ago

Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs

In most complaints, victims said they were given detailed information by fraudsters on how to take money from their bank account, where to find a cryptocurrency kiosk and how to send the funds. | Continue reading


@therecord.media | 29 days ago

GitHub confirms being hacked by TeamPCP, says customer data unaffected

Github, which hosts code for more than 100 million developers worldwide, confirmed the breach on social media after TeamPCP advertised stolen source code on a cybercrime forum. | Continue reading


@therecord.media | 29 days ago

Senator presses CISA for answers about alleged GitHub repository leak

U.S. Senator Maggie Hassan (D-NH) sent a letter to the acting director of the Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday demanding answers about an alleged breach uncovered by cybersecurity reporter Brian Krebs involving government contractor Nightwing. | Continue reading


@therecord.media | 29 days ago

Ukraine says Russia is deploying AI-powered malware on the battlefield

A new report from Ukraine’s National Security and Defense Council says Russia’s use of AI across cyber operations expanded dramatically over the past year, reshaping everything from social engineering campaigns to malware development and creating what Ukrainian officials describe … | Continue reading


@therecord.media | 29 days ago

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

There is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company. | Continue reading


@therecord.media | 29 days ago

UK regulator to require tech firms to tackle deepfakes, non-consensual intimate images

The regulator’s announcement said the change is being made due to the “urgent need to better protect women and girls online.” | Continue reading


@therecord.media | 1 month ago

Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs

The company unsealed a legal case in U.S. District Court on Tuesday detailing the disruption of Fox Tempest — a popular service that has operated since May 2025 and provides cybercriminals with code signing tools. | Continue reading


@therecord.media | 1 month ago

More than 200 arrested in cyber raids aimed at Middle East scam networks

Investigators found hundreds of compromised devices that were used as part of the cybercriminal operation and notified device owners as part of the raids. | Continue reading


@therecord.media | 1 month ago

Grafana refuses to pay ransom after codebase theft

On Saturday night, the company released a statement confirming the incident and outlining their decision not to pay a ransom issued by the hackers behind the attack. | Continue reading


@therecord.media | 1 month ago

Experts warn of privacy risks as AI firms looks to connect to financial accounts

OpenAI announced Friday that it is rolling out a new ChatGPT feature allowing users to connect all of their financial accounts to the chatbot for personal finance advice. | Continue reading


@therecord.media | 1 month ago

Experts warn of privacy risks as AI firms looks to connect to financial accounts

OpenAI announced Friday that it is rolling out a new ChatGPT feature allowing users to connect all of their financial accounts to the chatbot for personal finance advice. | Continue reading


@therecord.media | 1 month ago

More than $10 million stolen from crypto platform THORChain

THORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million. | Continue reading


@therecord.media | 1 month ago

CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday

Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.” | Continue reading


@therecord.media | 1 month ago

OpenAI asks macOS users to update after TanStack npm supply chain attack

The actions are being taken in light of an expanding supply chain campaign impacting the popular open-source library TanStack and additional npm and PyPI packages tied to several AI companies. | Continue reading


@therecord.media | 1 month ago

ODNI taps officials to coordinate response to foreign election threats

Director of National Intelligence Tulsi Gabbard has tapped two individuals to coordinate work across U.S. spy agencies to monitor threats to the 2026 elections, according to multiple sources familiar with the matter. | Continue reading


@therecord.media | 1 month ago