Threats & incidents
-
Berlin breach deepens with credential leak
Berlin has confirmed that a second package of stolen government data contained access credentials, prompting tighter controls and temporary restrictions on some administrative systems.
-
Researchers redraw North Korea’s cyber structure
Sekoia and Kudelski Security have divided the old Lazarus umbrella into six operational clusters spanning espionage, financial operations, cryptocurrency theft, and fraudulent IT-worker activity.
-
France arrests suspects in ZeroBytes investigation
French prosecutors have confirmed arrests in the ZeroBytes investigation following attacks including the compromise of the national tax administration.
-
Bavarian utility keeps services running through attack
Stadtwerke Landsberg kept electricity, water, heating, fibre, and other services operating after attackers encrypted central IT systems, while forensic work continues over possible data exposure.
-
Rogue ScreenConnect clients propagate malicious scripts
Huntress has observed modified ScreenConnect clients deploying malicious scripts and propagating the same activity to newly connected systems, while ConnectWise separately prepares a file-transfer fix.
-
BigBear steals Microsoft 365 sessions at scale
CloudSEK says a phishing-as-a-service operation has used adversary-in-the-middle infrastructure to collect Microsoft 365 credentials and authenticated-session cookies across hundreds of organisations.
-
Teams impersonation moves beyond email fraud
Belgian authorities and Microsoft are warning about Microsoft Teams impersonation attacks that turn trusted collaboration workflows into routes for payment fraud and remote enterprise compromise.
-
Trezor breach expands over retained records
Trezor says its ShipMonk breach now affects about 81,000 customers after historical records that should have been deleted remained in the logistics provider’s systems.
-
N-central flaw draws exploitation warning
Dutch authorities say exploitation attempts have been observed against a maximum-severity N-central vulnerability, while N-able says it has no confirmed production exploitation.
-
Police reveal route into Odido breach
Dutch investigators say an attacker impersonated Odido’s IT department, captured an employee’s credentials and verification code, and gained access to data belonging to more than six million customers.










