Rainbow Six Siege is experiencing another security issue, possibly a cyberattack, leading to outages and ongoing investigations by Ubisoft, who previously had to shut down the game due to attackers taking control.
Cybersecurity researchers uncovered a targeted spear-phishing campaign using 27 malicious npm packages to host browser-based phishing lures mimicking document-sharing portals and Microsoft sign-in pages, primarily targeting organizations in critical infrastructure sectors across multiple countries. The campaign leverages package CDNs for resilient hosting, employs anti-analysis techniques, and hard-codes specific email addresses, with the goal of stealing login credentials. The activity highlights ongoing threats in the software supply chain, emphasizing the need for stringent dependency verification and monitoring.
Shares of Coupang rose about 9% after the company announced it had resolved a cyberattack that exposed limited building entrance codes and some user data, but no payment or login information was compromised, and the hacker was identified as a former employee.
A pro-Russian hacking group claimed responsibility for a DDoS cyberattack that disrupted France's postal service just before Christmas, affecting package deliveries and online banking, as part of broader hybrid warfare efforts against Western countries supporting Ukraine.
Kuaishou, a major Chinese short-video platform, was hit by a cyberattack involving AI that flooded it with porn and violent videos, leading to platform disruptions and raising concerns about cybersecurity and content regulation in China.
A major cyberattack, likely a DDoS, disrupted France's postal service and banking operations just days before Christmas, causing delays and service outages amid ongoing concerns about cyber warfare involving Russia and other foreign actors.
France's postal service and banking division, La Poste and La Banque Postale, were hit by a suspected DDoS cyberattack during the Christmas period, disrupting package deliveries and online banking services. The incident follows previous attacks on La Poste and recent cyber breaches involving France's government and a suspected international ferry hacking plot, highlighting ongoing concerns about cyber threats and foreign interference in France.
A suspected cyberattack involving a DDoS incident disrupted France's La Poste postal service and La Banque Postale banking during the Christmas season, causing delays in mail delivery and online banking services, though customer data remained unaffected.
Denmark publicly blames Russia for cyberattacks in 2024 and 2025 targeting a water utility and government websites, linked to pro-Russian hacking groups, as part of Russia's broader hybrid warfare against the West, causing limited damage but highlighting vulnerabilities in critical infrastructure.
Denmark accuses Russia of orchestrating two major cyber-attacks, including a water utility hack and DDoS attacks targeting Danish websites, as part of a broader hybrid war effort to undermine Western support for Ukraine, with evidence linking pro-Russian groups to the Russian state.
SonicWall has issued a warning about a new zero-day vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in attacks to escalate privileges. The flaw is being exploited in conjunction with another critical vulnerability (CVE-2025-23006) to execute remote code with root privileges. SonicWall advises users to update to the latest firmware to mitigate the risk, as over 950 appliances are exposed online. This follows recent security breaches and malware attacks targeting SonicWall devices.
Multiple companies including Pornhub, SoundCloud, and Askul experienced data breaches affecting millions, primarily involving exposure of email addresses and user information through compromised analytics tools or ransomware attacks, with most sensitive data like passwords and payment details remaining secure.
Germany's Bundestag experienced a major email outage suspected to be a cyber attack coinciding with Zelenskyy's visit and high-stakes talks, amid ongoing tensions with Russia over cyber warfare, sabotage, and disinformation campaigns.
ClickFix is a sophisticated scam campaign targeting Windows and macOS users by exploiting trust in online travel bookings and using social engineering tactics, such as fake CAPTCHA prompts and device-adaptive payloads, to infect devices with malware like PureRAT. The attacks leverage native OS capabilities and often bypass security tools, making awareness and cautious behavior the best defenses, especially during holiday gatherings when family members may be less vigilant.
Cybersecurity researchers have identified three malicious VS Code extensions linked to the GlassWorm campaign, which uses invisible Unicode characters to hide malware, steal credentials, and spread in a worm-like fashion. Despite removal efforts, the threat has resurfaced, leveraging blockchain-based command-and-control infrastructure to maintain resilience. The attack has affected victims worldwide, including a major Middle Eastern government, and has expanded to target GitHub repositories.