Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS

Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.  Jamf Threat Labs fir...

All the recent news you need to know

California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time

 



A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against NSO Group, the Israeli company behind the Pegasus spyware allegedly used to surveil their phones for nearly two years. The ruling, issued Wednesday, marks the second time the case has been thrown out on jurisdictional grounds, though the journalists' legal team at the Knight First Amendment Institute at Columbia University has said it intends to appeal.

The case, Dada v. NSO Group, was the first lawsuit against NSO filed in any U.S. court when the Knight Institute took it on in November 2022 on behalf of 18 current and former El Faro journalists and staff. Between June 2020 and November 2021, Pegasus spyware was deployed against the outlet's employees at least 226 times, according to the Institute. Digital forensic analysis eventually confirmed that 22 members of El Faro's staff had their phones infected. The attacks were not random. Surveillance peaked during significant political moments and in the run-up to major investigations, including reporting on the Bukele administration's secret negotiations with criminal gangs, the theft of pandemic food relief, back-channel Bitcoin dealings, and the financial holdings of government officials.

The lead plaintiff, Carlos Dada, is the co-founder and director of El Faro, one of Central America's most prominent independent news organizations. El Faro was founded in El Salvador in 1998 and has built a reputation for independent investigative reporting. The outlet has paid a steep price for that journalism. Beyond the spyware attacks, El Faro says it has faced physical surveillance, advertiser harassment, and public defamation from government officials and ruling-party legislators. In 2023, the newsroom relocated its administrative and legal operations out of El Salvador entirely.

The core question before the court was whether Northern California was the right place to try this dispute. Dada and the plaintiffs argued it was, pointing to compromised U.S.-based infrastructure that was used as part of the attack chain. The judge was not persuaded. The court noted that there was no allegation Apple's California servers were actually exploited in delivering the Pegasus infections, even where the plaintiffs alleged the attacks moved through Apple's iMessage or iCloud systems. The same argument had failed once before: in March 2024, a California federal judge threw out the same lawsuit, saying the case was "entirely foreign" and that the journalists had no standing to sue in the U.S.

That first dismissal did not hold. The Ninth Circuit Court of Appeals reversed the March 2024 ruling in July 2025 and sent the case back to the Northern District of California, finding that the lower court erred in its analysis. The Ninth Circuit had concluded that the district judge failed to properly account for allegations that NSO created Apple ID accounts and engaged with California-based servers as part of the attack infrastructure. One factor that also came into play was a recent acquisition of NSO Group by a group of American investors, which El Faro's lawyers cited as further reason for trying the case on U.S. soil. After the Ninth Circuit's reversal, Dada called the outcome "good news." That window has now closed again.

The journalists had wanted specific remedies from the court. They asked the court to require NSO Group to identify, return, and delete all information obtained through the attacks, to prohibit the company from deploying Pegasus against them again, and to name the government client that commissioned the surveillance. That last demand was perhaps the most politically charged. NSO has never publicly identified its clients. The company maintains it sells Pegasus exclusively to government agencies for use against criminals and terrorists, subject to Israeli government authorization. El Salvador's government has repeatedly denied being an NSO client or playing any role in the surveillance.

With Apple having dropped its own case against NSO in September 2024, and WhatsApp having won a $167 million judgment against the company earlier in 2025, the El Faro lawsuit had become the last active case against NSO Group in U.S. courts. That distinction is now moot, at least temporarily.

The Knight First Amendment Institute plans to appeal. El Faro's director Carlos Dada said when the original lawsuit was filed that the outlet turned to the U.S. court system because justice in El Salvador was not possible. With the case now dismissed a second time and the appeal road still open, that search for accountability continues.

NSO Group did not respond to a request for comment.



DTU Data Breach Exposes Information of 200,000 People

 


The Technical University of Denmark (DTU) has disclosed a major data breach that may have exposed personal information belonging to as many as 200,000 current and former users. Hackers reportedly accessed DTUBasen, the university’s identity and access management system, after obtaining valid credentials. The system contains records collected over more than two decades, raising concerns about identity theft, targeted phishing and other forms of fraud.

DTU said it cannot yet determine exactly which information attackers downloaded or how many people have been affected. However, the database contains details linked to nearly 40,000 active users and approximately 160,000 former users. Information related to current users may include Danish civil registration numbers, full names, home addresses, profile photographs, work email addresses, job titles, office locations and other employment details. 

The breach may also have exposed emergency-contact information submitted by active users. This could include the names, relationships and phone numbers of next of kin. DTU noted that information about home addresses, profile pictures and next of kin belonging to former users is automatically deleted after six months. University Director Bjarke Bak Christensen described the incident as a serious attack and apologised for the uncertainty caused to potentially affected individuals. 

DTU plans to notify potentially impacted people through e-Boks, Denmark’s official digital mailbox service. The university said it will contact current and former employees, although not every student whose information may be stored in the system will receive a direct notification. Anyone who has been a DTU employee, student, guest or external partner since 2003 could potentially be affected, according to the university’s public warning. 

The university is advising affected individuals to remain alert for suspicious emails, text messages and phone calls that mention their connection with DTU or contain accurate personal details. People should avoid sharing passwords, personal information or authentication codes in response to unexpected requests. They should also change reused passwords on other services and consider placing a credit alert on their affected civil registration number. The incident highlights how compromised credentials can give attackers access to extensive historical records, even when an organisation’s main systems remain operational.

China-Aligned TA419 Uses Microsoft AitM Phishing Against U.S. AI Policy Experts

 

A China-linked cyber-espionage group is targeting Microsoft credentials belonging to U.S. policy and regulatory specialists in artificial intelligence, using highly focused social engineering techniques. 

TA419, the threat actor behind the campaign, has diversified its interest from defense, national security, energy, international relations and foreign policy to include those involved in the policy and regulation of AI, a Proofpoint analyst reported. The group has been targeting U.S. and Japan-based think tanks, defense contractors, universities and law firms through credential phishing since at least April 2025. 

One technique, deployed in a February 2026 campaign, involved impersonating prominent figures in economic and AI policy, as well as an Anthropic employee, in an email titled “Request for Feedback on Military Integration of Claude” to influence an AI policymaker at a U.S. think tank. Similarly, around July, the group began targeting individuals including a former White House Office of Science and Technology Policy (OSTP) leadership team member with an impersonation campaign. The attack chain is designed to appear to have come from a trusted source, not direct phishing. 

First, the victim receives an innocuous request designed to gain the confidence of their target by referencing a shared professional interest. If it gets a response, it then replies with a shortened URL. Once the link is clicked, the victim is directed to a Microsoft OneDrive-like adversarial in-the-middle phishing site after several redirections. The Cloudflare Turnstile Captcha is integrated into the attack chain, helping to lend credibility to the link. 

The credential harvesting component of the attack uses a technique called Frameless BitB, which uses a browser-in-the-browser approach to create the illusion of a separate window using only HTML, CSS and JavaScript. This differs from previous use of Bitb by this threat actor, which used an iframe. Proofpoint noted that TA419 has been modifying an open-source iteration of the attack to incorporate its own telemetry and automation components. The campaign uses an in-the-middle proxy to compromise Microsoft authentication by impersonating a legitimate login page.

It appears to be a legitimate login page; however, it is actually using the authentication token from the user’s Microsoft account to gain access to the account. This technique can be challenging to detect because the Microsoft logon page can appear to be authentic while the attacker’s application window is using some of the user’s session information. This allows the attacker to use the credentials to access the Microsoft account. Proofpoint noted that the activity supports Chinese intelligence interests by providing insight into the U.S. regulatory and policy environment around AI. 

The intensifying U.S.-vs-China strategic competition over AI, including issues around model distillation and export controls, appears to be a catalyst for the campaign. Entities should consider implementing phishing-resistant authentication factors such as passkeys, and individuals who received unexpected professional or professional correspondence should take steps to independently verify the request before responding or following any links.  

While the shift to AI policy experts represents a new focus area for TA419, it is not a significant change in the group’s interests. According to Proofpoint, this is an evolution, rather than a revolution, of the group’s current targeting.

China's Ministry Allegedly Funded Research Involving 100+ Academics


The U.K.’s domestic intelligence agency, MI5, has warned that more than 100 U.K.-linked academics have contributed to research projects allegedly funded by China’s Ministry of State Security (MSS).

Impacted areas

The research reportedly covered areas including artificial intelligence (AI), cybersecurity, covert communications and steganography.

The warning was issued in an MI5 Security Service Espionage Alert on September 30, 2026. According to MI5, the research funding was channelled through the China General Technology Research Institute (CGTRI), also known as the China Academy of General Technology (CAGT). 

About the warning

MI5 assessed that CGTRI is being used as a front for China’s MSS and claimed that its primary purpose is to fund research that can improve the Chinese intelligence service’s technical capabilities.

“The alert advises UK academic institutions to immediately review any ongoing or planned collaboration with CGTRI and advises academics to establish the ultimate funding source when conducting any research collaboration with Chinese institutions to ensure CGTRI are not involved,” reads the MI5 security alert.

Associated risks 

The areas of research identified by MI5 are particularly significant from a cybersecurity and intelligence perspective. Artificial intelligence can be used for data analysis, automation and surveillance, while cybersecurity research can contribute to offensive and defensive cyber capabilities.

The alert also revealed covert communications and steganography. Steganography involves hiding information inside another form of digital content, such as an image or audio file, making it potentially useful for concealing communications.

MI5 said that more than 100 academics linked to the U.K. had contributed to projects funded through CGTRI. The agency also said that some researchers may not have known that CGTRI was financially supporting the research they were involved in. 

MI5 further added, “It puts the fact that CGTRI has very strong ties to MSS in the public domain and states that academic institutions, staff and researchers should ensure they are aware of the National Security Act 2023.  Any institution or individual continuing to conduct research ultimately funded by CGTRI should take their own independent legal advice.”

Potential risks

MI5 warned that research developed through these collaborations could potentially strengthen Chinese intelligence capabilities. The agency particularly highlighted the risk to the U.K. because some of the technologies involved could have applications in cyber operations and intelligence gathering.

Chinese Embassy’s Response 

China has rejected the allegations. The Chinese Embassy in the U.K. described the claims as fabricated and baseless, arguing that academic exchanges between British universities and China are voluntary, lawful and mutually beneficial.

Polish Dental Software Firm Hit by Cyberattack

 

Polish dental software provider FELG Software has confirmed a cybersecurity incident affecting its FELG Dent cloud-based practice management platform. The company became aware of the attack on September 28, 2026, and publicly acknowledged it on October 1. A threat actor using the alias Horus reportedly contacted Polish cybersecurity news outlets, claiming to have accessed sensitive information stored in the system. FELG Software also confirmed receiving a ransom demand in exchange for preventing the disclosure of the allegedly stolen data. More than 16,000 dentists reportedly use the company’s tools, meaning one vendor breach could affect patients from numerous independent practices. 

The attackers claim to have obtained records linked to approximately 2.4 million patients and more than 700,000 medical professionals. The allegedly exposed information includes names, addresses, telephone numbers, national identification numbers known as PESEL, company details, medical records, electronic prescriptions, electronic sick-leave certificates and insurance-verification information. The group also claims to have accessed around 1.2 million prescriptions, visit documentation and diagnostic images. However, these figures have not been independently verified, and the company disputes the attackers’ assessment of the incident’s scale. 

FELG Software has reportedly said that the stolen information represents about 10 percent of its overall database, rather than the complete dataset claimed by Horus. Reports also indicate that the attackers threatened to publish or sell the information after the company refused to pay the ransom. One reported explanation for the intrusion involves an IDOR vulnerability, or Insecure Direct Object Reference flaw. Such weaknesses can allow unauthorized users to manipulate references in requests and retrieve records belonging to other accounts when access controls are not properly enforced. 

The incident is significant because FELG Dent operates as a shared platform for many healthcare organizations. A weakness in the central service can therefore create risks across multiple dental practices at the same time. The breach is also reportedly the third attack in three months targeting Polish healthcare software providers, following incidents involving MyDr in August and Medyc, operated by Qbusoft, in September. These repeated attacks highlight the risks created when sensitive medical information is concentrated in cloud systems without strong tenant isolation, monitoring and access controls. 

The exact scope of the FELG Dent breach remains under investigation. Dental practices using the service may need to review logs, identify affected patients and assess their legal notification responsibilities under applicable data-protection rules. Healthcare providers should also reset potentially compromised credentials, monitor suspicious activity and communicate carefully with patients without relying solely on unverified attacker claims. The case demonstrates why software vendors handling medical data require regular security testing, strict authorization controls, vulnerability disclosure processes and tested incident-response plans. Until forensic investigations are complete, the number of affected records and the precise information accessed should be treated as provisional.

ShinyHunters Hacker Reportedly Detained as FBI Seeks Cooperation


The FBI has reportedly detained a suspected ShinyHunters member known online as “Rey” and is cooperating with the government. Jordanian authorities captured a suspect identified as Saif al-Din Khader this week. According to two sources cited by Reuters, Khader is helping U.S. and international investigators identify other members of the hacking group. 


It is believed that Khader's cooperation will provide investigators with information regarding the group's activities and alleged co-conspirators, according to a source. He has shown investigators his electronic devices and digital communication to help locate other suspected members. The FBI has not responded to Khader's reported detention specifically, however it has stated that it is continuing to investigate the recent cyber incident allegedly involving ShinyHunters and is collaborating with international partners to resolve the matter. 

A series of law enforcement actions targeting individuals affiliated with ShinyHunters has led to this reported detention. Dutch authorities arrested a 24-year-old man in connection with an investigation into the group in September. Following the arrest, the FBI issued a warning encouraging other suspected members to surrender while they continued to investigate the matter. 

The developments are following the claim by ShinyHunters that a job portal breach had taken place. As claimed by the group, it obtained a significant amount of sensitive information from FBI systems. Particularly, it claimed to have acquired employee information, though the extent of the alleged theft has yet to be independently verified. During Khader's reported detention, the group's online activity was also disrupted. 

In addition to the disappearance of the group's data leak website, an account previously used to communicate with journalists no longer responded. Later, another ShinyHunters leak site appeared, indicating the group may continue to conduct activities. Moreover, Khader's reported cooperation strengthens the investigation, which has already been conducted by several individuals associated with the ShinyHunters network in general. 

Khader's identity was previously associated with the group until the latest detention was made. It has been reported that Brian Krebs identified Khader as a member of the Scattered Lapsus$ Hunters umbrella operation in 2025, which is affiliated with ShinyHunters, Lapsus$, and Scattered Spider. Aside from being linked to the HellCat leak site and BreachForums hacking forum, Khader had previously asserted that he was cooperating with law enforcement and had ceased all data theft and extortion activities. Those claims were not independently verified. 

While this was the case, ShinyHunters continued to conduct attacks in 2026, including attacks on Rockstar Games as well as Canvas, which disrupted schools across the country. Despite this, the group has continued to engage in data theft and extortion operations. ShinyHunters has recently begun targeting cloud-based services as well as third-party providers, resulting in incidents that are linked to organizations such as Google, Cisco, and Pornhub.

ShinyHunters has also been linked to the May 2026 breach involving Instructure Canvas, while previous investigations have resulted in arrests related to Snowflake-related attacks, PowerSchool and Breached hacking forums. It may be possible for investigators to gain a better understanding of how this loosely organized network operates and who remains active within it through the recent arrests. 

It has been reported that FBI agents have indicated that information obtained from arrests and seized infrastructure may be useful for identifying additional participants. However, the appearance of a new ShinyHunters leak site following the earlier closure indicates that the organization has not been completely dismantled. Furthermore, the case illustrates the difficulty of disrupting cybercrime groups that are built upon informal networks rather than a rigid organizational structure. 

According to Reuters, investigations and prosecutions can become complicated by the young age of some suspects, the fluid nature of related groups, and the limited cooperation of victims. While ShinyHunters' continued online activity suggests that law enforcement efforts are ongoing, the reported detention and cooperation may provide investigators with valuable insight into ShinyHunters' wider network.

Featured