FBI Seizes RAMP Cybercrime Forum Used by Ransomware Gangs
The FBI has seized the notorious RAMP dark web forum in coordination with DOJ. The forum had 14,000+ users and facilitated hundreds of millions in ransomware damages. Leaked database may expose LockBit operator.
Google Disrupts IPIDEA, One of the World's Largest Residential Proxy Networks
Google Threat Intelligence dismantles a Chinese-operated proxy network spanning 9 million Android devices and 13 proxy brands, used by 550+ threat groups including nation-state actors from China, Russia, Iran, and North Korea.
Match Group Breach Exposes Data from Tinder, Hinge, and OkCupid
ShinyHunters stole 10 million records from Match Group dating platforms via a vishing attack that compromised Okta SSO credentials. The breach exposed user advertising IDs, IP addresses, and dating profile content.
SolarWinds Patches Critical RCE and Auth Bypass Flaws in Web Help Desk
Four critical vulnerabilities in SolarWinds Web Help Desk allow unauthenticated remote code execution and authentication bypass. CISA confirms active exploitation with February 6 federal deadline.
Aisuru Botnet Hits 31.4 Tbps in Record-Setting DDoS Attack on Telecom Providers
The Aisuru/Kimwolf botnet launched the largest recorded DDoS attack at 31.4 Tbps, powered by 2 million compromised Android TV boxes infected via exposed ADB ports through residential proxy networks.
Ransomware Attacks Surge 45% in 2025 with Over 9,200 Cases Recorded
NordStellar research reveals 9,251 ransomware incidents in 2025, with Qilin leading at 1,066 attacks (408% increase). December set a two-year record with 1,004 incidents. 2026 projected to exceed 12,000 attacks.
Google's $32 Billion Wiz Acquisition Nears Completion Pending EU Decision
Alphabet's record-breaking acquisition of cloud security startup Wiz awaits final EU regulatory clearance expected February 10, 2026. The deal will reshape the cloud security market and integrate Wiz's CNAPP platform into Google Cloud.
China-Linked UAT-8099 Deploys BadIIS Malware for SEO Fraud Across Asia
Cisco Talos identified Chinese-speaking threat actor UAT-8099 compromising IIS servers in Asia with BadIIS malware variants, hijacking legitimate websites for SEO poisoning and credential theft.
xz Utils Backdoor: The Most Sophisticated Supply Chain Attack Since SolarWinds
In March 2024, a Microsoft engineer accidentally discovered a backdoor in xz Utils that had been planted by an attacker who spent nearly three years building trust in the open-source community. The near-miss could have compromised millions of Linux servers.
ClickFix Attacks Combine Fake CAPTCHAs with Signed Microsoft Scripts to Deploy Stealer
The EVALUSION campaign uses social engineering, Google Calendar C2, and steganography to distribute Amatera information stealer—part of a technique now used in 47% of observed attacks.
Fortinet Patches FortiCloud SSO Authentication Bypass Under Active Exploitation
CVE-2026-24858 allows attackers with any FortiCloud account to authenticate to other customers' devices. Arctic Wolf observed automated exploitation creating backdoor admin accounts within seconds.
Critical 'Cellbreak' Vulnerability in Grist Spreadsheet Platform Enables RCE
CVE-2026-24002 allows remote code execution through malicious spreadsheet formulas via Pyodide sandbox escape. Affects government, education, and enterprise deployments.