
German police identify alleged Black Basta leader as Europol and Interpol target
European authorities identify an alleged Black Basta leader and report raids on two other suspected participants as investigations continue.
Verified cybersecurity, fraud and digital-banking signals with decision context, affected audiences and practical actions.

European authorities identify an alleged Black Basta leader and report raids on two other suspected participants as investigations continue.

LastPass says deceptive holiday-weekend emails claiming maintenance were part of a phishing campaign framed as a backup request.

Ransomware negotiation can help address an immediate crisis, but it also creates legal, operational and ethical risks for security teams and their clients.

A reported IoT botnet called Kimwolf has spread to more than 2 million devices and is present in corporate and government networks.

Researchers say phishing emails impersonating Afghanistan’s prime minister’s office are targeting government employees, underscoring the risk of official-looking correspondence.

UK authorities warn that pro-Russia groups are targeting critical infrastructure and local government, following a recent allied advisory about hacktivist activity against OT providers.

Southeast Asia CISOs identify cloud and AI security, identity protection, and operational resilience as central priorities for the year ahead.

A Jordanian national pleaded guilty in a reported access-broker case involving unauthorized access to at least 50 company networks and alleged EDR-disabling malware.

Schneier on Security describes facial recognition, behavioral AI, audio capture, drones, and license plate readers deployed around Beverly Hills High School.

Canada’s investment regulator says hackers breached its systems in August 2025, with information connected to 750,000 investors reportedly affected.

Cisco Talos says Chinese hackers breached multiple North American critical-infrastructure organizations using compromised credentials and exploitable servers over the past year.

A reported CVSS 10.0 n8n vulnerability may enable takeover of locally deployed instances; users are advised to upgrade to version 1.121.0 or later.

SpyCloud says its new Supply Chain Threat Protection product extends identity-threat monitoring across organizations’ vendor ecosystems and extended workforce.

CSO Online describes cybercrime as a coordinated underground industry, emphasizing the need for preparedness, continuity, and recovery planning.

Microsoft’s January updates address at least 113 flaws, including eight critical issues and CVE-2026-20805, which the company says attackers are exploiting.

Microsoft’s January 2026 update fixes 112 vulnerabilities, including an actively exploited Desktop Window Manager zero-day added to CISA’s KEV catalog.

A World Economic Forum report places cyber-enabled fraud, geopolitics and AI at the center of executives’ cyber-risk concerns, alongside support for regulation.

A threat intelligence report cited by Cybersecurity Dive links a steady telecom ransomware rise with unpatched flaws and lax perimeter controls.

A Krebs on Security report examines how Kimwolf allegedly spread through unofficial Android TV boxes and supported DDoS and residential-proxy activity.

A critical n8n vulnerability reportedly enabled unauthenticated takeover of local deployments, with potential access to connected systems and workflow data.

A fraud expert says AI could make 2026 a pivotal year for impersonation attacks, prompting organizations to reassess identity checks and response procedures.

Agentic AI may waste time or miss instructions when added to human teams, making thoughtful task selection and hybrid-team leadership essential.

A reported cyberattack at Catholic healthcare organization Covenant Health exposed sensitive information tied to more than 478,000 people.

Elliptic’s reported analysis describes two Telegram markets allegedly enabling nearly $2 billion monthly in laundering and black-market transactions.