On May 19, Europol seized 33 servers across 27 countries and handed investigators the complete user database of a VPN service that ransomware groups, fraud networks and data theft operations had trusted for over a decade. The service thought it was above the law.
Category: News
FBI Warns Kali365 PhaaS Kit Is Hijacking Microsoft 365 Accounts Without Stealing a Single Password
A PhaaS platform called Kali365 is hijacking Microsoft 365 accounts without stealing passwords. It bypasses MFA by abusing a legitimate Microsoft sign-in flow. The FBI has issued a formal warning. Here is how it works and what to do now.
Iran-Linked Hackers Wiped 200,000 Stryker Devices Overnight Without Installing a Single Line of Malware
At 3:30 in the morning on March 11, more than 200,000 Stryker devices across 79 countries began reverting to factory settings simultaneously. No malware. No exploit. The Iran-linked group Handala had compromised administrator credentials to Stryker's Microsoft Intune device management platform and used its own remote wipe function against it. The Department of Justice formally attributed the attack to Iran's Ministry of Intelligence and Security. The State Department put a $10 million bounty on the perpetrators. The attack used no sophisticated tools because it did not need to.
Megalodon: The GitHub Supply Chain Attack That Compromised 5,500 Repositories in Six Hours Flat
Six hours. 5,500 compromised repositories. The Megalodon campaign represents a massive escalation in supply chain attack velocity, targeting GitHub Actions workflows to silently exfiltrate production cloud secrets. Here is why your current security review process might be missing this critical automation blind spot.
CERT-In’s 12 Hour Patching Mandate Is Not a Compliance Deadline. It’s a Signal That AI Has Changed the Game Permanently
The attack window has officially collapsed. CERT-In’s new blueprint urges Indian organizations to patch critical vulnerabilities within 12 hours of detection. Driven by AI-assisted threat exploitation, this radical shift demands that enterprise security operations match machine-speed attacks or face severe compliance risks.



