Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Cybercrime
Latest news

84 TanStack npm Packages Poisoned in Sophisticated Supply-Chain Attack Stealing Cloud and CI Credentials

15 May 2026  |  dark6  |  Cybercrime

Attackers compromised 84 npm artifacts across 42 TanStack packages — including react-router with 12M+ weekly downloads — injecting a credential-stealing payload via chained GitHub Actions abuse. Organizations that...

>> read more

Massive 2.45 Billion-Request DDoS Attack Uses 1.2 Million IPs to Defeat Rate Limiting in “Low and Slow” Campaign

7 May 2026  |  dark6  |  Cybercrime

DataDome researchers have documented a record-scale DDoS attack that delivered 2.45 billion malicious requests over five hours using 1.2 million unique IP addresses across 16,402 ASNs. Each source...

>> read more

Europol Dismantles €50 Million Investment Fraud Network Operating Corporate-Style Scam Call Centres in Albania

30 April 2026  |  dark6  |  Cybercrime

A coordinated Europol operation has taken down a €50 million online investment fraud network operating out of corporate-style call centres in Tirana, Albania, with up to 450 employees....

>> read more

North Korean IT Worker Scheme: How DPRK Operatives Infiltrate Companies to Fund Weapons Programs

24 April 2026  |  dark6  |  Cybercrime

A Team Cymru investigation has exposed the technical infrastructure behind North Korea's long-running fake IT worker scheme, revealing how state-sponsored operatives use stolen identities, commercial VPNs, and U.S.-based...

>> read more

Fake Ledger Live App on Apple’s Mac App Store Steals $9.5 Million in Crypto from 50+ Victims

16 April 2026  |  dark6  |  Cybercrime

A counterfeit Ledger Live app remained live on Apple's Mac App Store for two weeks, tricking users into entering their cryptocurrency wallet seed phrases. At least 50 victims...

>> read more

CISA Warning: Iranian-Affiliated Hackers Targeting US Critical Infrastructure PLCs to Cause Disruption

12 April 2026  |  dark6  |  Cybercrime

CISA has issued an urgent advisory (AA26-097A) warning that Iranian-affiliated APT actors have been actively targeting internet-exposed Programmable Logic Controllers across U.S. critical infrastructure since at least March...

>> read more

APT28’s FrostArmada: How Russian Hackers Built an 18,000-Router Army to Steal Microsoft 365 Credentials

9 April 2026  |  dark6  |  Cybercrime

Russia’s APT28 compromised over 18,000 routers across 120 countries to silently hijack DNS and steal Microsoft 365 credentials from government agencies and cloud providers. An international disruption operation...

>> read more

K.G.B. RAT Strikes Again: A Case Study in Undetectable Malware Distribution

3 December 2025  |  dark6  |  Cybercrime

The underground cybercriminal ecosystem has witnessed a worrisome development – the rise of a highly sophisticated remote access trojan (RAT) known as K.G.B. RAT. This weaponized software, now...

>> read more