Dark Web News – The Cyber Express Trending Cybersecurity News, Updates, Magazine and More.
- Cyberattack Hits Ukraine Agency Ahead of Major Asset Tenderby Samiksha Jain on August 19, 2026 at 5:33 am
A suspected ARMA cyberattack has targeted Ukraine’s Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow. ARMA Cyberattack Raises Questions Over IDS Ukraine Competition ARMA said the attack occurred shortly before the August 22 deadline for applications to participate in the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman. The agency said its experts and law enforcement authorities are examining the cyberattack and the events surrounding the IDS Ukraine competition. The Security Service of Ukraine, or SBU, is investigating the recent attack, while a broader National Anti-Corruption Bureau of Ukraine, or NABU, investigation is examining earlier alleged interference. According to ARMA, signs of illegal interference in processes connected to its work have been recorded since spring. These included unauthorized access to the agency’s officials’ register. ARMA said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament had raised concerns about a possible coordinated campaign. The agency said investigators must determine whether these events were intended to disrupt its work, create pressure or affect the competition. ARMA has not identified those it believes may have organized or carried out the alleged campaign. IDS Ukraine Selection Continues Despite Cyberattack Despite the incident, ARMA said the competition to select the IDS Ukraine asset manager will proceed according to the procedures and timeframe established by law. The deadline for applications is August 22, 2026, with the competition announcement published through Ukraine’s Prozorro public procurement system. The agency said it has also started an audit of the financial indicators of seized IDS group assets to support the legality, objectivity and transparency of the transfer process. ARMA said additional information concerning possible unauthorized access to officials’ email accounts and official information will be provided to law enforcement authorities for investigation and legal assessment. Acting ARMA Head Yaroslava Maksymenko said the agency would continue the competition despite what it described as information pressure, political interference and attempts to gain unauthorized access to its resources. Ukraine Investigates Possible Coordinated Interference ARMA said the latest incident is not being viewed in isolation. The agency pointed to a similar episode earlier this year, when Reuters reported on a cyberattack involving attempts at interference and hacking alongside increased information activity and inquiries. The agency said each event could have an individual explanation, but their timing and combination warranted further investigation. The cyberattack comes as Ukraine continues efforts to prevent sanctioned Russian capital from retaining control over assets seized in the country. ARMA said this includes preventing control through management arrangements, intermediaries or influence groups. Fridman has been sanctioned by Ukraine and several Western governments since Russia’s invasion. ARMA said the final responsibility for determining the organizers, customers and perpetrators of the attack rests with the ongoing investigations. The agency said it will continue the IDS Ukraine competition and act within the law while law enforcement agencies examine the reported cyber incidents and possible attempts to interfere with its activities.
- The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threatsby Ashish Khaitan on July 31, 2026 at 12:02 pm
This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. The Cyber Express Weekly Roundup Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more… Tribeca Data Leak Exposes Celebrity-Linked Information A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more… Origin Energy Data Breach Impacts Around 900,000 Customers Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more… Joyfill npm Packages Found Distributing DEV#POPPER Malware Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more… Student Accused of IIT Website Breaches Offered Technical Assessment A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more… FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more… Weekly Cybersecurity Takeaway This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting. A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives. Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning. As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management.
- Tanaka Dominates Data Leak Landscape With 25 Leak Postsby Ashish Khaitan on July 28, 2026 at 11:58 am
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble. Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publishing stolen information, Tanaka emerged as the most active, accounting for 25 distinct leak posts — more than double the activity of several other major actors. A Data Leak Operation Without Industry Boundaries Unlike threat actors that specialize in a single vertical, Tanaka followed a broad targeting approach across multiple industries and regions. The actor’s campaigns showed no strict preference for a specific sector, instead focusing on organizations where stolen information could hold financial or strategic value. The Banking, Financial Services, and Insurance (BFSI) sector remained the most targeted industry globally, accounting for 38 breach incidents during the reporting period. Financial organizations continue to attract attackers due to the value of customer information, account data, and personally identifiable information (PII). Government and Technology organizations were also frequent targets, reflecting the wider value of sensitive records, intellectual property, and institutional data. Regional Presence Across Major Markets Tanaka’s activity was visible across multiple regions. In North America, the actor was responsible for seven leak posts, making it the most active data leak actor in the region alongside other prominent sellers. Europe and the UK also saw significant activity, with Tanaka linked to six leak posts during H1 2026. The region’s BFSI, Telecommunications, and Retail sectors faced heightened exposure due to the amount of valuable customer and financial data they hold. The actor’s global footprint demonstrates how modern data leak operations can function independently of geography. Instead of focusing on a single country or industry, operators like Tanaka exploit opportunities wherever valuable information becomes available. The Rise of the Data Leak Marketplace Tanaka’s activity reflects a broader shift in the cybercrime ecosystem. Data leaks are no longer only a byproduct of ransomware attacks; they have become a standalone business model. Threat actors monetize stolen information through underground marketplaces, using leaked databases for fraud, extortion, intelligence gathering, or resale. This specialization mirrors other parts of the cybercrime economy, where access brokers, ransomware affiliates, and data sellers perform separate roles. For organizations, this means a breach does not always begin with a ransomware demand. A stolen database appearing in underground channels may indicate an earlier compromise that requires immediate investigation. Staying Ahead of Data Exposure Risks Security teams must treat underground data exposure monitoring as part of their broader defense strategy. Identifying leaked credentials, compromised databases, or mentions in cybercrime marketplaces can provide early warning before stolen information is weaponized. To understand the 2026 data breach landscape, including the most active threat actors, targeted industries, and regional trends, access the full Cyble H1 2026 Cyber Threat Landscape Report.
- The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threatsby Ashish Khaitan on July 24, 2026 at 1:21 pm
This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior. The latest developments underline the need for stronger security practices, including improved identity protection, faster incident response, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond data theft, affecting operations, customer trust, and critical services. The Cyber Express Weekly Roundup U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026 The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from Cyble Research and Intelligence Labs (CRIL). The report identified ransomware groups Qilin and Akira as among the most active threat actors during the period. Read more… Dubai Police Warns Against Online Visa Fraud Schemes Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. Read more… Craneware Data Breach Exposes Employee and Customer Information Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. Read more… U.S. Targets Illegal FIFA World Cup Streaming Networks The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. Read more… Chick-fil-A Customer Accounts Targeted in Credential Attack Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. Read more… South Korea Diplomatic System Breach Lasted Nearly 10 Months South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. Read more… Weekly Cybersecurity Takeaway The week’s incidents demonstrate how cyber threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure. Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of social engineering tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust.
- The Cyber Express Weekly Roundup: AI Security Controls, Major Patch Releases, Public Sector Audits, and Emerging Online Scamsby Ashish Khaitan on June 12, 2026 at 11:48 am
This week’s cybersecurity developments highlight a growing emphasis on proactive security measures, governance oversight, and risk management across both public and private sectors. From large-scale vulnerability remediation efforts and AI security enhancements to government-led technology reviews and event-driven cybercrime campaigns, organizations continue to face a complex threat landscape. A common theme across this week’s stories is the balance between innovation and security. As institutions adopt AI-powered systems, expand digital services, and move critical operations online, security teams are being challenged to strengthen protections without slowing modernization efforts. At the same time, threat actors continue to capitalize on public-interest events and trusted digital platforms to conduct fraud and data-theft campaigns. The Cyber Express Weekly Roundup CBSE Re-Evaluation Portal Receives Final Security Clearance The Central Board of Secondary Education (CBSE) has completed the final cybersecurity review of its examiner-facing re-evaluation platform, clearing the way for the reassessment of Class 12 answer scripts. Following an IIT-led audit and security testing process, examiners can now access the system to process applications submitted by more than 70,000 students. Read more… OpenAI Expands Lockdown Mode Across ChatGPT Accounts OpenAI has extended its Lockdown Mode security feature to all personal ChatGPT users, including Free, Go, Plus, Pro, and self-service Business accounts. The feature is designed to reduce the risk of prompt injection-related data exposure by limiting access to high-risk capabilities such as live web browsing, Deep Research, Agent Mode, and external file interactions. Read more… UK Courts Explore AI-Powered Legal Assistance The UK government has announced plans to test AI legal assistants within Crown Courts as part of broader judicial modernization efforts. The tools are expected to assist with legal research, case review, scheduling, and administrative processes while remaining under human supervision. Read more… Microsoft Issues Largest Patch Tuesday Update on Record Microsoft’s June 2026 Patch Tuesday addressed a record-breaking 200 security vulnerabilities across its product ecosystem, including Windows, Office, Azure, and Exchange. The release included fixes for three publicly disclosed zero-day vulnerabilities and dozens of critical flaws. Read more… ServiceNow Clarifies Nature of Recent Security Incident ServiceNow has provided additional details regarding a recently disclosed security vulnerability, stating that observed activity originated from security researchers and customer investigations rather than malicious attackers. The company released a security update to address the issue and emphasized that there is no evidence of customer data misuse. Read more… World Cup-Themed Scams Target Fans Ahead of FIFA 2026 Cybercriminals are already leveraging interest in the FIFA World Cup 2026 to launch phishing campaigns, fake ticket sales, and fraudulent recruitment schemes. Security researchers and law enforcement agencies have identified numerous lookalike domains impersonating official FIFA services in an effort to steal personal and financial information. Read more… Weekly Cybersecurity Takeaway This week’s developments demonstrate that cybersecurity is becoming a foundational requirement for digital transformation rather than a separate consideration. Whether securing AI platforms, protecting educational systems, modernizing public services, or managing enterprise vulnerabilities, organizations are being forced to address security challenges alongside innovation initiatives. Meanwhile, threat actors continue to exploit trust, familiarity, and public interest to achieve their objectives. From phishing campaigns targeting global sporting events to attacks focused on cloud services and enterprise platforms, the most effective defenses remain strong security governance, timely patching, user awareness, and continuous monitoring of emerging risks.
- 163 Organizations Hit by Thai Gambling SEO Poisoning Campaignby Ashish Khaitan on June 12, 2026 at 7:28 am
A large-scale Thai gambling SEO poisoning operation has compromised 163 organizations across more than 30 countries by exploiting abandoned cloud DNS delegations, according to research from Cyble Research & Intelligence Labs (CRIL). The ongoing SEO poisoning campaign has affected government agencies, healthcare organizations, financial institutions, universities, and critical infrastructure operators, allowing attackers to host Thai-language gambling content on trusted enterprise domains. How the SEO Poisoning Campaign Works Researchers found that the campaign primarily abuses abandoned Azure DNS zone delegations. When organizations retire cloud projects, DNS records that delegate subdomains to Azure are often left behind. Threat actors identify these orphaned delegations, recreate the abandoned DNS zones under new Azure subscriptions, and gain authority over the affected subdomains. Using this method, the attackers deploy a Next.js-based Thai-language gambling kit protected by valid Let’s Encrypt wildcard certificates. As a result, users, browsers, and search engines see what appears to be legitimate content hosted under trusted corporate domains. At the time of publication, 161 of the 163 affected organizations remained actively compromised. Discovery Leads to Global Exposure The investigation began when CRIL identified unusual DNS activity on a Verizon subdomain environment. Researchers discovered more than 1,000 individually named subdomains serving Thai-language gambling content. Each page contains affiliate links designed to drive user registrations and generate commissions. Further analysis revealed the same infrastructure and content fingerprints across 162 additional organizations. More than 90 compromised enterprise subdomains shared the same Next.js build ID (QQOrXCFjoI6C9oF-4YVhl), favicon path (/img/ib99-hq.ico), and affiliate redirect destinations. Four DNS Abuse Methods Identified The Thai gambling SEO poisoning operation relied on four compromise mechanisms: Azure DNS zone takeover: More than 150 organizations were affected through abandoned Azure DNS delegations. DigitalOcean DNS zone takeover: Two organizations were compromised using a similar technique. Direct wildcard DNS misconfigurations: Two organizations had wildcard records pointing to attacker-controlled infrastructure. Mass A-record creation: Verizon’s environment contained over 1,000 individual DNS records directing traffic to gambling content. Certificate Transparency records showed some abandoned zones had remained dormant for years. One pharmaceutical company’s subdomain had not seen a legitimate certificate since October 2019 before attackers obtained a new certificate on April 11, 2026. Another electronics firm’s platform showed a gap between February 2023 and April 10, 2026. Monetization and Backend Infrastructure The SEO poisoning campaign generated revenue through affiliate tracking codes such as “ibiza99vip1,” “bigwinv1,” “seven77vip1,” and “link99.” Researchers observed server-side filtering that verified visitors originated from Thailand before redirecting them to gambling platforms. The campaign ultimately linked to four gambling destinations: ibiza99.autos, big888.store, seven77.click, and link99.nova555.rest. The gambling pages promoted deposits as low as 1 Thai Baht (approximately $0.03 USD) and included structured SEO content, FAQ schema, and mobile optimization features. Behind the delivery infrastructure, researchers uncovered a dedicated backend fleet of 103 servers located in Hong Kong under AS398478 (PEG TECH INC). Evidence linking the servers included identical TLS fingerprints, shared certificates, matching HTTP hashes, uniform MySQL configurations, and common administration tools. Detection and Mitigation CRIL noted that traditional security tools are unlikely to detect this Thai gambling SEO poisoning activity because the attackers use valid certificates, reputable domains, and clean infrastructure. The researchers recommend continuous monitoring of Certificate Transparency logs, auditing all DNS delegations, and immediately removing abandoned NS records pointing to cloud providers. According to the report, the campaign demonstrates how a single DNS hygiene failure can be systematically exploited at scale. Rather than breaching networks or applications, the attackers capitalized on forgotten cloud configurations, turning trusted domains into vehicles for a sophisticated SEO poisoning campaign targeting Thai search traffic.
- Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attackby Ashish Khaitan on June 2, 2026 at 8:14 am
A newly discovered software supply chain campaign, dubbed Miasma, has emerged as the latest evolution of the Shai-Hulud supply chain attack, compromising several redhat-cloud-services npm packages to steal credentials, harvest secrets from developer systems, and spread through development environments using worm-like behavior. Security researchers at Socket described the operation as a smaller but highly capable successor to earlier Shai-Hulud campaigns, noting that it employs many of the same techniques that made previous attacks effective against software development ecosystems. “This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation,” Socket said. Attribution Remains Unclear as TeamPCP Tools Continue to Circulate The identity of the threat actor behind the latest Shai-Hulud supply chain attack remains uncertain. One major reason is the role of TeamPCP, a well-known cybercrime group that previously open-sourced tools associated with the original Shai-Hulud worm. By publicly releasing those resources, TeamPCP lowered the barrier for other attackers to launch similar operations, making attribution significantly more difficult. Researchers have not yet linked the Miasma campaign to any specific actor with confidence. Affected redhat-cloud-services Packages The attack targeted multiple packages published under the redhat-cloud-services namespace. The known compromised packages include: @redhat-cloud-services/vulnerabilities-client @redhat-cloud-services/tsc-transform-imports @redhat-cloud-services/topological-inventory-client @redhat-cloud-services/sources-client @redhat-cloud-services/rule-components @redhat-cloud-services/remediations-client @redhat-cloud-services/rbac-client The malicious code embedded within these packages was designed to execute during installation, allowing attackers to collect sensitive information from infected developer environments. Encrypted Data Theft and GitHub-Based Propagation Similar to earlier waves of the Shai-Hulud supply chain attack, the malware incorporates encrypted exfiltration capabilities. Stolen information is transmitted to the endpoint “api.anthropic[.]com:443/v1/api,” while GitHub serves as a secondary communication and propagation channel. According to Socket, the malware can commit encrypted data packages directly through GitHub’s API. “It commits the encrypted result envelope through the GitHub API,” Socket said. “The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:.” Researchers from OX Security identified the first commit containing the phrase “Miasma: The Spreading Blight” on May 29, 2026. This suggests either that the malware variant had already been active by that date or that attackers began testing the campaign around that time. GitHub Abuse Enables Verified Malicious Commits The Miasma malware actively searches for repositories where stolen GitHub tokens possess write permissions. It then inspects action.yml and action.yaml files using GraphQL queries before injecting malicious workflows through GitHub’s createCommitOnBranch mutation. This technique allows the resulting commits to appear as legitimate, verified, and signed changes, increasing the likelihood that malicious modifications will evade scrutiny. The malware is also capable of performing several additional actions, including: Attempting privilege escalation by launching containers that bind-mount the host’s /etc/sudoers.d directory and grant passwordless sudo access to CI runners. Detecting endpoint protection products such as CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before executing malicious activities. Establishing persistence by modifying Anthropic Claude Code through a SessionStart hook. Creating Visual Studio Code tasks.json files configured with “runOn”: “folderOpen” to ensure automatic execution whenever a project is opened. Red Hat GitHub Account Believed to Be Initial Entry Point Investigators believe the campaign originated from the compromise of a Red Hat employee’s GitHub account. Evidence indicates that the account served as the patient zero event used to inject malicious code into the affected redhat-cloud-services packages. The compromised account reportedly pushed malicious orphan commits into two RedHatInsights repositories, allowing the attacker to bypass normal code review procedures and introduce the malicious payload. Recommended Response and Remediation Steps Security experts advise organizations that installed affected redhat-cloud-services package versions to immediately isolate impacted systems and remove compromised releases. Additional recommendations include: Rotating all potentially exposed credentials. Reviewing GitHub and npm activity for suspicious behavior. Auditing environments for persistence mechanisms. Investigating modifications to configuration files such as: ~/.claude/settings.json .vscode/tasks.json .github/workflows/codeql.yml .github/setup.js Enforcing stronger access controls across development environments. Socket warned that removing the malicious package alone is not sufficient. “Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup,” Socket explained. The company also urged organizations operating CI/CD pipelines to suspend affected workflows, invalidate any build artifacts created during the exposure period, and review whether software releases, container images, npm packages, or deployment artifacts were generated after installation of the malicious package.
- The Cyber Express Weekly Roundup: Supply Chain Breaches, AI Content Enforcement, And Event Disruption Attacksby Ashish Khaitan on May 22, 2026 at 11:44 am
The global cybersecurity landscape continues to evolve rapidly as attackers expand their focus on developer ecosystems, public-facing institutions, and anonymization infrastructure. At the same time, regulators and law enforcement agencies are stepping up enforcement efforts around AI misuse and cybercrime-enabling services. This week’s weekly roundup developments highlight how cyber threats are becoming increasingly distributed across platforms and industries, with supply chain compromises, operational disruptions, and policy enforcement actions shaping the broader risk environment. The Cyber Express Weekly Roundup Austria Blocks Hundreds of Cyberattacks During Eurovision Week in Vienna Austria successfully prevented nearly 500 cyberattack attempts targeting systems connected to Eurovision operations during the contest week in Vienna. Officials stated that the attacks were intended to disrupt event infrastructure and associated services, but no major operational failures were recorded. Read more… Massive npm Supply Chain Attack Hits AntV Ecosystem A large-scale software supply chain compromise has impacted more than 300 npm packages within the AntV ecosystem following the hijacking of a trusted maintainer account. The compromised packages were reportedly modified as part of the “Mini Shai-Hulud” malware campaign, which targeted developer environments and widely used JavaScript libraries. Read more… Chanhassen Dinner Theatres Cyberattack Disrupts Operations and Ticketing Systems A cyberattack targeting Chanhassen Dinner Theatres disrupted key operational systems, including ticketing, payment processing, and customer communications, forcing additional cancellations of scheduled performances of “Guys and Dolls.” The disruption comes amid concurrent operational challenges, including an illness outbreak affecting performers and attendees, further complicating recovery efforts. Read more… FTC Targets AI “Nudify” Platforms Over TAKE IT DOWN Act Violations The U.S. Federal Trade Commission has issued formal warnings to multiple AI-powered “nudify” platforms over alleged violations of the TAKE IT DOWN Act, which requires rapid removal of nonconsensual intimate content upon valid request. According to regulators, several platforms failed to implement compliant removal workflows, including the mandated 48-hour takedown requirement. Read more… GitHub Confirms Internal Repository Breach via Malicious VS Code Extension GitHub has confirmed a security incident in which attackers accessed thousands of internal repositories after compromising an employee’s device through a malicious Visual Studio Code extension. The company stated that there is no evidence of customer repository compromise or enterprise data exposure, and that the incident was contained following detection. Read more… European Authorities Shut Down VPN Service Used in Ransomware Operations European law enforcement agencies have seized the infrastructure of a VPN service known as First VPN during “Operation Saffron,” targeting its alleged use in supporting ransomware and cybercriminal operations. Authorities dismantled 33 servers and detained the suspected administrator in Ukraine. Read more… Weekly Cybersecurity Takeaway This week’s weekly roundup reflects a cybersecurity landscape defined by ecosystem-level compromise rather than isolated incidents. Supply chain attacks continue to target developer tooling and open-source ecosystems, while AI-related enforcement actions signal growing regulatory pressure around synthetic content abuse. At the same time, law enforcement actions against anonymization infrastructure demonstrate a stronger focus on disrupting the operational backbone of cybercriminal networks. Taken together, these events highlight a shifting threat environment where compromise of platforms, dependencies, and infrastructure can cascade across multiple industries simultaneously.














