Scattered Spider, ShinyHunters, and LAPSUS$ are the three groups involved, and have collectively been the most active of the major cybercrime gangs over roughly the past year. The groups all had prior ties via "The Com," a broader collection of cyber criminals that loosely affiliate and come together for singular projects in a fluid way.
Google's report of novel AI-enabled malware in the wild is a game changer if these capabilities are now being picked up by sophisticated attackers. It identifies two specific new malware families, "PROMPTFLUX" and "PROMPTSTEAL," that are the first to incorporate a "just in time" dynamic function creation feature that draws on an LLM.
Nikkei, the world’s largest business news outlet, which owns over 40 affiliates, including The Financial Times, and has more than 3.7 million paid subscribers and over 1.7 million daily readers, has confirmed a data breach that leaked personal information after threat actors compromised its Slack accounts.
The apparently partially politically motivated attacker claimed to have exfiltrated over 1.2 million records of personal information in the data breach, some of which dates back decades and included banking information.
The Canadian Centre for Cyber Security has warned of hacktivists breaching critical infrastructure via Internet-exposed ICS devices, posing serious safety risks.
Another security breach involving US telecom companies has come to light, with a third-party contractor that interfaces between some of the industry's big names reporting discovery of unauthorized access to their systems by nation-state hackers that began in late 2024 and continued through much of 2025.
Toys “R” Us Canada, a subsidiary of the American toy giant, has confirmed a data breach after threat actors leaked the stolen customer information on the dark web.
The UN cybercrime treaty is meeting with some pushback from both the tech industry and human rights activists. Privacy and human rights organizations, to include the UN's own High Commissioner for Human Rights, have aired concerns that the treaty's definitions of crimes are too vague and open to potential abuse.
An internal memo sent to Meta risk division workers on October 29 by Protti outlined the company's intention to lay off hundreds of privacy compliance staff, as part of cost-cutting measures that shift more duties from humans to AI.
A phishing campaign by state-sponsored Iranian hackers has targeted over 100 government entities and other organizations with version 4 of the Phoenix malware backdoor.










