Archive of

KillSec ransomware: 16-year-old suspected leader arrested

A 16-year-old is suspected of running KillSec, a ransomware group linked to almost 1,000 attacks around the world. Police arrested three people during a coordinated action day across four European countries.

The operation was coordinated by Eurojust, the European Union's agency for judicial cooperation in criminal matters. According to the agency, KillSec has been active since 2024. Investigators identified suspects in four roles within the group: administrator, developer, negotiator and affiliate.

The teenager is suspected of being both the administrator and the main operator of the group. A second suspect, who worked as a developer, has just turned 18. Eurojust noted that this person was still a minor when some of the alleged offences took place.

Read More


Fakturownia breach exposes Polish invoicing platform data

Fakturownia, one of Poland's major online invoicing platforms, has disclosed a data breach that may have exposed information on its users and on their customers and business partners.

The company said an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to its servers. More than 600,000 businesses use the service. Fakturownia has not yet determined how many of them were affected.

What the attacker may have accessed

According to Fakturownia, the potentially compromised data includes:

  • user and company account data
  • password hashes
  • bank account information
  • authentication and integration tokens
  • information on customers and business partners

The attacker may also have reached invoices issued through the platform before 2023. The company said payment card data and information stored through its integrations were not affected.

Read More


Zimbra CVE-2026-73570 exploited before public disclosure

Attackers began abusing a high-severity command injection flaw in Zimbra Collaboration Suite (ZCS) in the weeks after a fix was released but before the bug was publicly disclosed, according to Microsoft.

The vulnerability, tracked as CVE-2026-73570, carries a CVSS score of 8.9. It affects ZCS versions before 10.1.20 and allows unauthenticated attackers to run code remotely on vulnerable mail servers.

How the flaw works

The problem lies in how ZCS handles SNMP notifications. SNMP (Simple Network Management Protocol) is commonly used to monitor and manage network devices and services. In affected versions, untrusted input processed during these notifications is not properly sanitized, which opens the door to OS command injection.

Read More


Windows settings backup now on by default for Entra orgs

Microsoft has switched on Windows settings backup by default for enterprise devices that are Microsoft Entra-joined or Microsoft Entra hybrid-joined and have been upgraded to Windows 11 26H2. Microsoft Entra is the company's cloud identity and access management platform.

The change follows the release of Windows 11, version 26H2 on September 29. Microsoft had announced the plan in July.

From opt-in to default

The Windows settings backup tool was previously known as Windows Backup for Organizations. It saves enterprise users' Windows settings and restores them after a device is reset, replaced, upgraded, or reimaged.

Microsoft first presented the feature at its Ignite conference in November 2024. At that point it was opt-in and disabled by default. It went into public preview in May 2025 and became generally available in August 2025.

Read More


RedFlick technique lets Star Blizzard push CosmicPulse

Star Blizzard, a Russian state-backed threat actor, has adopted a new way of installing malware on victims' machines. Microsoft researchers call the method "RedFlick" and say the group is using it to deliver its signature CosmicPulse backdoor.

The technique itself is not new to the security world. What is new is that Star Blizzard now uses it. It lets the group automate more of each attack and cut down on what the victim has to do before the infection runs.

According to Microsoft, Star Blizzard expanded its phishing operations in 2026 and made its malware delivery more efficient. The group has been active since 2017. It has a history of trying out new ways to deliver payloads, including ClickFix and WhatsApp, and it keeps building and deploying new malware families.

Read More