Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief – April 27, 2026

## Italy Extradites Alleged Chinese APT Operator; Microsoft Entra Flaw Disclosed

Italy has approved the extradition of a Chinese national to the United States on charges related to state-directed hacking operations. The suspect is accused of theft of COVID-19 research and is allegedly linked to the Hafnium threat group. An Italian court approved extradition in January, with the country's top court rejecting the suspect's appeal. Separately, Microsoft disclosed a critical identity management vulnerability in its Entra Agent ID system that enabled tenant takeover through privilege escalation. The flaw allowed attackers to perform Service Principal takeovers—effectively identity theft for application identities—by gaining ownership of the Service Principal and creating their own secret keys for persistent access.

North Korean state actors remain active across multiple theaters. Security researchers attribute a data breach at South Korea's Lee & Lee Country Club to North Korean hackers, with malware believed to have been inserted in October 2025. The breach exposed data belonging to approximately 100,000 individuals. Separately, Russian state actors are suspected in a social engineering campaign targeting German officials through Signal, where attackers impersonated "Signal Support" to harvest PINs and credentials. Additional breaches include the theft of personal data belonging to 350,000 engineers from Thailand's engineering council database, and an escalating series of cryptocurrency thefts—including the $1.5 billion Bybit hack in February 2025 and a $282 million single-holder theft in January—highlighting persistent weaknesses in cryptocurrency security infrastructure.


Sources: UNN · Financial Times · Hackread · DataBreaches.Net · Binance Square · New York Post

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

'I suspected I was being socially engineered.' Why crypto's hacking epidemic is getting even worse

The $1.5 billion Bybit hack in February 2025, a January $282 million theft from a single crypto holder, and, this month, the Drift Protocol attack are...

Read more →

TH: Hacker steals personal data of 350,000 engineers - DataBreaches.Net

Prof Amorn Pimanmas, a director in the council's board, said that about a week ago a hacker breached the database containing members' personal data .....

Read more →

Researcher Drops Two More Microsoft Defender Zero-Days, All Three Now Exploited in the Wild

Security researcher Chaotic Eclipse released RedSun and UnDefend proof-of-concept exploits for Microsoft Defender, with all three vulnerabilities now ...

Read more →

Discord Sleuths Gained Unauthorized Access to Anthropic's Mythos | WIRED

But one group of amateur sleuths on Discord found their own, relatively simple ways—no AI hacking required—to gain unauthorized access to a ...

Read more →

US strikes back at Iran-linked hacking group - MSN

US authorities seized four domains linked to Iran-backed hacker group Handala, accusing it of running cyber-enabled psychological operations and ...

Read more →
Cybersecurity icon

Big Cyber

Cisco Catalyst SD-WAN Compromise Alert Issued by Federal Agencies

Federal agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN systems and full updating and hardening o...

Read more →

UK could face 'hacktivist attacks at scale', says head of security agency - The Guardian

Richard Horne, chief executive of the National Cyber Security Centre (NCSC), will warn today that nation states now account for the most significant ....

Read more →

Rhode Island Hospitals Face Cybersecurity Threats Without Federal Support and Iran-Linked Targeting

Rhode Island hospitals lack enforceable cybersecurity requirements while facing growing threats from Iran-linked cyber activity targeting U.S. healthc...

Read more →

Vercel systems targeted after third-party tool compromised | Cybersecurity Dive

... Cybersecurity Dive. “That isn't about the inherent security flaws of AI applications, it's more about AI tools requiring permissions to be as ...

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.