Latest Internet & Cybersecurity News

📅April 15, 2026 at 1:00 AM
Recent cybersecurity threats include rapid ransomware by Storm-1175, Iran-linked password spraying, Russian router hacks, botnet disruptions, and surging ransomware against US infrastructure amid geopolitical tensions.
1

Storm-1175 Deploys Medusa Ransomware in High-Velocity Attacks

Microsoft reports Storm-1175 using n-day and zero-day exploits to rapidly escalate from initial access to Medusa ransomware deployment, often within 24 hours. The group targeted healthcare, education, and finance sectors in Australia, UK, and US, exploiting over 16 vulnerabilities across products like Exchange and TeamCity.Source 1 Post-exploitation involves creating accounts, stealing credentials, and tampering with security controls.Source 1

2

Iran-Linked Actors Launch Widespread Password Spraying on Microsoft 365

Iran-linked attackers conducted password spraying against hundreds of Microsoft 365 tenants across government, tech, energy, and private sectors. They used common passwords systematically to avoid lockouts, masking origins via VPNs and Tor.Source 1 Successful access enables email, data exfiltration, and lateral movement without malware.Source 1

3

Russian Forest Blizzard Harvests Microsoft Tokens via Router Flaws

Russia's military-linked Forest Blizzard exploited vulnerabilities in 18,000+ outdated routers to siphon authentication tokens from Microsoft Office users across 200+ organizations and 5,000 devices. The campaign peaked in December 2025, targeting government agencies without deploying malware.Source 2 Black Lotus Labs detailed DNS redirection tactics used in the surveillance.Source 2

4

Global Operation Dismantles Four Major IoT Botnets

US, Canada, and Germany disrupted Aisuru, Kimwolf, JackSkid, and Mossad botnets infecting over 3 million IoT devices like routers and webcams. These botnets launched massive DDoS attacks, including on US defense systems, with hundreds of thousands of commands issued.Source 2Source 3 Victims faced extortion and significant losses.Source 2

5

FBI Reports 2,100+ Ransomware Incidents on US Critical Infrastructure in 2025

The FBI's IC3 logged over 2,100 ransomware attacks on sectors like healthcare, energy, and manufacturing in 2025, far exceeding data breaches. Top groups Akira, Qilin, and Lynx used double extortion and compromised credentials to disable backups and encrypt files.Source 4 Healthcare reported the highest incidents, impacting public services.Source 4

6

Cyberattacks Target US Infrastructure Amid Middle East Conflict

Geopolitical tensions, especially with Iran, drive attacks on US industrial control systems and public finance entities like healthcare and utilities. The World Economic Forum notes 64% of organizations now factor geopolitics into cyber strategies.Source 3 This shift aims at physical infrastructure disruption.Source 3

7

Stryker Hit by Iranian-Linked Handala Wiper Malware Attack

Iranian pro-Palestinian group Handala claimed a wiper attack on medical tech firm Stryker, stealing 50TB of data and wiping systems, forcing office shutdowns in 79 countries on March 11, 2026.Source 5 The incident highlights escalating cyber risks from state-linked hacktivists.Source 5

8

Microsoft Announces $10 Billion AI and Cyber Investment in Japan

Microsoft plans $10 billion to expand AI infrastructure and cybersecurity in Japan, partnering with local firms and training 1 million engineers by 2030. The initiative strengthens secure cloud capacity amid regional threats.Source 3 Brad Smith emphasized reliable infrastructure on Japan's terms.Source 3

9

Anthropic Launches Project Glasswing for AI Cybersecurity

Anthropic's Project Glasswing lets partners like Amazon, Microsoft, and Google test unreleased AI model Claude Mythos Preview for vulnerability detection. It has identified thousands of flaws and supports open-source security efforts.Source 3 The initiative bolsters defensive AI capabilities.Source 3

10

Washington Post Oracle E-Suite Breach Exposes 9,700 Staff Data

Hackers compromised the Washington Post's Oracle E-Suite, exposing data of over 9,700 employees and contractors. The external system breach underscores risks in third-party SaaS integrations.Source 8 Investigation details remain ongoing.Source 8

11

Critical Imunify360 Vulnerability Threatens 56 Million Websites

A patched Remote Code Execution flaw in Imunify360 AV exposes millions of Linux-hosted sites to attacks. Hosting providers must update to protect the widely used security product.Source 8 The vulnerability bypassed protections for widespread compromise.Source 8

12

Basic-Fit Data Breach Compromises 1 Million Gym Members' Info

Europe's largest gym chain Basic-Fit suffered a breach where hackers accessed systems, stealing personal data of around 1 million members. The incident highlights ongoing risks to consumer data in non-critical sectors.Source 10 Unauthorized access methods are under review.Source 10