The Record (Recorded Future News)
therecord · B · active
Cybersecurity journalism owned by Recorded Future. The homepage / lists recent dated articles. /news/cybercrime is a navigation/podcast hub with NO articles, never cite this path. Article slugs are top-level, do not GUESS slugs from headlines; always start at the homepage and follow the actual link. RSS at https://therecord.media/feed. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://therecord.media/ (homepage) OR feed https://therecord.media/feed 5, then webfetch the top-level /<slug> article. AVOID: Never cite /news/cybercrime (navigation/podcast hub, no articles); do not GUESS slugs from headlines, follow the actual link from homepage/feed. | 2026-07-05 admiralty audit: B, original, corroborated cybersecurity journalism; live. Keep active. Follow homepage/feed links, never guess slugs or cite /news/cybercrime.
Cited in 42 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 37).
- WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm"2026-09-19
- CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory2026-09-16
- BlueMoon: five separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week2026-09-10
- Thomson Reuters' C-Track court case-management platform breach reaches at least 13 US states, the US Virgin Islands and three Ontario courts2026-09-05
- Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments2026-09-02
- Norway's shared national identity gateway ID-porten knocked out for 64 hours by the third escalating DDoS against Digdir since June2026-08-31
- Latvia's vehicle-registration authority lost payment records on two-thirds of the country's population, and the provider contractually watching its infrastructure round the clock did not notice2026-08-20
- Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself2026-08-19
- Evooo1Bot: a Mirai-derived Linux botnet whose exploit arsenal reaches Confluence, WSO2 and Kubernetes ingress-nginx, and whose SSH dictionary is stocked with enterprise service accounts rather than router defaults2026-08-16
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed2026-08-05
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution2026-08-04
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable2026-08-03
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated2026-07-31
- Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it2026-07-29
- Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration, now exposed in a 16-nation joint advisory2026-07-24
- CERT.LV: ransomware crew breaches Latvia's state forestry operator LVM via a 2-year-unpatched system, hits essential-services provider Olpha, and is probing other EU/NATO institutions2026-07-10
- Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus2026-07-03
- Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection2026-06-27
- Citizen Lab: Cellebrite UFED used by Russian authorities three months after the vendor's Russia pull-out2026-06-27
- Ukrposhta digital services disrupted by an overnight attack; pro-Russian hacktivists claim a prior data theft2026-06-26
- UK Information Commissioner resigns with immediate effect, regulator left leaderless mid-restructure2026-06-21
- The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national2026-06-20
- South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key held by a former employee2026-06-13
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration2026-06-11
- Five Eyes joint bulletin: Chinese military intelligence recruiting cleared personnel through LinkedIn and job platforms2026-06-06
- Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands2026-05-29
- Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front, 700 GB exfiltrated, backups and VMs deliberately destroyed2026-05-28
- FBI FLASH CSA 260526, Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails2026-05-28
- Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach, misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000 season-ticket records2026-05-28
- Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected2026-05-27
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed2026-05-24
- Kimwolf / "Dort" DDoS-for-hire operator arrested, 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant2026-05-23
- FBI PSA260521, Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture2026-05-23
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations2026-05-20
- Huawei VRP enterprise-router zero-day caused POST Luxembourg nationwide telecom outage (July 2025), no CVE filed 10 months later2026-05-20
- THORChain GG20 Threshold Signature Scheme vault drain, ~$11M across nine chains; Switzerland-based protocol2026-05-18
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany, cryptocurrency-to-physical-gold OPSEC failure after seven years at large2026-05-16
- Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed2026-05-13
- ICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record2026-05-12
- DAEMON Tools Lite supply chain, QUIC RAT deployed via signed installer; EU governments among targeted victims2026-05-09
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed2026-05-08