Category archive
Scam alerts
Track the latest scam alerts, fake support incidents, delivery fraud, payment scams and rapid verification guidance in one archive.
This landing page groups scam alerts into one indexable archive so users and Google can navigate the incident stream by topic instead of only by date, with stronger internal links into the right tools and recovery paths.
Filter the alert archive
Narrow the archive by category and risk level to review phishing alerts, data breach alerts, malware coverage, vulnerability updates and ransomware incidents faster.
Full alert archive
Showing 12 of 241 matching alerts.
Each alert card surfaces the threat type, documented summary and best next step so the listing itself can answer intent around latest cybersecurity alerts, phishing alerts, breach alerts and incident response without forcing every visitor to click through immediately.
Older alerts from 2021-2025 are still available, but stronger, documented and more recent reporting is ranked first so the archive stays aligned with current Google quality expectations.
Lawmakers Debate Terrorism Labels and Homicide Charges for Hospital Ransomware Attacks Amid Rising Threats
Human review: Marcin Pocztowski | Source date: Apr 21, 2026 | Sources: 1As ransomware attacks targeting hospitals surge, U.S. lawmakers are considering elevating these cybercrimes to terrorism designations and pursuing homicide charges aga... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Backdoor in Popular WordPress Redirect Plugin Allowed Five Years of Arbitrary Code Injection
Human review: Marcin Pocztowski | Source date: May 01, 2026 | Sources: 1A stealthy backdoor embedded in the widely used Quick Page/Post Redirect WordPress plugin has enabled arbitrary code execution on affected sites for nearly five years.... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.
Best next step: Identity Theft Recovery Planner
Dutch Phishing Sites Remain Active for Average of 20 Hours, SIDN Reports
Human review: Artur Ślesik | Source date: Apr 30, 2026 | Sources: 1Phishing websites registered under the.nl domain persist online for an average of 20 hours, according to SIDN, the Dutch domain registry. This extended uptime increase... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Chinese Spear-Phishing Campaign Targets NASA Employees to Steal U.S. Defense Software Secrets
Human review: Artur Ślesik | Source date: Apr 24, 2026 | Sources: 1A sophisticated Chinese spear-phishing operation has compromised NASA employees to illicitly access sensitive U.S. defense software and export-controlled information. Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
Proofpoint Uncovers Cargo Theft Gang's Sophisticated Post-Breach Fraud Tactics
Human review: Artur Ślesik | Source date: Apr 21, 2026 | Sources: 1Proofpoint researchers have tracked a cargo theft gang that, after breaching a decoy network, spent weeks probing critical systems related to banking, fleet payments,... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
SmokedMeat: New Open-Source Tool Reveals Attack Techniques Inside CI/CD Pipelines
Human review: Marcin Pocztowski | Source date: Apr 20, 2026 | Sources: 1Boost Security has released SmokedMeat, an open-source framework designed to simulate attacker behaviors within CI/CD environments by exploiting pipeline vulnerabiliti... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Discontinued D-Link DIR-823X Routers Exploited by Mirai Botnet via CVE-2025-29635 Command Injection
Human review: Marcin Pocztowski | Source date: Apr 23, 2026 | Sources: 1Since early 2025, discontinued D-Link DIR-823X routers have been actively targeted by the Mirai botnet exploiting a known command injection vulnerability (CVE-2025-296... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Trojanized TestDisk Installer and Microsoft Binary Exploited for Illicit ScreenConnect Deployment
Human review: Marcin Pocztowski | Source date: Apr 21, 2026 | Sources: 1A sophisticated attack campaign has been uncovered involving a trojanized TestDisk installer and abuse of a Microsoft-signed binary for DLL side-loading to deploy Conn... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.
Best next step: Identity Theft Recovery Planner
The FTC Expands Its AI Enforcement Portfolio to Combat Deepfakes and Voice Cloning Scams
Human review: Artur Ślesik | Source date: Apr 20, 2026 | Sources: 1The Federal Trade Commission (FTC) is significantly broadening its regulatory scope over AI technologies, focusing on combating sexual deepfakes and AI-driven voice cl... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
DPRK Fake Job Scams Self-Propagate via Compromised Developer Repositories Spreading RATs
Human review: Artur Ślesik | Source date: Apr 22, 2026 | Sources: 1A sophisticated North Korean-linked fake job scam has evolved into a self-propagating malware campaign leveraging compromised developer repositories. This worm-like in... Documented alert summary. Focus: lure pattern, spoofing signals and account-protection next steps.
Best next step: Identity Theft Recovery Planner
New 'Copy Fail' Linux Kernel Flaw Lets Local Attackers Gain Root Access
Human review: Marcin Pocztowski | Source date: Apr 30, 2026 | Sources: 1A critical local privilege escalation vulnerability called 'Copy Fail' affects Linux kernels released since 2017, allowing unprivileged users to gain root access. Majo... Documented alert summary. Focus: affected products, exploit urgency and remediation guidance.
Best next step: Identity Theft Recovery Planner
Operation PhantomCLR: Hackers Exploit AppDomain Hijacking to Weaponize Trusted Intel Utility
Human review: Marcin Pocztowski | Source date: Apr 20, 2026 | Sources: 1A sophisticated cyberattack campaign named Operation PhantomCLR has been uncovered, where hackers exploit AppDomain hijacking to covertly turn a legitimate, digitally... Documented alert summary. Focus: infection path, likely payload impact and containment priorities.
Best next step: Identity Theft Recovery Planner
Alerts archive SEO topics
Archive maintenance and remediation tracking. HackWatch does not treat alerts as one-time posts. We continue checking whether vendors have issued patches, workarounds or final remediation updates, then refresh the article with the latest incident status so readers can see whether a threat is still active, mitigated or already resolved.