Home › Cyber News
CYBER NEWS · HACKS · SCAMS

Cyber security news and hacks, in plain English

Real incidents, explained simply, each with dated sources and a “what this means for you” box. From the USB attacks on Iran and the US to the biggest crypto thefts and the breaches of 2026.

Updated October 9, 2026 · Written and maintained by the cyberhygiene.tools team

The full stories

The four biggest stories on this page, told in full. Each one says what is confirmed, what is only reported, and what it means for you, with dated sources.

History · USBPublished October 9, 2026

Stuxnet: the USB-spread cyberweapon that hit Iran's nuclear programme

What happened

Stuxnet was discovered in June 2010. It was a computer worm aimed at Siemens industrial control software and the controllers it programs, and it was built to damage the centrifuges at Iran's Natanz uranium enrichment plant.

Researchers at the security company Symantec reported that it only acted on specific equipment running at specific speeds. That suggests it was made for one particular target rather than for general damage. About 60% of the infected computers Symantec found were in Iran.

How it got into a plant with no internet

Natanz's control computers were kept off the internet on purpose. Stuxnet was built around that. Industrial systems are often programmed from standalone Windows computers, and staff move files between them on removable drives. Stuxnet copied itself onto any USB drive that was plugged in.

Symantec also reported that Stuxnet first hit five Iranian organisations between June 2009 and May 2010, before it reached the plant. Those organisations were not named, but their business ties to the plant appear to have given the worm a route in. Symantec traced about 12,000 infections back to them. The worm also used several previously unknown Windows flaws, including one that could run code just by showing a shortcut icon in a folder.

What it did to the centrifuges

Stuxnet is reported to have targeted motor-speed controllers connected to the centrifuges and damaged them. The Institute for Science and International Security estimated in December 2010 that up to about 1,000 centrifuges, around 10%, were destroyed between November 2009 and late January 2010. That is an estimate, not a verified figure.

On November 29, 2010 Iran's president at the time, Mahmoud Ahmadinejad, said a computer virus had caused problems for "a limited number" of centrifuges. Iran later replaced the damaged equipment.

Who was behind it

Nobody has officially taken responsibility. The New York Times reported on June 1, 2012 that Stuxnet was part of a joint US and Israeli operation. Neither government has confirmed it. Kaspersky concluded an attack this advanced needed the backing of a nation state. A 2019 report that an engineer recruited by Dutch intelligence carried it in relies on unnamed sources and is unconfirmed.

What this means for you

  • Never plug in a USB drive you found, or one handed to you by a stranger.
  • Turn off AutoPlay so a drive cannot launch anything by itself. In Windows, search Settings for "AutoPlay" and set it to take no action.
  • Keep your computer updated. Stuxnet relied on flaws that updates close.
  • At work, hand found drives to IT instead of checking what is on them.
Read the full article →
History · USBPublished October 9, 2026

Agent.btz: how one USB drive breached the US military

What happened

In 2008 a USB flash drive carrying malware was inserted into a laptop at a US military base in the Middle East. From that one laptop, a worm called Agent.btz spread onto a network run by US Central Command, across both classified and unclassified systems, without being noticed.

US Deputy Defense Secretary William Lynn confirmed the incident publicly in an article for Foreign Affairs, reported on August 25, 2010. He said the malicious code on the drive had been placed there by a foreign intelligence agency. A senior US defence official later called it the most significant breach of US military computers. Some retellings say the drive was left in a car park for someone to find. The sources we checked do not confirm that.

How it worked

Agent.btz is reported to be a variant of an older worm called SillyFDC, which spread whenever an infected removable drive was plugged into a computer. It could scan an infected computer for certain data and open a backdoor to a remote server. Lynn described the result as a "digital beachhead" from which information could be sent out.

The sources disagree on whether data was actually stolen. One report says classified and unclassified data was sent to servers under foreign control. Another says Lynn did not say whether any data was taken.

The response

The Pentagon banned removable drives and switched off the Windows AutoPlay feature to slow the spread. Wired reported this on November 19, 2008. The ban was later lifted. The clean-up, named Operation Buckshot Yankee, took more than a year, and reports link the incident to the later creation of US Cyber Command.

Who was behind it

Lynn did not name the agency in 2010. In December 2016 a joint FBI and Department of Homeland Security report attributed Agent.btz to "one or more" Russian civilian and military intelligence services. Wired reported in 2010 that some insiders doubted it was a foreign spy operation, so treat the attribution as reported, not settled.

What this means for you

  • The US military has strong security and still lost control of its networks because one person plugged in one drive.
  • Never plug in a drive you found or were given by a stranger. A "lost" drive left where you will find it is a classic trap.
  • Turn off AutoPlay, and keep your computer and apps updated.
  • In public, use your own charger and cable, or a USB data blocker.
Read the full article →
CryptoPublished October 9, 2026

Bybit: the biggest crypto theft on record

What happened

On or about February 21, 2025 attackers stole about US$1.5 billion from the crypto exchange Bybit. It was described as the largest crypto theft recorded at that time.

How it happened

Security reviews by Sygnia and Verichains, reported by BleepingComputer, found the attackers did not break into Bybit's own systems directly. They first compromised a developer's computer at Safe{Wallet}, a wallet service Bybit used. That gave them access to Bybit's wallet account.

They then intercepted a routine transfer from Bybit's offline storage and redirected the money to wallets they controlled. The FBI said the stolen funds were being converted to bitcoin and other assets and spread across thousands of addresses, and it published a list of 51 Ethereum addresses holding stolen funds.

Who was behind it

On February 26, 2025 the FBI issued a public notice naming North Korea, specifically the groups known as TraderTraitor, Lazarus Group and APT38. The same groups were blamed by the FBI for the US$620 million Ronin Network theft in March 2022.

The bigger picture

Chainalysis, a firm that tracks crypto crime, estimates more than US$3.4 billion was stolen across the crypto world in 2025, and that North Korea-linked hackers took at least US$2.02 billion of it, up 51% on the year before. It also counted about 158,000 personal wallet compromises, with roughly US$713 million taken from individuals. Figures are in US dollars, as reported.

What this means for you

  • Never share your recovery phrase. Nobody legitimate will ever ask for it, including "support staff".
  • Use a hardware wallet for any amount you cannot afford to lose, and keep the recovery phrase offline.
  • Do not leave everything on one exchange.
  • Use an authenticator app, not text messages, for two-factor sign-in, and double-check wallet addresses before sending.
Read the full article →
2026Published October 9, 2026

Stryker: tens of thousands of work devices wiped

What happened

On about March 11, 2026 attackers got into the internal Microsoft environment of Stryker, a US medical technology company, and remotely wiped employee devices. Stryker confirmed "tens of thousands" of devices were affected. It said this was not ransomware, that no malware was deployed, and that its medical products and connected devices were not affected.

How it happened

BleepingComputer, citing a source, reported that the attacker compromised an administrator account and then used a device management tool's built-in wipe command. In other words, the attackers did not need to write or plant any malicious software. They used a normal admin tool against the company.

Who was behind it

A group called Handala claimed the attack. Security researchers widely link Handala to Iran, but that link is not officially confirmed. Device counts vary: Stryker confirmed "tens of thousands", one report says nearly 80,000, and Handala claims more than 200,000. Treat the larger figures as claims.

What this means for you

  • One stolen admin login can do more damage than malware.
  • Protect every admin and email account with two-factor authentication.
  • Keep backups that a single account cannot delete.
  • At home, the same rule applies to your main email: it is the admin account for your whole digital life.
Read the full article →

How we cover the news

We link every claim to a source and show its date. When something is reported but not confirmed, we say so, and we leave out what we cannot verify. Dollar amounts are given in US dollars, as reported. Our editorial policy explains how we work, and you can tell us about a mistake through Contact Us.

What to do with any of it

Most stories lead to the same short list: strong, different passwords, two-factor sign-in, automatic updates and verifying anything urgent through a channel you chose. Our stay safe online guide puts it all in one place.