A roundup of the alerts, incident reports and security tips we published on our Telegram channel Cyber Israel during 2025. Join the channel to get these updates in real time (updates are posted in Hebrew).

May 5, 2025

❗ Investor impersonation scams: don't take the bait!
If you've recently seen ads on Facebook, Instagram, or Reels in which "leading investors" such as Dovi Frances, Gil Shwed, Yasmin Lukatz, Prof. Amnon Shashua, or Eyal Waldman invite you to join an investment that will change your life — stop for a moment.
🚨 This is a malicious, large-scale phishing campaign.
Hundreds of fake profiles and sponsored ads are launched every day — some featuring fabricated or edited videos and interviews — all with a single goal: to steal your money.
🧠 Sophisticated impersonation, persuasive language, sponsored campaigns — but it is not really them.
The real entrepreneurs are aware of the phenomenon, and some have even reported it publicly, yet the damage continues.
📉 The victims? Ordinary people who simply believed an offer "they couldn't refuse."
💰 The promises? Returns of thousands of percent within days.
🔒 How can you tell it's a scam?
• An unverified page running a sponsored post promising fast returns.
• Links leading to a suspicious website or demanding that you enter credit card details right away.
• Ads featuring well-known business figures, but posted from a brand-new page or one with a misspelled name.
🙏 Stay safe. Don't be tempted by "dream" offers that will end in a nightmare.
Help spread the word so no one else falls victim:
📲 Share this post.
📢 Report every fake ad.
👥 Talk to the people close to you — especially older adults.
#Fraud #Phishing #FakeInvestments #Cyber #Impersonation

Join to receive cyber-security updates
Telegram channel https://t.me/cyberisrael
Facebook group
https://www.facebook.com/groups/cyberisrael
Lior Ben-David, entrepreneur, researcher, and lecturer in cyber security and blockchain.

View the original update on Telegram →

May 12, 2025

❗ Email security vulnerability at the Ministry of Justice — apparently exploited for widespread impersonation over the past week ❗
In recent days, reports have come in of suspicious emails sent in the name of the Ministry of Justice from addresses such as:
legal.department@justice.gov.il, using convincing legal language and content.
🔍 A technical analysis performed by Serge Cherniak shows that the official domain justice.gov.il http://justice.gov.il/ is misconfigured:
• ❌ No active DKIM signature — no content-authentication mechanism.
• ❌ SPF record fails — the actual sending servers are not authorized under the domain's configuration.
• ❌ No DMARC policy — there is no policy instructing mail servers how to handle messages that fail authentication.
🧯 What this means:
The absence of these three most basic layers of protection allows attackers to send emails in the Ministry of Justice's name that will appear entirely legitimate to most recipients — including browsers, email clients, and anti-spam systems.
🔐 Recommendations:
• The Ministry of Justice should urgently implement SPF, DKIM, and DMARC settings to reduce impersonation risk.
• The public should exercise extra caution with any email correspondence arriving in the Ministry's name — and avoid clicking links or opening suspicious attachments.
• Organizations that communicate with government bodies should enable active filtering and verification of sender addresses (SPF/DKIM enforcement) at the mail-server level.
🛡️ In a world where every user is a potential target for social-engineering attacks, responsibility for proper email configuration is not a matter of convenience — it is a matter of protecting the public.
📲 Share this post.
#Fraud #Phishing #FakeInvestments #Cyber #Impersonation
Join to receive cyber-security updates
Telegram channel https://t.me/cyberisrael
Facebook group
https://www.facebook.com/groups/cyberisrael
Lior Ben-David, entrepreneur, researcher, and lecturer in cyber security and blockchain.

View the original update on Telegram →

June 12, 2025

‼️‼️‼️
Widespread disruptions are currently affecting leading cloud services, including Google Cloud, Amazon, and Cloudflare. The outage is impacting several essential Google services across the US, Europe, and Asia, and is also hitting platforms such as GitHub, Mailchimp, Replit, and Twitch.

According to reports on Downdetector, there are more than 13,000 reports of issues with Google Cloud, and the company's stock has dropped 6% as a result. Cloudflare has also reported failures across many of its services and is still investigating the cause.

If you depend on these services, keep monitoring the situation and let us know if further disruptions occur.

View the original update on Telegram →

July 2, 2025

🚨 Serious breach! 🚨
The Israeli domain registrar Pligon (webline.co.il http://webline.co.il/) was hacked overnight.
For all compromised customers, a new NS address was set pointing to an attacker-controlled domain, glitweb*.*xyz, which displays Iranian anti-Israel propaganda videos with a redirect to their propaganda site:

👉 fathalqouds*.*com
🔒 If you have domains managed through Pligon — check your NS settings immediately,
change your passwords and secure your account, and keep in mind that certain providers may be affected as well. The issue is being handled.

Share as widely as possible! 🇮🇱

View the original update on Telegram →

July 10, 2025

It appears Isracard is experiencing a widespread outage — many customers are reporting that they cannot log in to the app.

View the original update on Telegram →

July 10, 2025

Global outage affecting Outlook and Hotmail services. Microsoft says it is aware of the issue and working on a fix.

View the original update on Telegram →

July 13, 2025

The Bit payment app has been experiencing difficulties for several hours now — users are unable to log in or transfer money.

View the original update on Telegram →

November 18, 2025

Cloudflare is down! A huge number of services and websites are offline

View the original update on Telegram →

November 25, 2025

🚩 Hi everyone,
Just raising a red flag 🚩 — a very significant supply-chain attack called Shai-Hulud 2.0 (per Wiz) is unfolding right now, compromising a huge number of npm packages and thousands of projects. For some reason, it still isn't getting enough attention.

I strongly recommend passing these guidelines to your development / DevOps teams for an urgent scan of dependencies and post/pre-install scripts:
https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
Better to catch it in time than after the fact 🙏

View the original update on Telegram →

Join our Telegram channel

🇮🇱 לקריאת הפוסט בעברית