Topic: corporate security

  • Microsoft Disrupts AI Platform That Compromised 12,000 Accounts

    Microsoft Disrupts AI Platform That Compromised 12,000 Accounts

    Microsoft dismantled the EvilTokens AI scam infrastructure, which used an automated chatbot to breach 12,000 user accounts across thousands of organizations for a subscription fee. The platform exploited OAuth device code authentication to gain unauthorized email access without passwords or MFA a...

    Read More »
  • Microsoft Teams vishing leads to Chaos ransomware attacks

    Microsoft Teams vishing leads to Chaos ransomware attacks

    Cybercriminals posing as IT support staff over Microsoft Teams calls have targeted North American businesses, with 95% of attacks hitting Canadian (50%) and U.S. (45%) entities across services, manufacturing, energy, and construction sectors. The scheme uses external Teams accounts and IT-themed ...

    Read More »
  • LastPass confirms breach in Klue supply chain attack

    LastPass confirms breach in Klue supply chain attack

    LastPass confirmed a data breach after attackers stole OAuth tokens during the Klue supply chain attack, compromising customer data in its Salesforce environment without affecting core password vaults or master passwords. Hackers exploited vulnerabilities in the third-party platform Klue to captu...

    Read More »
  • Who Bears the Cost of Gating Advanced AI Models?

    Who Bears the Cost of Gating Advanced AI Models?

    Jaya Baloo examines the debate over limiting access to advanced AI with cybersecurity capabilities, starting with the rationale that gating mechanisms prevent malicious exploitation by bad actors. She argues that gating backfires by hindering security teams who need unfettered AI access to simula...

    Read More »
  • Why JLR’s CISO Mandated In-Person Password Resets After Cyber-Attack

    Why JLR’s CISO Mandated In-Person Password Resets After Cyber-Attack

    Jaguar Land Rover's former CISO Ashish Shrestha required over 30,000 employees to reset their passwords in person after a major cyber-attack, prioritizing security over convenience. The in-person resets allowed the security team to verify identities, educate staff on threats, and enforce stronger...

    Read More »
  • Securing the AI blind spot from virtual barbarians at the gate

    Securing the AI blind spot from virtual barbarians at the gate

    The rapid integration of AI into business operations has created unfamiliar attack surfaces and novel exploitation methods that traditional security tools cannot detect. AI applications behave in non-deterministic ways, making it difficult for security teams to predict how attackers might exploit...

    Read More »
  • Microsoft Confirms Active 0-Day - Apply Emergency Fix Now

    Microsoft Confirms Active 0-Day - Apply Emergency Fix Now

    Microsoft has confirmed the CVE-2026-42897 zero-day spoofing flaw in on-premises Exchange Server 2016, 2019, and Subscription Edition, which CISA has added to its Known Exploited Vulnerabilities Catalog due to active exploitation. Microsoft urges organizations to immediately enable and verify the...

    Read More »
  • Fired Twin Brothers Wipe 96 Government Databases in Minutes

    Fired Twin Brothers Wipe 96 Government Databases in Minutes

    Employers often terminate digital access before notifying employees of their firing, as active credentials from disgruntled former employees pose a major security threat. The Akhter twin brothers are accused of deleting 96 government databases within minutes of being fired, after previously plead...

    Read More »
  • Education Tech Giant Instructure Breached, Hackers Steal Student Data

    Education Tech Giant Instructure Breached, Hackers Steal Student Data

    Instructure confirmed a data breach of its Canvas platform, with ShinyHunters hacking group stealing sensitive student data including names, email addresses, and teacher-student messages. ShinyHunters provided a sample of stolen data from two U.S. schools and claimed roughly 8,800 schools were im...

    Read More »
  • Cosmetics brand Rituals reveals customer data breach

    Cosmetics brand Rituals reveals customer data breach

    Rituals confirmed a data breach of its "My Rituals" membership database, compromising customer names, email addresses, phone numbers, and shipping addresses, but not financial payment details. The company notified affected customers, reported the incident to Dutch authorities, and advised custome...

    Read More »
  • Basic-Fit Data Breach Impacts 1 Million Gym Members

    Basic-Fit Data Breach Impacts 1 Million Gym Members

    A major data breach at European fitness chain Basic-Fit has compromised the personal information of approximately one million members across its operating regions. The exposed data likely includes sensitive details like names and contact information, prompting the company to activate its incident...

    Read More »
  • Starbucks Employee Data Breach Impacts Hundreds

    Starbucks Employee Data Breach Impacts Hundreds

    A security breach at Starbucks compromised the personal data of several hundred employees by targeting the internal **Starbucks Partner Central** platform, which manages work schedules and payroll. The exposed data likely includes sensitive information like names and Social Security numbers, prom...

    Read More »
  • AkzoNobel U.S. Site Hit by Cyberattack, Company Confirms

    AkzoNobel U.S. Site Hit by Cyberattack, Company Confirms

    AkzoNobel, a major paints and coatings company, confirmed a contained cybersecurity breach at a U.S. facility, with the impact appearing limited. The Anubis ransomware gang claimed responsibility, alleging theft of 170 GB of sensitive data, including confidential agreements and employee personal ...

    Read More »
  • Report: Chinese hackers exploited VPN flaws to breach Ivanti customers

    Report: Chinese hackers exploited VPN flaws to breach Ivanti customers

    State-linked Chinese hackers exploited a hidden backdoor in Ivanti's Pulse Secure VPN in February 2021, compromising 119 organizations including government agencies and military contractors. The breach is linked to corporate restructuring after Ivanti's 2017 acquisition, where cost-cutting and la...

    Read More »
  • 1Password's New Anti-Phishing Tool Protects Your Weakest Link

    1Password's New Anti-Phishing Tool Protects Your Weakest Link

    AI-powered phishing scams are creating sophisticated, convincing fake websites at scale, posing a significant threat to both individuals and corporations as a common entry point for attacks. 1Password's new phishing protection feature counters this by issuing a warning when users manually paste c...

    Read More »
  • 48 Million Gmail Credentials Leaked Online

    48 Million Gmail Credentials Leaked Online

    A database containing nearly 149 million login credentials, including an estimated 48 million Gmail accounts, was exposed online, compiled from past breaches and infostealer malware. The primary risk is credential stuffing attacks, where stolen usernames and passwords are used to access other acc...

    Read More »
  • Okta Users Targeted by Advanced Phishing & Vishing Kits

    Okta Users Targeted by Advanced Phishing & Vishing Kits

    New phishing kits enable real-time credential interception and control of authentication flows, targeting users of major identity platforms like Google and Microsoft. These attacks combine voice phishing with dynamic, convincing fake login pages that bypass multi-factor authentication methods lik...

    Read More »
  • Scammers Impersonate Police to Steal Private Data From Tech Giants

    Scammers Impersonate Police to Steal Private Data From Tech Giants

    Hackers are impersonating law enforcement to fraudulently obtain private customer data from major tech companies like Apple and Amazon, exploiting weak corporate verification processes for emergency data requests. A criminal group operates a "doxing-as-a-service" model, boasting hundreds of succe...

    Read More »
  • Ivanti warns of critical code execution flaw in Endpoint Manager

    Ivanti warns of critical code execution flaw in Endpoint Manager

    A critical vulnerability (CVE-2025-10573) in Ivanti's Endpoint Manager allows unauthenticated attackers to execute arbitrary code by tricking an administrator into viewing a compromised dashboard. Ivanti has released a patch, but the risk is heightened as hundreds of EPM instances are exposed onl...

    Read More »
  • Beware: Hackers Hijack Calendar Subscriptions for Attacks

    Beware: Hackers Hijack Calendar Subscriptions for Attacks

    Hackers exploit digital calendar subscriptions by using deceptive systems to deliver malicious content like phishing links and malware through third-party feeds. BitSight's investigation revealed that expired or hijacked domains were used in large-scale campaigns, affecting millions of users thro...

    Read More »