New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spo…
Unauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ …
Key Takeaways Proofpoint has observed OAuth client ID spoofing emerging as a novel technique, increasingly leveraged in cloud campaigns. Microsoft En…
Tomorrowland 2026 sold out fast, and scammers moved faster. CloudSEK uncovered a dozen fake ticket shops and travel sites mimicking the festival, com…
Summary Since 26 June 2026, an unattributed threat actor has published at least 292 deceptive brand-impersonation GitHub pages and .github repositori…
Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of it…
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been download…
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and cry…
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Sepa…
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromis…
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after resear…
Following the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her corres…
German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers …
The UK and EU are demanding urgent action from critical infrastructure organizations after formally attributing the December 2025 cyberattack on Pola…
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of i…
The EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targetin…
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in…
UK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used …
Ghostcommit is a proof of concept that shows how AI assistants used to review software code can be tricked by hidden instructions embedded in images.…
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, …
It’s no secret that cybercriminals have recently been leveraging large language models to optimize their operations. As a result, numerous phishing a…
A former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential…
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Sto…
Hudson Rock says the suspected compromise of the Argentine Football Association (AFA) may be linked to an infostealer infection nearly a year earlier…
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network …
You want to turn some crypto into a gift card. You search, click a promising result, and land on a site that looks polished and legitimate: a dark th…
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (A…
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP cred…
Progress Software has ordered some ShareFile customers to pull the plug on their own servers after detecting what it describes as a "credible externa…
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execut…
The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage o…
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerab…
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Explo…
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers L…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. T…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensi…
Chip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a ra…