loader image
Hackers Use Pentest Tool to Breach Entra ID Accounts

A global account takeover campaign is exploiting a legitimate pentest tool to breach Entra ID environments, targeting over 80,000 user accounts across roughly 100 cloud tenants. The campaign, which escalated in December 2024, uses TeamFiltration—a penetration testing framework released at DefCon30—to compromise Microsoft Office 365 Entra ID users. Researchers at Proofpoint have identified the operation, […]

Rehab Worker Charged With Selling Patient Data

A former staff member at Evoke Wellness in Hilliard, Ohio, faces criminal charges for allegedly stealing and selling the personal data of at least 240 patients undergoing addiction treatment, according to Cybernews. The Rehab Worker Charged With data theft reportedly accessed confidential information during their time at the facility, raising significant concerns about medical privacy […]

Salt Typhoon Hackers Hit Cisco to Breach Canadian Telecom

China-linked threat group Salt Typhoon Hackers Hitnaturally targeted a major Canadian telecommunications provider by exploiting a critical Cisco vulnerability, according to a joint warning issued by the Canadian Centre for Cyber Security and the U.S. Federal Bureau of Investigation. The campaign is part of a broader cyber espionage effort aimed at breaching global telecom networks. […]

Ukraine Nabs Spies Using Dashcams for Missile Strikes

Ukrainian authorities have detained individuals accused of spying for Russia by using vehicle dash cameras to support missile targeting efforts. The suspects allegedly parked cars outfitted with activated dash cams near military installations and left them in place for up to 12 hours to capture detailed surveillance footage. According to officials, the recorded video was […]

UK Faces EU Pressure Over Data Adequacy Standards

European Digital Rights (EDRi), alongside its members Open Rights Group and Privacy International, has called on the European Commission to reconsider its stance on the United Kingdom’s data adequacy status. The civil society organizations argue that the UK should not have its data adequacy decisions renewed without implementing substantial reforms to its data protection regime. […]

Hackers Lure Victims With Fake Prompts in ClickFix Attacks

Hackers are deploying a new social engineering tactic known as “ClickFix” to exploit human error by mimicking routine computer prompts, cybersecurity researchers warned. First observed in March 2024, the method disguises malicious activity as legitimate system messages—such as CAPTCHA verifications or maintenance alerts—tricking users into executing harmful PowerShell commands. The technique has been linked to […]

Iran Hackers Target Iraq, Kurd Officials Since 2017

A hacking group with ties to Iran has been conducting a prolonged cyberespionage campaign targeting Kurdish and Iraqi officials, according to cybersecurity researchers. The group has been active since at least 2017, initially breaching systems associated with the Kurdistan Regional Government. Over the years, the scope of the campaign has widened to include entities within […]

Microsoft Issues Fix for Windows 11 Update Conflict

Microsoft has issued a revised version of its Windows 11 24H2 update to address compatibility issues reported with the original release earlier this month. The company confirmed Tuesday that the new update targets systems deemed incompatible with the initial Patch Tuesday rollout, which included security enhancements. The separate build is intended to ensure that affected […]

Euro Cops Bust Archetyp, Seize $270 Million Drug Hub

European law enforcement agencies dismantled a major dark web drug marketplace known as Archetyp, arresting eight individuals linked to the illicit operation. Authorities said the takedown, dubbed one of the largest of its kind, came after a coordinated investigation across multiple countries. Euro Cops Bust Archetyp marked a significant blow to underground online drug trade […]

NHS Teams Embrace AI as Calls Grow for Clear Rules

NHS communications teams are increasingly integrating artificial intelligence into their operations, according to a new survey by the NHS Confederation. The findings show growing enthusiasm across organizations as NHS teams embrace AI naturally to manage workloads, streamline messaging, and enhance public engagement. While the report highlights a surge in adoption, it also underscores the need […]

Hackers Twist ScreenConnect Into Signed Malware

Hackers twist ScreenConnect into a new cyber threat by manipulating the installer’s digital signature, turning the legitimate remote access tool into a vehicle for malware. According to recent findings, threat actors are exploiting the ConnectWise ScreenConnect client by altering concealed settings within its Authenticode signature. This technique allows them to create signed remote access malware […]

Australia Orders Ransomware Payment Reports in 3 Days

Australia has enacted new regulations mandating that covered organizations report ransomware and cyber extortion payments within three days. The requirement is part of a broader effort to strengthen the country’s cybersecurity posture and improve incident transparency. Under the new rules, entities classified as covered organizations must disclose any payments made in response to ransomware attacks […]