A June 2023 security breach at the Treasury's Office of the Comptroller of the Currency led to the theft of over 150,000 emails from about 100 accounts, but the damage is possibly more extensive as the hackers likely lurked in the bank regulator's systems into early 2025.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A recent campaign of cyber attacks made new and novel use of the Claude AI chatbot in scanning VPN endpoints and automating multiple portions of the attack cycle, representing another step forward in the deployment of LLMs for malicious purposes.
Hackers published one million stolen credit cards on the dark web to attract cybercriminals to their recently launched carding site. Up to 50% of the cards are active.
A cybersecurity startup Buguard said hackers used malware to steal passwords for Wiseasy's remote control dashboards to compromise payment terminals worldwide. Hackers could control payment terminals, install and remove apps, access personal information, and make configuration changes using the remote control dashboards.
Google Threat Intelligence Group has tracked threat actor UNC6395 stealing OAuth tokens via Salesloft Drift integrations in a massive Salesforce data theft campaign.
Microsoft discovered a coordinated phishing campaign targeting Office 365 users and leveraging an Adversary-in-the-Middle (AiTM) MFA bypass to execute business email compromise (BEC) attacks and commit fraud.
Since March 2019, hackers have been targeting the UN and affiliated humanitarian aid organizations with a sophisticated, mobile-centric phishing campaign to harvest Microsoft Office 365 login credentials.
Fear of Russian hackers infiltrating voting machines in the last U.S. presidential election has led to a new bill to enlist hackers to find vulnerabilities.
Google's new Cybersecurity Action Team warned that cybercriminals compromised unsecured or misconfigured Google Cloud instances to perform cryptocurrency mining.
Attackers exploit Google reCAPTCHA forms to sneak into users' inboxes because automated email security scanners cannot solve CAPTCHAs to determine the destination phishing URLs.










