Google Threat Intelligence Group has tracked threat actor UNC6395 stealing OAuth tokens via Salesloft Drift integrations in a massive Salesforce data theft campaign.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A cyber attack on Nevada has disrupted state services, including phone lines, websites, and online systems, forcing several offices to close with no expected date of resolution.
A recent campaign of cyber attacks made new and novel use of the Claude AI chatbot in scanning VPN endpoints and automating multiple portions of the attack cycle, representing another step forward in the deployment of LLMs for malicious purposes.
A whistleblower report submitted to Congress and the Office of Special Counsel claims that DOGE employees uploaded a very sensitive Social Security Administration (SSA) database to a vulnerable cloud server while auditing the agency, one that contains Social Security numbers for 300 million Americans as well as associated identity information.
Farmers Insurance Hit by Third-Party Data Breach Exposing Personal Information of 1.1 Million People
A third-party data breach at Farmers Insurance has exposed the sensitive personal information of over 1.1 million people after hackers breached a vendor-managed database.
Recent letters sent out by FTC Chairman Andrew N. Ferguson were directed to tech companies and warned against watering down privacy protections or censoring their products due to pressure by foreign governments.
The UK government has dropped its controversial plan to mandate an encryption backdoor into Apple's cloud storage systems, according to a statement by US Director of National Intelligence Tulsi Gabbard.
Russian hackers linked to the country’s Federal Security Service (FSB) Center 16 have exploited vulnerable Cisco devices for over a year to target critical infrastructure organizations for cyber espionage.
A ransomware attack has forced drug research firm Inotiv to shut down critical systems, resulting in operational disruptions. The Qilin cyber gang has taken responsibility for the Inotiv ransomware attack and listed the drug research firm on its data leak site.
British telecommunications service provider Colt Telecom has attributed the multi-day service disruption to a cyber attack claimed by the prolific WarLock ransomware group.










