A cybersecurity startup Buguard said hackers used malware to steal passwords for Wiseasy's remote control dashboards to compromise payment terminals worldwide. Hackers could control payment terminals, install and remove apps, access personal information, and make configuration changes using the remote control dashboards.
Google Threat Intelligence Group has tracked threat actor UNC6395 stealing OAuth tokens via Salesloft Drift integrations in a massive Salesforce data theft campaign.
Microsoft discovered a coordinated phishing campaign targeting Office 365 users and leveraging an Adversary-in-the-Middle (AiTM) MFA bypass to execute business email compromise (BEC) attacks and commit fraud.
Since March 2019, hackers have been targeting the UN and affiliated humanitarian aid organizations with a sophisticated, mobile-centric phishing campaign to harvest Microsoft Office 365 login credentials.
Fear of Russian hackers infiltrating voting machines in the last U.S. presidential election has led to a new bill to enlist hackers to find vulnerabilities.
Google's new Cybersecurity Action Team warned that cybercriminals compromised unsecured or misconfigured Google Cloud instances to perform cryptocurrency mining.
Attackers exploit Google reCAPTCHA forms to sneak into users' inboxes because automated email security scanners cannot solve CAPTCHAs to determine the destination phishing URLs.
Attackers exfiltrated sensitive data from thousands of websites, desktop, and mobile applications in a supply chain attack leveraging typo-squatting in popular NPM packages.
By searching the internet, hackers have begun hijacking smart building access control systems to recruit these IoT devices into botnets for launching DDoS attacks.
Malicious actors are using deepfake videos impersonating YouTube’s CEO to steal users’ credentials in a multi-month phishing campaign. The attackers sent private videos to targeted users via legitimate-looking emails, warning them that YouTube was changing its monetization policies.









