An established cybercrime gang leaked sensitive data, including unredacted child abuse files, after a ransomware attack on San Francisco Bay Area Rapid Transit Police department.
A recent campaign of cyber attacks made new and novel use of the Claude AI chatbot in scanning VPN endpoints and automating multiple portions of the attack cycle, representing another step forward in the deployment of LLMs for malicious purposes.
Hackers published one million stolen credit cards on the dark web to attract cybercriminals to their recently launched carding site. Up to 50% of the cards are active.
A cybersecurity startup Buguard said hackers used malware to steal passwords for Wiseasy's remote control dashboards to compromise payment terminals worldwide. Hackers could control payment terminals, install and remove apps, access personal information, and make configuration changes using the remote control dashboards.
Google Threat Intelligence Group has tracked threat actor UNC6395 stealing OAuth tokens via Salesloft Drift integrations in a massive Salesforce data theft campaign.
Microsoft discovered a coordinated phishing campaign targeting Office 365 users and leveraging an Adversary-in-the-Middle (AiTM) MFA bypass to execute business email compromise (BEC) attacks and commit fraud.
Since March 2019, hackers have been targeting the UN and affiliated humanitarian aid organizations with a sophisticated, mobile-centric phishing campaign to harvest Microsoft Office 365 login credentials.
Fear of Russian hackers infiltrating voting machines in the last U.S. presidential election has led to a new bill to enlist hackers to find vulnerabilities.
Google's new Cybersecurity Action Team warned that cybercriminals compromised unsecured or misconfigured Google Cloud instances to perform cryptocurrency mining.
Attackers exploit Google reCAPTCHA forms to sneak into users' inboxes because automated email security scanners cannot solve CAPTCHAs to determine the destination phishing URLs.










