Starbucks has confirmed a data breach that leaked the personally identifiable information of its employees after a threat actor breached its business partner’s portal.
A massive data breach has affected business process outsourcing giant TELUS Digital, leaking nearly a petabyte of data, with the hacking group ShinyHunters taking credit.
DarkSword packs both a complete iOS exploit chain and infostealer into one package. The chain initiates when Safari opens a malicious webpage with a hidden iframe that springs the malware from the WebContent sandbox. It then works its way into deploying a number of custom payloads designed to tap into various vital and privileged iOS services.
A security flaw at the U.K.’s business registry, Companies House, exposed the personal information of business executives and allowed unauthorized alteration.
The sensitive personal and financial information of 672,075 people was compromised during the August 2025 Marquis cyberattack, which was previously misattributed to a Russian ransomware gang.
A new vulnerability chain discovered by Oasis Security can compromise the Claude AI chatbot and does not require the target to have the app installed or even have an account with the service. The attack chain instead begins with a malicious webpage doctored up to place highly in search results for Claude, which passes the user to a pre-filled chat URL that exploits other vulnerabilities in the AI agent.
A data breach at the Washington-based benefits administrator Navia Benefit Solutions has exposed the sensitive personal information of nearly 2.7 million individuals.
New US National Security Directive: Foreign Internet Routers Require Special FCC Approval to be Sold
Consumer-grade internet routers have been added as a category to the FCC's Covered List, which establishes communications equipment and services deemed to be an unacceptable national security risk. Some individual manufacturers, such as Huawei and ZTE, have already been added to this list in years past.
Armed forces would prefer to keep the exact locations of their assets secret as they come within striking range of hostile forces. Just one soldier using a fitness app or tracking device can out this location if their fitness results are automatically posted to a public profile.
Fraudsters used Nordstrom’s official email system to promote a crypto scam promising to double funds sent to the scammers’ wallet addresses as a St. Patrick’s Day giveaway.










