Skip to main content

Cybersecurity

General cybersecurity news and analysis

Azure AD credentials: Devastating Exposure, Critical Fix

Azure AD credentials: Devastating Exposure, Critical Fix

A stray appsettings.json can hand attackers your Azure AD ClientId and ClientSecret and let them impersonate apps to access sensitive tenant data in minutes. Use managed identities, vaults, credential rotation and CI/CD secret scanning to make convenience harmless, not catastrophic.

Analyst 207
OAuth tokens: Must-Have Fixes to Stop Risky Leaks

OAuth tokens: Must-Have Fixes to Stop Risky Leaks

Palo Alto Networks says some commercially sensitive customer data may have been exposed after attackers used OAuth tokens stolen from the Salesloft Drift breach to access its Salesforce—proof that handy integrations can let a single vendor compromise cascade across your business. Now’s the time to audit connected apps, tighten token lifecycles, and treat integrations as continuously verified trust relationships, not set‑and‑forget conveniences.

Analyst 207
cyber incident: Stunning Risky Blow to Jaguar Sales

cyber incident: Stunning Risky Blow to Jaguar Sales

A recent cyber incident forced Jaguar to take IT systems offline, halting production and leaving workers home and customers wondering about deliveries. It’s a clear reminder that modern, connected factories can be brought to their knees by digital attacks — with real costs to sales, jobs and reputation.

Analyst 207
NSA training workbook: Exclusive Essential Read

NSA training workbook: Exclusive Essential Read

A newly declassified 1965 NSA workbook—featuring 147 “Stethoscope” printouts—shows how Cold War cryptanalysts learned to read the anatomy of ciphertext by spotting patterns rather than seeing plaintext. It’s a fascinating reminder that human pattern recognition paired with machine diagnostics shaped past tradecraft and still matters for today’s debates about encryption, AI, and security.

Analyst 207
SSL VPN Urgent: Must-Have Best Defenses

SSL VPN Urgent: Must-Have Best Defenses

Imagine someone pounding on invisible locks: a massive brute‑force campaign recently blasted SSL VPNs and RDP hosts with relentless login attempts, showing how one weak credential can lead to ransomware or data theft. If you run remote access services, enable MFA, rate‑limit logins, and segment networks now to stop attackers before they get in.

Analyst 207
public disclosure: Exclusive Best Guide to Safer AI

public disclosure: Exclusive Best Guide to Safer AI

The UK’s NCSC is pushing to adapt trusted vulnerability-disclosure programs to AI so researchers have a clear, safe route to report model-bypass tricks and give developers time to fix harms before details leak. If adopted, this pragmatic step could speed fixes, boost accountability, and make powerful models harder to weaponize while policy and tech catch up.

Analyst 207
Copeland refrigeration controllers: Stunning Risky Flaws

Copeland refrigeration controllers: Stunning Risky Flaws

Imagine a stranger on the internet able to warm your supermarket freezers — Frostbyte10 exposes thousands of Copeland refrigeration controllers to attacks that could spoil food, ruin vaccines and cripple supply chains. Patches and mitigations exist, but grocers and cold‑chain operators need to act fast to isolate, update and secure vulnerable units before losses mount.

Analyst 207
signed Windows kernel driver: Stunning Risky Backdoor

signed Windows kernel driver: Stunning Risky Backdoor

When a Microsoft‑signed WatchDog driver (amsdk.sys) was abused to neuter endpoint defenses and plant ValleyRAT, it proved that a valid signature isn’t a guarantee of safety. This Silver Fox campaign underscores why organizations must stop trusting signatures alone and add behavior‑based controls and tighter vetting for privileged drivers.

Analyst 207
GPS jamming: Stunningly Dangerous Threat to Europe

GPS jamming: Stunningly Dangerous Threat to Europe

When GPS signals were deliberately jammed over southeastern Europe, even the plane carrying EU Commission President von der Leyen had to fly without satellite guidance — a stark reminder that our reliance on GNSS leaves aviation, infrastructure and economies vulnerable to cheap, deniable interference. Europe’s push to harden Galileo, boost anti‑jamming tools and speed up detection shows this isn’t hypothetical: GPS jamming is a present, systemic threat that needs urgent action.

Analyst 207
exposed Ollama servers: Risky Must-Have Security Fix

exposed Ollama servers: Risky Must-Have Security Fix

Cisco Talos found 1,100+ publicly exposed Ollama servers, creating easy paths for data theft, malicious model swaps, and other abuse. It’s a wake-up call to fix misconfigurations, enforce authentication, and make secure defaults the norm.

Analyst 207
authentication tokens Risky Fallout: Stunning Wake-Up

authentication tokens Risky Fallout: Stunning Wake-Up

When Salesloft’s stolen authentication tokens turned into a supply‑chain free‑for‑all, hundreds of companies woke up to the scary truth that machine identities are as precious as passwords. Now’s the time to rotate keys, audit integrations, and rethink how we trust the apps that sit between our teams and their data.

Analyst 207
signed driver Dangerous: Stunning ValleyRAT Risk

signed driver Dangerous: Stunning ValleyRAT Risk

Imagine a trusted vendor’s driver used as a battering ram—Silver Fox has been abusing Microsoft‑signed kernel drivers to slip past endpoint defenses and install the ValleyRAT backdoor for stealthy, long‑term access and data theft. Tighten driver policies, add kernel‑level telemetry, and vet supply chains before digital trust becomes the next attack surface.

Analyst 207
Paid Memberships Subscription plugin Urgent Exclusive Risk

Paid Memberships Subscription plugin Urgent Exclusive Risk

A critical unauthenticated SQL injection was found in the Paid Memberships Subscription plugin, putting thousands of WordPress membership sites at risk. If you use the plugin, check your version and apply the patch or disable it now to protect user data and memberships.

Analyst 207
WhatsApp zero-day: Critical Risk, Must-Have Fixes

WhatsApp zero-day: Critical Risk, Must-Have Fixes

This week’s wake‑up call — a WhatsApp zero‑day, a Docker escape bug, and reported Salesforce access — shows how small misconfigurations and stolen credentials chain together into big breaches. Patch promptly, enable MFA, and tighten container and identity hygiene before attackers stitch those gaps into a compromise.

Analyst 207
Ransomware incidents: Must-Have Resilience or Costly Chaos

Ransomware incidents: Must-Have Resilience or Costly Chaos

Pennsylvania’s Attorney General says “we refused to pay,” choosing to withstand a ransomware attack that has delayed court filings and strained case processing across the state. The decision highlights the painful trade-off between short-term recovery and long-term deterrence—and underscores why public agencies must invest in stronger backups, better defenses, and robust continuity plans.

Analyst 207
Scattered Spider: Must-Have Defense for Risky Browser Attacks

Scattered Spider: Must-Have Defense for Risky Browser Attacks

The browser is now the workplace front door—and groups like Scattered Spider are exploiting it with social engineering and account-takeover tricks. Enterprises can keep cloud-first convenience without handing over the keys by layering phishing‑resistant MFA, locking down extensions and OAuth grants, and monitoring browser telemetry.

Analyst 207
DDoS attacks: Must-Have Defenses for Best Protection

DDoS attacks: Must-Have Defenses for Best Protection

When a small-town hospital’s patient portal or a county election website goes dark from a DDoS attack, the fallout can be disastrous — yet these digital sieges are often overlooked despite becoming cheaper, more frequent, and more damaging. It’s time to stop treating DDoS as a nuisance and start taking it seriously to protect healthcare, elections, and everyday businesses.

Analyst 207
watering-hole technique: Exclusive Risky Exposed

watering-hole technique: Exclusive Risky Exposed

When nation‑state actors like APT29 weaponize familiar conveniences — such as “Sign in with Microsoft” flows and popular websites — a routine visit can hand over credentials and session tokens at scale. Amazon’s disclosure shows watering‑hole attacks have evolved, so teams and users should treat federated logins and consent prompts with fresh skepticism and stronger protections.

Analyst 207
legal-looking text: Stunning Risky Jailbreaks

legal-looking text: Stunning Risky Jailbreaks

Pangea’s LegalPwn reveals how hiding adversarial instructions inside legal‑sounding text can trick LLMs into ignoring safety rules — a clever jailbreak that exploits models’ trust in formal language. Defenders must stop treating “legal” formatting as a seal of safety and build context‑aware checks before this becomes a bigger problem.

Analyst 207
Salesloft Drift integration: Risky Must-Have Fixes

Salesloft Drift integration: Risky Must-Have Fixes

A widely used Salesloft–Drift integration meant to speed workflows is being abused to pivot into Google Workspace accounts—now’s the time to audit OAuth permissions, enforce least privilege, and revoke any unnecessary app access before attackers do.

Analyst 207
zero-click exploit: Stunning Dangerous WhatsApp Flaw

zero-click exploit: Stunning Dangerous WhatsApp Flaw

WhatsApp has just patched a rare zero-day, zero-click flaw that let attackers run code and spy on devices without any user action. If you use WhatsApp, update now — silent exploits like this show why keeping apps and phones patched is essential.

Analyst 207
Operation HanKook Phantom: Exclusive Dangerous Threat

Operation HanKook Phantom: Exclusive Dangerous Threat

When colleagues become targets, South Korea’s academic community is facing a stealthy campaign — Operation HanKook Phantom — where ScarCruft (APT37) uses tailored phishing and the RokRAT trojan to siphon research and influence policy debates. Universities must boost basics like MFA, endpoint protection and phishing training to protect open inquiry without closing it off.

Analyst 207
government domains: Shocking Security Risks

government domains: Shocking Security Risks

New ISOC research shows traffic to government websites often crosses borders, rides a handful of links, and sometimes travels unencrypted — putting privacy, sovereignty, and service reliability at risk. Governments should enforce HTTPS, diversify routing, and be more transparent so citizens’ data and access aren’t left vulnerable to interception or outages.

Analyst 207
vulnerability in WhatsApp: Must-Have Fix for Risky Flaw

vulnerability in WhatsApp: Must-Have Fix for Risky Flaw

Meta warns a WhatsApp flaw may have been used in a sophisticated, targeted attack — a stark reminder that end-to-end encryption protects content but not every implementation error. Update your app, tighten device hygiene, and treat secure messaging as an ongoing practice, not a guarantee.

Analyst 207