Skip to main content

Cybersecurity

General cybersecurity news and analysis

AI-powered ransomware: Stunning New Risk Exposed

AI-powered ransomware: Stunning New Risk Exposed

ESET just uncovered PromptLock — the first AI-powered ransomware that runs OpenAI’s gpt-oss:20b locally via Ollama to generate bespoke Lua payloads on the fly. It’s a wake-up call: dynamically generated malware can evade signature-based defenses, so teams must lock down local model hosting, boost runtime monitoring, and update incident playbooks.

Analyst 207
compromised Microsoft Teams account: Stunning Risk Alert

compromised Microsoft Teams account: Stunning Risk Alert

Think your cloud and Teams are safe? Storm‑0501 slipped from on‑prem into Azure, stole sensitive files, and even used a compromised Teams account to extort the victim — a wake‑up call to lock down identities, tighten segmentation, and treat collaboration tools as prime targets.

Analyst 207
software procurement Must-Have Guide: Essential Security

software procurement Must-Have Guide: Essential Security

CISA’s new Software Acquisition Guide Web Tool puts buyers back in control of supply‑chain risk with practical checklists, vendor assessment criteria and contract language to make secure software purchasing repeatable and auditable. If adopted thoughtfully, it can turn procurement from a blind spot into a frontline defense—though success will hinge on implementation, resources and market incentives.

Analyst 207
cybersecurity incident: Stunning Risky Nevada Outage

cybersecurity incident: Stunning Risky Nevada Outage

Nevada is racing to restore state services after a network security incident left offices closed and phone lines and websites offline, disrupting everything from licensing to benefits. Officials say recovery is underway as residents wait for clearer timelines and reassurance about service access and data safety.

Analyst 207
OAuth tokens Risky: Stunning CRM Data Breach Alert

OAuth tokens Risky: Stunning CRM Data Breach Alert

Google says attackers stole OAuth tokens from Salesloft’s Drift app to siphon Salesforce CRM records, leaving customers scrambling as missing or altered data disrupts sales operations. It’s a sharp reminder that convenient third‑party integrations can become powerful attack vectors unless tokens, permissions and vendor vetting are tightly managed.

Analyst 207
NetScaler appliances Must-Have Urgent Patch Alert

NetScaler appliances Must-Have Urgent Patch Alert

Citrix just released fixes for three critical NetScaler zero-days—one already exploited—so update and verify your appliances immediately. Then shore up defenses with segmentation, MFA and monitoring to reduce exposure while you patch.

Analyst 207
multifactor authentication Risky Crisis, Must-Have Fix

multifactor authentication Risky Crisis, Must-Have Fix

Login attacks are skyrocketing, and the identity systems we trust—from MFA to identity providers—are under siege, eroding confidence and leaving security teams scrambling. Rebuilding trust will take pragmatic steps like phased passkey rollouts, phishing‑resistant methods, and smarter help‑desk controls that balance security with usability.

Analyst 207
OAuth tokens: Stunning Risky Drift AI Data Breach

OAuth tokens: Stunning Risky Drift AI Data Breach

A recent campaign abused compromised OAuth and refresh tokens tied to the Drift AI chat agent to siphon data from Salesloft—potentially creating a corridor into downstream Salesforce records. If you used Salesloft–Drift integrations, assume exposure: revoke tokens, rotate credentials, enable MFA, and audit access immediately.

Analyst 207
EU Cybersecurity Reserve Must-Have: Best Defense

EU Cybersecurity Reserve Must-Have: Best Defense

ENISA’s new €36M EU Cybersecurity Reserve turns a long‑talked idea into a real, deployable digital fire brigade — pooling expert teams, forensic tools and logistics to help member states and critical infrastructure bounce back faster from cross‑border cyberattacks. If Europe pairs this funding with clear rules, joint exercises and legal certainty, the Reserve could become a reliable, lifesaving safety net rather than just another well‑intentioned plan.

Analyst 207
credential-theft campaign: Exclusive Salesforce Risk

credential-theft campaign: Exclusive Salesforce Risk

Google warns of a credential-theft campaign that abused a Salesloft integration to phish Salesforce logins — a wake-up call that third-party apps can be your weakest link. Audit connected apps, enforce MFA, and tighten permissions now before attackers pivot from integrations into your CRM.

Analyst 207
ConnectWise ScreenConnect: Stunning Security Risk

ConnectWise ScreenConnect: Stunning Security Risk

Attackers are now tricking victims into installing legitimate remote-support tools like ConnectWise ScreenConnect, then using those same trusted apps to seize control of devices — a stealthy shift that makes phishing far harder to spot. Stay skeptical of unsolicited support requests and verify them out of band, because convenience is the new vulnerability.

Analyst 207
BGP Security Fixes Still a Work in Progress

BGP Security Fixes Still a Work in Progress

BGP security has come a long way with tools like RPKI and better operational practices, but uneven adoption, cost, and complexity still leave routing open to accidental and malicious hijacks. Fixing it won’t be a one-time upgrade—our networks need coordinated technical, policy, and cultural changes to make routing truly resilient.

Analyst 207
web hijacking: Stunning Diplomatic Threat

web hijacking: Stunning Diplomatic Threat

Imagine being a diplomat and not knowing your web traffic is being silently rerouted—Google has warned of a suspected state-backed web hijacking campaign hitting foreign ministries and diplomats across Asia. This stealthy interception can steal credentials, deploy malware, and influence negotiations, so stronger encryption, hardened captive‑portal workflows, and robust MFA are now mission‑critical.

Analyst 207
custom silicon Must-Have for Best Cloud Security

custom silicon Must-Have for Best Cloud Security

Microsoft’s Azure team is betting big on custom silicon and open-source Roots of Trust to give customers stronger, auditable hardware-backed assurances that their code and data run in tamper-resistant environments. It’s a bold move toward transparency and tougher defenses — but success will hinge on rigorous review, trustworthy manufacturing, and clear safeguards against new concentration risks.

Analyst 207
Social Security numbers: Stunning Risky Cloud Leak

Social Security numbers: Stunning Risky Cloud Leak

A whistleblower alleges a Social Security Administration unit copied an SSA database containing Social Security numbers into an unauthorized, unsecured cloud—potentially exposing tens of millions of Americans to identity theft. This raises urgent questions about whether cost‑cutting pushed security and oversight to the breaking point.

Analyst 207
phishing attack Stunning Risky ZipLine Exposed

phishing attack Stunning Risky ZipLine Exposed

A new ZipLine phishing campaign uses a legitimate-looking White House photo and fake contact forms to trick employees at U.S. manufacturers into handing over credentials — opening the door to IP theft and ransomware. It’s a sharp reminder that a single authentic image can bypass defenses, so tighten verification, MFA, and training now.

Analyst 207
CVE-2025-7775 Urgent: Critical NetScaler RCE Risk

CVE-2025-7775 Urgent: Critical NetScaler RCE Risk

Citrix has released fixes for three NetScaler vulnerabilities — including actively exploited CVE-2025-7775 — so if you run NetScaler ADC/Gateway, patch immediately and hunt for signs of compromise. These gateway flaws can allow remote code execution or disruption, so quick action will sharply reduce your risk.

Analyst 207
Sni5Gect: Stunning Dangerous 5G Downgrade Risk

Sni5Gect: Stunning Dangerous 5G Downgrade Risk

Researchers revealed Sni5Gect, an open-source toolkit that can silently force 5G phones onto older, less secure networks — and in some cases crash them — exposing users to interception, tracking and service loss. While the release aims to spur fixes, it also risks putting a powerful downgrade tool into the wrong hands unless vendors and regulators act fast.

Analyst 207
NetScaler vulnerabilities: Critical Must-Fix Patches

NetScaler vulnerabilities: Critical Must-Fix Patches

Citrix has released urgent patches for three actively exploited NetScaler flaws, but fixing them often means juggling downtime, complex dependencies, and the worry that attackers may already be inside — update your appliances now, monitor logs, and apply recommended mitigations if you can’t patch immediately.

Analyst 207
hardware security Must-Have Standards for Best Defense

hardware security Must-Have Standards for Best Defense

As global tensions and supply‑chain shocks put chips at the center of national security, SUSHI@NIST is bringing engineers, industry and policy makers together to create measurable standards that make next‑gen hardware verifiably secure. If successful, those standards could turn trust into a testable feature of every device — lowering risk for buyers and raising the bar for attackers.

Analyst 207
phishing campaign: Critical RAT Threat Exposed

phishing campaign: Critical RAT Threat Exposed

Researchers warn of a global phishing campaign that uses highly personalized emails and convincing fake sites to slip UpCrypter-wrapped downloads that install remote access trojans, giving attackers persistent control of machines. Stay cautious—verify unexpected requests, avoid untrusted downloads, enable MFA, and keep endpoint defenses tuned to block obfuscated threats.

Analyst 207
cyber incident: Maryland’s Stunning, Risky Wake-Up

cyber incident: Maryland’s Stunning, Risky Wake-Up

Maryland has confirmed a cyber incident affecting parts of its transportation system, but officials say all scheduled trips this week will be honored while investigators work to determine the scope. Commuters should stay alert for updates as authorities probe the issue and protect essential services.

Analyst 207
cybersecurity legislation: Must-Have Rules, Risky Tradeoffs

cybersecurity legislation: Must-Have Rules, Risky Tradeoffs

A new CIISec poll shows most security professionals want tougher, clearer cybersecurity laws—urging policymakers to create practical, enforceable rules that boost defenses without stifling innovation. If lawmakers listen and invest in enforcement and workforce skills, stronger regulation could deliver real protection for businesses and citizens.

Analyst 207
fake support sites: Stunningly Dangerous macOS Threat

fake support sites: Stunningly Dangerous macOS Threat

Think twice before downloading “help” tools from ads—attackers are using convincing fake macOS support sites and malvertising to deliver the Atomic macOS Stealer (AMOS) and quietly scoop up credentials, cookies and crypto wallets. Verify support pages with vendors directly and treat unsolicited downloads like risky strangers offering to fix your device.

Analyst 207