Cybersecurity News and Updates
Cyber Command turns to veteran of intelligence agencies for top AI role
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
“UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.
“
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Researcher Claims Control of ChatGPT Secure Sandbox
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
“The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
Microsoft, Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.
The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.
Recent Comments