Operation HookedWing Phishing Campaign
Over 500 organizations across multiple industries have been targeted in a years-long phishing campaign, resulting in the theft of more than 2,000 user credentials.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Over 500 organizations across multiple industries have been targeted in a years-long phishing campaign, resulting in the theft of more than 2,000 user credentials.
RansomHouse ransomware group has taken credit for the recent attack on cybersecurity firm Trellix, claiming to have accessed internal services and management dashboards.
RansomHouse hackers have claimed responsibility for a breach of Trellix's source code repository, leaking screenshots as proof of the intrusion.
The PCPJack worm is stealing credentials from exposed cloud infrastructure and removing TeamPCP infections, with researchers believing it may be the work of a former TeamPCP affiliate.
Attackers are exploiting a zero-day vulnerability in Ivanti Endpoint Manager Mobile, with limited exploitation reported in the wild, requiring authenticated administrative access to implement.
Rep. Summer Lee is pressing the Commerce Department for a briefing on the government's use of commercial spyware, including NSO Group's technology.
Pro-Ukraine hacktivist groups BO Team and Head Mare appear to be coordinating cyber operations against Russian organizations, according to a Kaspersky report.
Modern DLP controls often lack visibility into browser-based data movement, with 46% of sensitive file uploads sent to unsanctioned accounts.
The Trump administration is redirecting the CyberCorps Scholarship For Service program toward artificial intelligence, leaving current scholars uncertain about their future employability