Researchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.
Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion
Analog Devices, Inc., a leading U.S. semiconductor manufacturer specializing in analog, mixed-signal, and digital signal processing technology, has…
Amazon Attributes Earlier npm Supply Chain Attacks to North Korea’s Sapphire Sleet
Amazon has linked a series of high-profile npm supply chain compromises spanning 2025 and 2026 to the North Korean threat group Sapphire Sleet, suggesting…
Hackers Are Exploiting Nearly One in Four Vulnerabilities Before Defenders Get a CVE
Attackers are exploiting a significant portion of vulnerabilities even before defenders receive a published CVE (Common Vulnerabilities and Exposures). In…
Tribeca Film Festival Data Breach Exposes 666K Records
Security researcher Jeremiah Fowler discovered four publicly accessible databases containing nearly 666,000 records linked to the Tribeca Film Festival,…
New CosmosEscape Vulnerability Lets Attackers Take Over Azure Cosmos DB Instances
A critical vulnerability, dubbed CosmosEscape, in Microsoft Azure Cosmos DB could have let attackers seize control of virtually every database hosted on…
Microsoft Warns of Rising ACR Stealer Campaigns Targeting Enterprise Credentials
Microsoft has observed an uptick in attacks using the ACR Stealer information-stealing malware family. Attackers distributed the malicious payload…
Vatican’s Click To Pray app exposed personal data from 700,000 users
Anyone could access other Click To Pray users’ personal information. The flaw went unfixed for more than six months after it was reported.
Experts react as Department for Education cyber attack exposes 607,000 records
The Department for Education (DfE) has confirmed that a cyber attack on two of its external-facing systems resulted in the theft of around 607,000…
API Security for Government Services: Protecting Citizen-Facing Applications
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: API Security for Government Services: Protecting Citizen-Facing Applications
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access…
TA488 Exploits Outlook Web Access Flaw with Half-Click Attack
TA488 is exploiting a Microsoft Outlook Web Access vulnerability to compromise users through half-click attacks.
Axon Is Another License Plate Surveillance Company
Governments are switching, but I’m not sure it makes a difference : …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But…
In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
Cybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but…
One-click Claude Desktop flaw could enable hidden prompt injection and code execution
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local…
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in…
Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations…
OpenAI’s Hacking Debacle Comes Down to Human Error
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet…
Cyber Briefing: 2026.07.30
Attackers are combining sophisticated zero-interaction web exploits and deceptive social engineering to breach critical systems, driving the industry…
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Hims & Hers sued over alleged health data privacy failures
The FTC has sued telehealth provider Hims & Hers, alleging it shared customers’ sensitive health information with advertisers.
The 5 Best VPN Extensions for Chrome
Looking for the best Chrome VPN extensions in 2026 to enhance your online security and privacy? Dive into our list of top-rated VPNs and find your best…
Discern Security Raises $13 Million in Series A Funding
The company will invest in accelerating the development and adoption of its agentic platform.
Hugging Face Deepfake Tests Raise New Risks for AI Procurement
Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight,…