Source
DARKReading
A group tracked as UNC6395 engaged in "widespread data theft" via compromised OAuth tokens from a third-party app called Salesloft Drift.
The financially motivated threat group used cloud resources to conduct a complex, ransomware-style attack against an enterprise victim.
Researchers raise the alarm that a new, rapidly evolving ransomware strain uses an OpenAI model to render and execute malicious code in real time, ushering in a new era of cyberattacks against enterprises.
Failure to comply with consumer data access and deletion requests highlights the urgent need for standardized verification processes and stronger enforcement mechanisms to protect consumer privacy.
African nations work with Interpol and private-sector partners to disrupt cybercriminal operations on the continent, but more work needs to be done.
Without key security defenses, including backup recovery and multifactor authentication implementation, all parties, including neighboring hospitals and patients, suffer.
Companies looking to benefit from agentic browsers pause: The services can tap into a user's online accounts and automate tasks but can expose organizational data and systems to myriad threats.
Though the company is informing its customers of the breach, Farmers isn't publicly divulging what kinds of personal data were affected.
While 34 countries worldwide already use some form of e-voting, the Philippines can serve as a model for what a secure online voting operation looks like.
The flaw is one of three that the company disclosed affecting its NetScaler ADC and NetScaler Gateway technologies.