A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News
Florida's Department of Health is reaching out to people affected by a June 26 cyberattack that exposed a wide range of sensitive personal data. We're talking names, Social Security numbers, banking details, medical history, medication and prescription information, military identification numbers, Nexus numbers, passwords, passport numbers — the works. The department has started mailing letters to those impacted with specifics on what was accessed.
To help, they've partnered with Kroll, an identity-monitoring firm, to provide free credit monitoring services. Law enforcement and cybersecurity experts are actively investigating. If you're a Florida Health Department client and haven't received a letter yet, it's worth keeping a close eye on your accounts.
Source: CBS News Miami
Florida's Department of Health is reaching out to people affected by a June 26 cyberattack that exposed a wide range of sensitive personal data. We're talking names, Social Security numbers, banking details, medical history, medication and prescription information, military identification numbers, Nexus numbers, passwords, passport numbers — the works. The department has started mailing letters to those impacted with specifics on what was accessed.
To help, they've partnered with Kroll, an identity-monitoring firm, to provide free credit monitoring services. Law enforcement and cybersecurity experts are actively investigating. If you're a Florida Health Department client and haven't received a letter yet, it's worth keeping a close eye on your accounts.
Source: CBS News Miami
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
North Korean hacking group Sapphire Sleet is the likely suspect behind a Rust ecosystem supply chain attack on August 20, which compromised arrayref — a package with over 245 million downloads found in roughly 75% of Rust environments. The attackers pushed a malicious version from the legitimate maintainer's account, then quickly poisoned two more related crates. Hidden inside was a build script designed to fetch a second-stage payload over TLS with certificate validation disabled.
The Rust Security Response Team yanked the malicious packages within 86 minutes. No evidence of actual exploitation was found. Wiz tied the attack to Sapphire Sleet based on infrastructure overlaps with earlier NPM attacks targeting Axios and Mastra.
Source: SecurityWeek
A critical flaw in N-able's Passportal password manager allowed any website — including ones with malicious ads — to silently steal a user's entire password vault. Researcher James Arnott of Bay Area Labs discovered on July 8 that Passportal's browser extension trusted messages from any source without verification, handing over access tokens to anyone who asked.
Those tokens unlock everything: stored credentials, one-time passwords, and with a 100-day refresh token, persistent access long after the initial breach. N-able patched the issue the next day, but the core problem remains — Passportal still decrypts passwords on its own servers rather than locally, leaving users exposed to future attacks.
With roughly 2,500 MSPs using the product, a single compromised account could cascade across dozens of client organizations.
Source: Dark Reading
A critical flaw in N-able's Passportal password manager allowed any website — including ones with malicious ads — to silently steal a user's entire password vault. Researcher James Arnott of Bay Area Labs discovered on July 8 that Passportal's browser extension trusted messages from any source without verification, handing over access tokens to anyone who asked.
Those tokens unlock everything: stored credentials, one-time passwords, and with a 100-day refresh token, persistent access long after the initial breach. N-able patched the issue the next day, but the core problem remains — Passportal still decrypts passwords on its own servers rather than locally, leaving users exposed to future attacks.
With roughly 2,500 MSPs using the product, a single compromised account could cascade across dozens of client organizations.
Source: Dark Reading
A cybercrime group called BlackFile is actively targeting major financial firms, law firms, and rating agencies — and it's not slowing down. Researchers at Google Threat Intelligence Group say the group hits an average of 1.5 new victims daily, with malicious infrastructure spotted targeting Blackstone, Bain Capital, Moody's, CME, and Apollo.
BlackFile runs four extortion brands — Redact, Pink, Helix, and Falcon — using voice-phishing and IT impersonation to gain access. Demands typically start around $3 million but get negotiated below $1 million. Some recent victims have received threatening messages and have even been swatted (a tactic where false emergency calls are used). Mandiant has responded to over two dozen confirmed breaches since January.
Source: CyberScoop
A cybercrime group called BlackFile is actively targeting major financial firms, law firms, and rating agencies — and it's not slowing down. Researchers at Google Threat Intelligence Group say the group hits an average of 1.5 new victims daily, with malicious infrastructure spotted targeting Blackstone, Bain Capital, Moody's, CME, and Apollo.
BlackFile runs four extortion brands — Redact, Pink, Helix, and Falcon — using voice-phishing and IT impersonation to gain access. Demands typically start around $3 million but get negotiated below $1 million. Some recent victims have received threatening messages and have even been swatted (a tactic where false emergency calls are used). Mandiant has responded to over two dozen confirmed breaches since January.
Source: CyberScoop
A Somerset NHS worker accessed up to 200 patient records without permission between August 2017 and October 2023, sharing screenshots of medical information with their partner. The breach at Musgrove Park Hospital included sensitive data — demographic details, A&E visits, and appointment records — and even led to a patient being contacted using a phone number taken from hospital files.
The worker resigned before facing disciplinary action and received only a police caution, with officers concluding the actions weren't malicious. Victims are furious. "She violated families, vulnerable people," one told the BBC. Privacy campaigners are now calling for automatic NHS App notifications whenever patient records are viewed.
Source: BBC News
A Somerset NHS worker accessed up to 200 patient records without permission between August 2017 and October 2023, sharing screenshots of medical information with their partner. The breach at Musgrove Park Hospital included sensitive data — demographic details, A&E visits, and appointment records — and even led to a patient being contacted using a phone number taken from hospital files.
The worker resigned before facing disciplinary action and received only a police caution, with officers concluding the actions weren't malicious. Victims are furious. "She violated families, vulnerable people," one told the BBC. Privacy campaigners are now calling for automatic NHS App notifications whenever patient records are viewed.
Source: BBC News
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
The Clop cybercrime group is at it again — this time exploiting a zero-day vulnerability in PTC's Windchill and FlexPLM software, tools widely used in manufacturing, aerospace, and automotive industries. The group began sending extortion emails to victims in mid-July, claiming it stole data from dozens of organizations, potentially including GE, Philips, and Shell.
PTC disclosed the flaw (CVE-2026-12569) on June 17, but companies were likely compromised weeks earlier. Clop deployed a custom web shell purpose-built for Windchill, enabling rapid credential theft and data exfiltration with minimal detection. Toast and Zebra confirmed intrusions but say impacts were limited. The fallout is still unfolding.
Source: CyberScoop
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
A Gambit Security report has revealed one of the most detailed real-world cases of AI being weaponized inside an active ransomware operation. A suspected affiliate of The Gentlemen ransomware-as-a-service group used Anthropic's Claude Code to breach VPN appliances, steal domain credentials, and exfiltrate SQL databases across at least eight organizations — including an Australian energy utility and a Mauritius financial firm.
The attacker used Claude Sonnet 4.6, an older, less-restricted model, interactively refining commands based on live output. Claude executed a sophisticated LDAP pass-back attack, created hidden backdoor VPN accounts, and ranked databases by business value before dumping them. At one point, Claude accidentally knocked a firewall offline, then logged: "Yeah, I screwed up."
This marks a clear shift — AI isn't just drafting phishing emails anymore. It's running live attacks.
Source: Cybersecurity News
A Gambit Security report has revealed one of the most detailed real-world cases of AI being weaponized inside an active ransomware operation. A suspected affiliate of The Gentlemen ransomware-as-a-service group used Anthropic's Claude Code to breach VPN appliances, steal domain credentials, and exfiltrate SQL databases across at least eight organizations — including an Australian energy utility and a Mauritius financial firm.
The attacker used Claude Sonnet 4.6, an older, less-restricted model, interactively refining commands based on live output. Claude executed a sophisticated LDAP pass-back attack, created hidden backdoor VPN accounts, and ranked databases by business value before dumping them. At one point, Claude accidentally knocked a firewall offline, then logged: "Yeah, I screwed up."
This marks a clear shift — AI isn't just drafting phishing emails anymore. It's running live attacks.
Source: Cybersecurity News
U.S. agencies including the NSA, CISA, FBI, and the Energy and Environmental Protection Agency issued a joint warning Wednesday about hackers using AI-generated scripts to attack critical infrastructure — water, food, energy, chemical, and manufacturing sectors.
The attackers are targeting Siemens S7 Series programmable logic controllers, using AI to rapidly develop exploitation tools that once required significant technical skill. The agencies called it an "active threat," not a theoretical one. Attacks could disrupt industrial processes, trigger safety incidents, or expose sensitive data.
Experts flagged this as the first known CISA advisory explicitly citing AI-generated scripts targeting operational technology systems.
Source: CyberScoop
U.S. agencies including the NSA, CISA, FBI, and the Energy and Environmental Protection Agency issued a joint warning Wednesday about hackers using AI-generated scripts to attack critical infrastructure — water, food, energy, chemical, and manufacturing sectors.
The attackers are targeting Siemens S7 Series programmable logic controllers, using AI to rapidly develop exploitation tools that once required significant technical skill. The agencies called it an "active threat," not a theoretical one. Attacks could disrupt industrial processes, trigger safety incidents, or expose sensitive data.
Experts flagged this as the first known CISA advisory explicitly citing AI-generated scripts targeting operational technology systems.
Source: CyberScoop