Cyberattacks (4)
Tenable confirmed hackers accessed customer contact details and support case information through a sophisticated supply chain attack exploiting Salesforce-Salesloft Drift integrations. The breach exposed business emails, phone numbers, and support ticket descriptions but didn't compromise Tenable's core products.
This wasn't an isolated incident—the same campaign hit major tech companies including Palo Alto Networks, Zscaler, Google, Cloudflare, and PagerDuty. Attackers specifically targeted vulnerabilities in the integration between Salesforce and the popular sales platform Salesloft Drift.
Tenable responded by revoking compromised credentials, disabling the Drift application, and hardening their Salesforce environment. The company found no evidence the stolen data has been misused yet.
Source: Cybersecurity News
Tenable confirmed hackers accessed customer contact details and support case information through a sophisticated supply chain attack exploiting Salesforce-Salesloft Drift integrations. The breach exposed business emails, phone numbers, and support ticket descriptions but didn't compromise Tenable's core products.
This wasn't an isolated incident—the same campaign hit major tech companies including Palo Alto Networks, Zscaler, Google, Cloudflare, and PagerDuty. Attackers specifically targeted vulnerabilities in the integration between Salesforce and the popular sales platform Salesloft Drift.
Tenable responded by revoking compromised credentials, disabling the Drift application, and hardening their Salesforce environment. The company found no evidence the stolen data has been misused yet.
Source: Cybersecurity News
CISA issued an urgent alert Thursday about a high-severity Android zero-day vulnerability (CVE-2025-48543) being actively exploited by attackers. The use-after-free bug in Android Runtime allows hackers to escape Chrome's security sandbox and gain elevated device permissions, potentially installing malware or accessing sensitive data.
The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on September 4, 2025, confirming real-world attacks are underway. Federal agencies must patch by September 25 or stop using affected products.
Google addressed the flaw in its September 1 security bulletin. All Android users should immediately check Settings > System > System update and install available patches to protect against this serious threat.
Source: Cybersecurity News
CISA issued an urgent alert Thursday about a high-severity Android zero-day vulnerability (CVE-2025-48543) being actively exploited by attackers. The use-after-free bug in Android Runtime allows hackers to escape Chrome's security sandbox and gain elevated device permissions, potentially installing malware or accessing sensitive data.
The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on September 4, 2025, confirming real-world attacks are underway. Federal agencies must patch by September 25 or stop using affected products.
Google addressed the flaw in its September 1 security bulletin. All Android users should immediately check Settings > System > System update and install available patches to protect against this serious threat.
Source: Cybersecurity News
Jaguar Land Rover has told factory workers to stay home until at least September 9 following a devastating cyber attack that hit the company Sunday. Production has stopped at major facilities in Halewood, Solihull, and Wolverhampton, affecting the UK's biggest car manufacturer during peak sales season.
The hack has severely disrupted global operations, forcing JLR to shut down systems as a precaution. While no customer data appears stolen, thousands of customers can't get new vehicles and repairs are stalled since dealerships can't order parts online.
English-speaking hackers linked to recent UK retail attacks claimed responsibility Wednesday. The same group previously cost Marks & Spencer £300m during a six-week shutdown.
Source: The Guardian
Jaguar Land Rover has told factory workers to stay home until at least September 9 following a devastating cyber attack that hit the company Sunday. Production has stopped at major facilities in Halewood, Solihull, and Wolverhampton, affecting the UK's biggest car manufacturer during peak sales season.
The hack has severely disrupted global operations, forcing JLR to shut down systems as a precaution. While no customer data appears stolen, thousands of customers can't get new vehicles and repairs are stalled since dealerships can't order parts online.
English-speaking hackers linked to recent UK retail attacks claimed responsibility Wednesday. The same group previously cost Marks & Spencer £300m during a six-week shutdown.
Source: The Guardian
Tire giant Bridgestone confirmed a cyberattack disrupted operations at North American manufacturing facilities in South Carolina and Quebec this week. The company says it quickly contained the breach and prevented customer data theft, with operations now back to normal.
Bridgestone hasn't revealed attack details or whether ransomware was involved. No group has claimed responsibility yet, though the LockBit gang previously hit Bridgestone in March 2022. Security experts note manufacturers face rising ransomware threats—attacks jumped 57% from July to August.
The incident highlights supply chain vulnerabilities, as even contained attacks can halt production lines and create product shortages.
Source: Industrial Cyber
Tire giant Bridgestone confirmed a cyberattack disrupted operations at North American manufacturing facilities in South Carolina and Quebec this week. The company says it quickly contained the breach and prevented customer data theft, with operations now back to normal.
Bridgestone hasn't revealed attack details or whether ransomware was involved. No group has claimed responsibility yet, though the LockBit gang previously hit Bridgestone in March 2022. Security experts note manufacturers face rising ransomware threats—attacks jumped 57% from July to August.
The incident highlights supply chain vulnerabilities, as even contained attacks can halt production lines and create product shortages.
Source: Industrial Cyber
Palo Alto Networks researchers discovered a dangerous new attack called 'Model Namespace Reuse' that exploits AI supply chains. Attackers register names of deleted or transferred AI models on platforms like Hugging Face, then upload malicious versions that developers unknowingly download.
The team successfully demonstrated attacks against Google's Vertex AI and Microsoft's Azure AI Foundry, gaining access to underlying infrastructure by deploying weaponized models. They also found thousands of vulnerable open source repositories.
Google now performs daily scans for orphaned models, but the core problem remains widespread. Security experts recommend pinning models to specific versions and storing them in trusted locations rather than fetching by name alone.
Source: Security Week
Palo Alto Networks researchers discovered a dangerous new attack called 'Model Namespace Reuse' that exploits AI supply chains. Attackers register names of deleted or transferred AI models on platforms like Hugging Face, then upload malicious versions that developers unknowingly download.
The team successfully demonstrated attacks against Google's Vertex AI and Microsoft's Azure AI Foundry, gaining access to underlying infrastructure by deploying weaponized models. They also found thousands of vulnerable open source repositories.
Google now performs daily scans for orphaned models, but the core problem remains widespread. Security experts recommend pinning models to specific versions and storing them in trusted locations rather than fetching by name alone.
Source: Security Week
Jaguar Land Rover has shut down its global manufacturing and retail operations following a severe cyber incident that forced workers at its Halewood plant to stay home Monday morning. Britain's largest carmaker proactively closed all systems to prevent further damage, though it says no customer data appears stolen.
The timing couldn't be worse for JLR, which is already struggling with a 49% profit drop and delayed electric vehicle launches. The attack comes during one of the busiest weeks for car dealers, preventing them from registering new 75-plate vehicles. Cybersecurity experts say the speed of the shutdown suggests attackers may have targeted operational systems rather than just data.
Source: The Guardian
Jaguar Land Rover has shut down its global manufacturing and retail operations following a severe cyber incident that forced workers at its Halewood plant to stay home Monday morning. Britain's largest carmaker proactively closed all systems to prevent further damage, though it says no customer data appears stolen.
The timing couldn't be worse for JLR, which is already struggling with a 49% profit drop and delayed electric vehicle launches. The attack comes during one of the busiest weeks for car dealers, preventing them from registering new 75-plate vehicles. Cybersecurity experts say the speed of the shutdown suggests attackers may have targeted operational systems rather than just data.
Source: The Guardian
A massive supply chain attack through Salesloft Drift has compromised major tech companies including Cloudflare, Palo Alto Networks, Zscaler, and PagerDuty. Google's threat intelligence team says the 10-day campaign in August potentially hit over 700 organizations.
The attack group UNC6395 exploited integrations between Drift's AI chat platform and Salesforce to steal customer data. Exposed information includes business contact details, support case notes, and in some cases sensitive credentials and API tokens.
Salesloft is taking Drift offline completely to investigate and rebuild security. The timing is particularly awkward - the attack started just one day after Salesloft announced a merger with competitor Clari, creating a combined company serving 5,000+ organizations globally.
Source: CyberScoop
A massive supply chain attack through Salesloft Drift has compromised major tech companies including Cloudflare, Palo Alto Networks, Zscaler, and PagerDuty. Google's threat intelligence team says the 10-day campaign in August potentially hit over 700 organizations.
The attack group UNC6395 exploited integrations between Drift's AI chat platform and Salesforce to steal customer data. Exposed information includes business contact details, support case notes, and in some cases sensitive credentials and API tokens.
Salesloft is taking Drift offline completely to investigate and rebuild security. The timing is particularly awkward - the attack started just one day after Salesloft announced a merger with competitor Clari, creating a combined company serving 5,000+ organizations globally.
Source: CyberScoop
A sophisticated Lazarus subgroup is targeting financial and crypto organizations with a three-stage malware attack that may exploit a Chrome zero-day vulnerability. The hackers pose as legitimate trading firm employees on Telegram, luring victims to fake meeting sites like counterfeit Calendly portals.
Once compromised, attackers deploy PondRAT as an initial loader, followed by the memory-resident ThemeForestRAT for stealth operations. After months of reconnaissance, they install RemotePE RAT for long-term access. The malware enables file manipulation, credential theft, and secure data exfiltration.
DeFi organizations have reported significant disruptions from these hidden backdoors. The attack chain uses advanced techniques including phantom DLL hijacking and rolling XOR encryption to evade detection, catching many security teams off guard despite known Lazarus activity.
Source: Cybersecurity News
A sophisticated Lazarus subgroup is targeting financial and crypto organizations with a three-stage malware attack that may exploit a Chrome zero-day vulnerability. The hackers pose as legitimate trading firm employees on Telegram, luring victims to fake meeting sites like counterfeit Calendly portals.
Once compromised, attackers deploy PondRAT as an initial loader, followed by the memory-resident ThemeForestRAT for stealth operations. After months of reconnaissance, they install RemotePE RAT for long-term access. The malware enables file manipulation, credential theft, and secure data exfiltration.
DeFi organizations have reported significant disruptions from these hidden backdoors. The attack chain uses advanced techniques including phantom DLL hijacking and rolling XOR encryption to evade detection, catching many security teams off guard despite known Lazarus activity.
Source: Cybersecurity News
AI company Anthropic revealed that hackers have weaponized its Claude chatbot to carry out sophisticated cyberattacks and fraud schemes. The company detected cases where criminals used Claude to write malicious code targeting at least 17 organizations, including government bodies. The AI helped hackers make strategic decisions about data theft and even suggested ransom amounts for victims.
In a separate scheme, North Korean operatives used Claude to create fake profiles and secure remote jobs at Fortune 500 tech companies, potentially violating international sanctions. Anthropic has disrupted these threats and reported them to authorities while improving its detection systems. Experts warn that AI is rapidly shrinking the time needed to exploit cybersecurity vulnerabilities.
Source: BBC
AI company Anthropic revealed that hackers have weaponized its Claude chatbot to carry out sophisticated cyberattacks and fraud schemes. The company detected cases where criminals used Claude to write malicious code targeting at least 17 organizations, including government bodies. The AI helped hackers make strategic decisions about data theft and even suggested ransom amounts for victims.
In a separate scheme, North Korean operatives used Claude to create fake profiles and secure remote jobs at Fortune 500 tech companies, potentially violating international sanctions. Anthropic has disrupted these threats and reported them to authorities while improving its detection systems. Experts warn that AI is rapidly shrinking the time needed to exploit cybersecurity vulnerabilities.
Source: BBC
Critical infrastructure faced 420 million cyberattacks between January 2023-2024, a 30% jump equaling 13 attacks per second. Nation-state hackers like Iran's CyberAv3ngers are targeting water, oil, and gas systems with custom malware, while 60% of energy sector attacks link to state-sponsored groups.
Experts say industrial "crown jewels" now extend beyond physical machines to include digital twins, cloud platforms, data flows, and remote access gateways. The challenge? Many organizations only discover critical assets after breaches expose hidden dependencies.
As operational technology merges with IT systems, companies must continuously map assets and vulnerabilities rather than react to incidents. The stakes are clear: poor protection risks safety, uptime, and competitive advantage in an increasingly connected industrial landscape.
Source: Industrial Cyber
Critical infrastructure faced 420 million cyberattacks between January 2023-2024, a 30% jump equaling 13 attacks per second. Nation-state hackers like Iran's CyberAv3ngers are targeting water, oil, and gas systems with custom malware, while 60% of energy sector attacks link to state-sponsored groups.
Experts say industrial "crown jewels" now extend beyond physical machines to include digital twins, cloud platforms, data flows, and remote access gateways. The challenge? Many organizations only discover critical assets after breaches expose hidden dependencies.
As operational technology merges with IT systems, companies must continuously map assets and vulnerabilities rather than react to incidents. The stakes are clear: poor protection risks safety, uptime, and competitive advantage in an increasingly connected industrial landscape.
Source: Industrial Cyber