News

The intruder is in the house: Storm-0501 attacked Azure, stole data, demanded payment via Teams

The Register - Wed, 27/08/2025 - 17:51
Don't let it happen to you

Storm-0501, a financially motivated cybercrime crew, recently broke into a large enterprise's on-premises and cloud environments, ultimately exfiltrating and destroying data within the org's Azure environment. The criminals then contacted the victim via a Microsoft Teams account that they'd also compromised in the attack, demanding a ransom payment for the stolen files.…

Categories: News

Salesforce data missing? It might be due to Salesloft breach, Google says

The Register - Wed, 27/08/2025 - 14:04
Attackers steal OAuth tokens to access third-party sales platform, then CRM data in 'widespread campaign'

Google says a recent spate of Salesforce-related breaches was caused by attackers stealing OAuth tokens from the third-party Salesloft Drift app.…

Categories: News

Who are you again? Infosec experiencing 'Identity crisis' amid rising login attacks

The Register - Wed, 27/08/2025 - 10:39
Vendor insists passkeys are the future, but getting workers on board is proving difficult

Infosec pros are losing confidence in their identity providers' ability to keep attackers out, with Cisco-owned Duo warning that the industry is facing what it calls "an identity crisis."…

Categories: News

BGP’s security problems are notorious. Attempts to fix that are a work in progress

The Register - Wed, 27/08/2025 - 07:30
Securing internet infrastructure remains a challenging endeavour

Systems Approach  I’ve been working on a chapter about infrastructure security for our network security book.…

Categories: News

Google issued ‘State-backed attack in progress’ warnings after spotting web hijack scheme

The Register - Wed, 27/08/2025 - 05:58
Suspects this was Beijing-backed Typhoon and/or Panda crew targeting diplomats in Asia

Google has warned customers of a suspected state-backed attack after observing a web traffic hijacking campaign.…

Categories: News

First AI-powered ransomware spotted, but it's not active – yet

The Register - Tue, 26/08/2025 - 22:24
Oh, look, a use case for OpenAI's gpt-oss-20b model

ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the "first known AI-powered ransomware," which they named PromptLock. …

Categories: News

Azure apparatchik shows custom silicon keeping everything locked down

The Register - Tue, 26/08/2025 - 21:50
From hardware security chips and trusted execution pipelines to open source Root of Trust modules

Hot Chips  Microsoft is one of the biggest names in cybersecurity, but it has a less-than-stellar track record in the department. Given its reputation, Redmond can't afford to mess around when it comes to securing its cloud customers' data and workloads.…

Categories: News

DOGE accused of duplicating critical Social Security database on unsecured cloud

The Register - Tue, 26/08/2025 - 21:02
Remember that cost-cutting group once led by Elon Musk? Federal employees are still dealing with it

A Social Security Administration employee has filed a whistleblower complaint alleging that Donald Trump's DOGE cost-cutting unit has put the records of every single American at risk by duplicating an agency database in an unauthorized cloud environment. …

Categories: News

ZipLine attack uses 'Contact Us' forms, White House butler pic to invade sensitive industries

The Register - Tue, 26/08/2025 - 20:43
'Many dozens' targeted in ongoing campaign, CheckPoint researcher tells The Reg

Cybercriminals are targeting critical US manufacturers and supply-chain companies, looking to steal sensitive IP and other data while deploying ransomware. Their attack involves a novel twist on phishing — and a photo of White House butlers. …

Categories: News

Citrix patches trio of NetScaler bugs – after attackers beat them to it

The Register - Tue, 26/08/2025 - 16:40
Criminals already abusing its latest zero-days

Citrix has pushed out fixes for three fresh NetScaler holes – and yes, they've already been used in the wild before the vendor got around to patching.…

Categories: News

Crypto thief earns additional prison time for assaulting witness

The Register - Tue, 26/08/2025 - 14:47
Remy Ra St Felix led a vicious international crime ring

A violent home invader and gunpoint cryptocurrency thief will now spend more than 50 years behind bars after being found guilty of assaulting a witness.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News