Mount Royal University confirms breach as hackers claim attack

A Calgary University Hit with Cyberattack, Hackers Demand $1.9 Million Ransom Mount Royal University in Calgary has confirmed a breach of its network after hackers stole and then deleted data from its file storage systems. The attack, which occurred on June 17, disrupted various university systems, including online services and internal systems. The university has … Read more

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Service desks around the world are increasingly becoming a target for sophisticated social engineering attacks, thanks in part to the growing use of artificial intelligence (AI) by malicious actors. A recent report found that 16% of data breaches studied involved attackers using AI tools, with phishing and deepfake impersonation attacks being among the most common … Read more

Entra passkey enrollment vishing targets Microsoft 365 users

**Threat Actor Exploits Microsoft Entra Passkey Feature to Phish Users** A sophisticated threat actor has been targeting organizations across various sectors with a clever voice phishing scam, convincing victims to enroll a new Entra passkey under their control. The attackers are taking advantage of a recent security feature introduced by Microsoft in May, which allows … Read more

Hackers exploit Roundcube flaw to spy on academic researchers

A China-Linked Threat Cluster is Stealing Credentials from Academic Researchers through Roundcube Servers A sophisticated hacking campaign has been uncovered, targeting vulnerable servers at universities in the United States and Canada. The attackers, linked to a China-based threat cluster, have been exploiting two previously identified vulnerabilities in Roundcube email clients to gain access to sensitive … Read more

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

Malicious SDKs on NPM and PyPI Steal Credentials from Developers and Users of Popular Payment Platforms A sophisticated cyber attack has been discovered on two popular software repositories, leaving developers and users of Paysafe, Skrill, and Neteller payment applications vulnerable to credential theft. The attackers published at least 17 malicious packages simultaneously on the Node … Read more

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

A new threat has emerged, one that challenges the very foundations of endpoint security: AI coding agents are inadvertently triggering rules designed to catch attackers, leaving organizations vulnerable to compromise. The issue stems from advanced artificial intelligence (AI) models, specifically those used in software development and testing, which can mimic malicious behavior and trigger security … Read more

Entra passkey enrollment vishing targets Microsoft 365 users

A sophisticated phishing campaign, dubbed “Pink,” has been targeting Microsoft 365 users across various industries, tricking them into enrolling fake Entra passkeys under the attacker’s control. The scheme exploits a legitimate Microsoft feature introduced in May, which allows administrators to run passkey registration campaigns. Threat actors are using this capability to phish victims and gain … Read more

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

GitHub’s AI-powered coding tool, Copilot, is being hailed for its ability to detect and refuse requests that could potentially harm users. This innovative feature allows Copilot to not only recognize malicious code but also prevent it from being written in the first place. Copilot uses a combination of machine learning algorithms and natural language processing … Read more

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti’s Critical UniFi Flaws Patched Across Multiple Devices, but Many Remain Unprotected Ubiquiti Networks, a leading provider of networking hardware and software solutions, has issued critical security patches for its widely-used UniFi platform. The patches address multiple vulnerabilities in various UniFi products, including Connect, Talk, Access, Protect, and OS, leaving millions of users exposed to … Read more

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

A new and insidious form of cyberattack is making headlines, threatening to compromise even the most advanced security measures. Dubbed “HalluSquatting,” this emerging threat exploits AI-powered coding assistants to install botnet malware on unsuspecting devices. The attack’s sophistication and potential impact have left cybersecurity experts scrambling for solutions. At its core, HalluSquatting relies on a … Read more