Hackers abuse Faronics Deploy admin tool to install ScreenConnect

A Sneaky Phishing Campaign Exploits Faronics Deploy Platform, Installs Malicious ScreenConnect Software Phishing actors have been using a legitimate endpoint management platform to gain remote control over victim computers and install malicious software. The attackers are abusing the cloud-based Faronics Deploy platform, which is designed for IT administrators to manage and deploy software remotely. By … Read more

FBI Probes Service Selling 153M+ Drivers Licenses

A massive identity theft operation has come to light, exposing over 153 million drivers licenses and other sensitive documents from individuals in the United States and Canada. The illicit service, dubbed “Nexus,” offers these digital scans for purchase on a notorious dark web forum called Exploit, with some records dating back to 2025. What’s more … Read more

Stronger Security Drives Ransomware Groups to Recruit From Within

Malicious Insiders Are Becoming a Growing Threat to Corporate Security A disturbing trend is emerging in the world of cybersecurity: malicious insiders are increasingly helping ransomware groups gain access to corporate networks, resulting in devastating financial losses and reputational damage. According to recent research, insider threats are on the rise, with 56% of incidents attributed … Read more

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

Threat actors are moving swiftly to exploit a critical vulnerability in JFrog’s Artifactory repository manager, just days after its public disclosure. The flaw, identified as CVE-2026-82329, allows an unauthenticated attacker to gain administrative access to affected systems with no user interaction required. JFrog disclosed the vulnerability on August 28 and released patched versions of the … Read more

Aesto Health says data breach affects over 9.5 million patients

A massive data breach at Aesto Health has compromised the sensitive information of over 9.5 million individuals, highlighting the ongoing vulnerabilities in the healthcare industry’s digital infrastructure. The attack, which occurred between December 2 and December 18 last year, involved an unauthorized actor accessing protected health information stored within Aesto’s network. Aesto Health provides software-as-a-service … Read more

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Cyberattackers Exploit Faronics Deploy to Install Malicious Remote Access Tool A sophisticated phishing campaign has been discovered abusing a legitimate endpoint management platform, Faronics Deploy, to gain unauthorized access to victim computers and install a remote support software. Researchers at Huntress, a managed detection and response company, uncovered the scheme, which targeted over 457 endpoints … Read more

FBI Probes Service Selling 153M+ Drivers Licenses

The dark web has given birth to a new identity theft service that’s selling digital scans of over 153 million drivers’ licenses from the United States and Canada. This staggering number was confirmed by interviews with individuals whose licenses are available for purchase on this service, which claims to have obtained these images from an … Read more

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange Servers at Risk of Hijack Attacks as Patch Remains Unapplied A staggering number of Microsoft Exchange servers remain unpatched against a critical security flaw that allows attackers to hijack user mailboxes. According to recent findings by Shadowserver, a threat intelligence watchdog group, nearly 22,000 Exchange servers are still vulnerable to the … Read more

Critical Langflow flaw exploited to steal OpenAI and AWS keys

A Critical Vulnerability in Langflow Framework Exposes OpenAI and AWS Keys to Attackers Threat actors have been exploiting a critical vulnerability in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys from vulnerable instances. According to threat intelligence firm VulnCheck, over 360 attacks were detected on its honeypots in the … Read more

Aesto Health says data breach affects over 9.5 million patients

A massive data breach at Aesto Health has compromised sensitive information for over 9.5 million individuals, sparking concerns about the security of healthcare organizations’ patient data. The company, which provides software-as-a-service solutions to help healthcare providers manage electronic health records, disclosed the attack in a recent statement. The breach occurred between December 2 and 18, … Read more