One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A stealthy attacker has been exploiting vulnerabilities in both Salesforce and ServiceNow portals, compromising sensitive data and creating backdoors for future attacks. The hacker’s activities have been ongoing since 2025, with a total of eleven identified instances of identity exposure used to unlock active attack paths. The method behind the attacks is based on cross-domain … Read more

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity Threat TCO Raises Alarm with TwinLoot Attacks on SharePoint and Teams A sophisticated attack campaign, code-named “TwinLoot,” has been spotted targeting organizations that use Microsoft’s collaboration platforms, SharePoint and Teams. The attackers have been leveraging a combination of clever tactics to steal sensitive credentials and move laterally across networks, leaving victims scrambling to contain … Read more

AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

A New Threat Emerges: “Mind Viruses” Spread Between AI Agents Through Persistent Prompt Files Researchers have discovered a novel attack vector that allows malicious actors to spread between artificial intelligence (AI) agents through persistent prompt files. This vulnerability has significant implications for organizations relying on AI-powered systems, as it enables attackers to create chains of … Read more

CISA: Windows Task Host flaw now exploited by ransomware gangs

A critical Windows vulnerability that was previously patched by Microsoft has been confirmed to be exploited by ransomware gangs, putting millions of devices at risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw, tracked as CVE-2025-60710, to its list of actively exploited vulnerabilities after discovering evidence of in-the-wild attacks. Task Host … Read more

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

A hardware wallet manufacturer, SafePal, has revealed that a flaw in its system exposed sensitive information for nearly 40,000 of its customers. The vulnerability allowed unauthorized access to user data, including email addresses and private keys. This security lapse highlights the importance of robust encryption and secure storage practices in the cryptocurrency industry. The issue, … Read more

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A highly skilled attacker has been quietly compromising both Salesforce and ServiceNow portals since 2025, exploiting vulnerabilities in these popular cloud platforms to gain unauthorized access to sensitive customer data. The brazen cyber campaign, which has flown under the radar for over a year, raises serious concerns about the security posture of companies that rely … Read more

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

A sophisticated malware campaign has targeted RubyGems, a popular package repository for Ruby developers, resulting in the compromise of 16 packages. The attack, which leverages a technique called typosquatting, has put browser credentials and cryptocurrency wallets at risk. Typosquatted packages are malicious versions of legitimate software that have been created to deceive users into installing … Read more

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

A massive data breach affecting over 1.2 million individuals has come to light, with consumer lender Heights Finance Holdings Co. notifying those whose personal and financial information was stolen by hackers. The incident, which occurred in early May, involved a third-party cloud-based platform used for customer data storage that was accessed by the attackers. The … Read more

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft has finally begun removing a long-abused tool from its latest Windows 11 builds, a move that’s expected to significantly boost the operating system’s security posture. The Windows Management Instrumentation Command-line (WMIC) tool, which has been a favorite among cybercriminals for its ability to interact with Windows systems using text commands, will no longer be … Read more