From Fake Workers to Account Recovery: The Growing Identity Verification Risk

Cybersecurity teams have made significant strides in strengthening authentication protocols, but a growing threat remains: identity verification risks during onboarding and recovery processes. Despite multi-factor authentication (MFA) and conditional access becoming increasingly common, attackers are exploiting weaknesses in these critical moments to gain unauthorized access. When employees join or leave an organization, account access is … Read more

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Threat Actors Use Voice AI Agents to Phish iPhone Passcodes in Sophisticated Scheme A new phishing-as-a-service (PhaaS) platform called AnonyMousKIT has been uncovered, using voice artificial intelligence agents to trick victims into revealing their iPhone passcodes. This brazen scheme allows threat actors to unlock and resell stolen Apple devices, while also accessing sensitive data stored … Read more

Hackers abuse npm mirrors to host phishing redirect pages

Cybercriminals have discovered a new way to use the npm package manager to host phishing redirect pages, exploiting a weakness in the system that allows them to store malicious HTML files on legitimate domains. This technique has been spotted in at least 24 packages, which were found to contain identical code that impersonates Cloudflare CAPTCHAs … Read more

LACMA data breach last year exposed social security and medical data

A Major Cultural Institution’s Data Breach Exposes Sensitive Information of Thousands The Los Angeles County Museum of Art (LACMA) has revealed that a significant data breach occurred last year, compromising sensitive information of its employees and visitors. The incident, which was discovered on July 11, 2025, exposed not only personal details but also sensitive financial … Read more

Massive DDoS attack disrupts Norway’s government digital services

A massive distributed denial-of-service (DDoS) attack has crippled Norway’s shared government digital services since Monday, leaving a trail of disruption and speculation in its wake. The assault on the Norwegian Digitalization Agency’s (Digdir) infrastructure has targeted public-facing services, forcing users to endure frustrating errors, slow server responses, and unusually long login times. The impact is … Read more

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Cybersecurity experts have uncovered a sophisticated PhaaS platform that uses voice AI agents to phish iPhone passcodes, exploiting vulnerabilities in Apple’s Activation Lock feature. The platform, known as AnonyMousKIT, has been active since early 2024 and is linked to a sprawling ecosystem of stolen iPhones, compromised Apple IDs, and accessed iCloud backups. At its core, … Read more

Frontier AI: Vulnerability Management’s Systemic Revolution

**Cybersecurity experts are sounding the alarm on a new vulnerability management system that’s revolutionizing the way organizations approach identity exposure and active attack paths. But what exactly does this mean, and why should you care?** A recent breakthrough in artificial intelligence (AI) has given rise to a cutting-edge vulnerability management platform called Frontier AI. This … Read more

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

**Malicious FTP Banners Used as Hidden Command Channels for Malware** A new and insidious tactic has emerged in the world of cyber attacks, where hackers are exploiting a seemingly innocuous aspect of network infrastructure to secretly command malware. Cybersecurity researchers have discovered that malicious actors are hijacking File Transfer Protocol (FTP) banners – those brief … Read more

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

A significant escalation in the ongoing cat-and-mouse game between nation-state hackers and global cybersecurity authorities has unfolded with the United States imposing sanctions on a group of Iranian-linked hackers accused of breaching critical infrastructure targets worldwide. The move is seen as a major step up in efforts to disrupt state-sponsored cyberattacks, which have reached unprecedented … Read more