“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

Cybersecurity researchers have uncovered a sophisticated data theft campaign targeting organizations worldwide. Dubbed City-Forum by SaaS security firm Reco, the attacks exploit vulnerable configurations on Salesforce and ServiceNow portals, allowing attackers to steal sensitive information exposed to anonymous users. The City-Forum campaign has been linked to a single server hosted in Germany by Contabo, which … Read more

Walmart’s "Trusted Agent" Approach to Purple Teaming

Walmart’s groundbreaking approach to cybersecurity has just been revealed, and it’s a game-changer. The retail giant has ditched traditional siloed red and blue teams in favor of a collaborative “Trusted Agent” model, where both offensive and defensive security practitioners work together to improve the company’s overall security posture. At the heart of this innovative approach … Read more

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A Long-Running Data Theft Campaign Targets Salesforce and ServiceNow, Exposing Sensitive Information Worldwide A sophisticated cyber threat actor has been conducting a long-running campaign of data theft against organizations using Salesforce and ServiceNow platforms, compromising sensitive information from multiple sectors around the world. The campaign, dubbed “City-Forum” by researchers at AI cybersecurity firm Reco, has … Read more

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers are exploiting a critical vulnerability in Adobe Commerce and Magento e-commerce platforms, potentially allowing them to hijack customer accounts. The bug, identified as CVE-2026-71362, is an incorrect authorization vulnerability that can be leveraged without authentication or administrator privileges. This means that attackers do not need to have existing account information or interact with users … Read more

Android malware combo takes out loans and relays victims’ credit cards

Android Malware Combo Takes Out Loans and Relays Victims’ Credit Cards in Real-Time A disturbing combination of malware has been used by attackers to steal card data from unsuspecting Android users, taking out loans and making unauthorized purchases using their credit cards. The malicious duo, consisting of the SpyNote remote administration tool (RAT) and WindRelay … Read more

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

A sophisticated data theft campaign has been targeting organizations worldwide, exploiting a common vulnerability in Salesforce Experience Cloud and ServiceNow customer portals. Dubbed “City-Forum” by SaaS security firm Reco, these attacks have been ongoing for over a year, with activity increasing steadily. The attackers are not exploiting vulnerabilities in the platforms themselves but rather stealing … Read more

Hackers leverage new Microsoft SharePoint exploit in attacks

A Critical Microsoft SharePoint Vulnerity is Being Exploited in Real-World Attacks, Putting Thousands at Risk A highly critical security vulnerability in Microsoft’s popular collaboration platform, SharePoint, has been found to be actively being used by hackers in real-world attacks. The flaw, tracked as CVE-2026-55040, allows attackers to bypass authentication and gain access to sensitive data … Read more

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Cybersecurity Threats Lurking in the Hiring Process: How Fake Remote Workers Gain Access The traditional threat landscape is filled with phishing emails, exploited vulnerabilities, and malicious code. However, a more insidious threat has been lurking in plain sight – one that exploits the very process of hiring new employees to gain access to corporate networks. … Read more

FBI: Hackers target online accounts to steal nude photos

The FBI has issued a public service announcement warning that cybercriminals are targeting adults’ and children’s online accounts, stealing sexually explicit images or videos to blackmail victims or sell on criminal marketplaces. This malicious activity is known as sextortion, where attackers threaten to leak private content unless the victim pays them or provides more intimate … Read more

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Over 737 fake Chrome VPN extensions, masquerading as well-known brands such as Proton VPN and NordVPN, have been discovered routing users’ traffic through SOCKS5 proxies operated by a single provider. This malicious campaign has resulted in nearly 75,000 downloads from the Chrome Web Store, with a significant number of victims hailing from Russia. The extensions, … Read more