Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Colombian Justice Ministry Hit by Ransomware Attack Just Days Before Presidential Transition A devastating ransomware attack struck Colombia’s Ministry of Justice on August 2, crippling several public-facing services and raising concerns about the country’s ability to protect its critical infrastructure. The attack, which occurred just five days before the presidential handover, is the latest in … Read more

Walmart’s "Trusted Agent" Approach to Purple Teaming

Walmart Revolutionizes Purple Teaming with “Trusted Agent” Approach In a bold move to shake up traditional cybersecurity practices, Walmart has abandoned the siloed approach of separate red and blue teams, instead embracing a collaborative culture that fosters trust, learning, and mutual growth. By co-locating teams, adopting a “trusted agent” observation model, and prioritizing organizational improvement … Read more

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A Long-Running Data Theft Campaign Targets Salesforce and ServiceNow Users Worldwide A sophisticated threat actor has been using custom-built tools to steal sensitive data from organizations that use Salesforce and ServiceNow platforms. The campaign, dubbed “City-Forum” by researchers at AI cybersecurity firm Reco, has been active since at least March 2025 and has targeted multiple … Read more

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability has been discovered in Adobe’s Commerce and Magento e-commerce platforms, potentially allowing hackers to hijack customer accounts. This flaw, identified as CVE-2026-71362, is just one of seven issues addressed by Adobe in a recent security update. Despite the software vendor’s claim that it is not aware of exploits in the wild for … Read more

Android malware combo takes out loans and relays victims’ credit cards

A New Android Malware Combo Steals Credit Cards and Takes Out Loans via Phone Calls Cyber attackers have devised a sophisticated scheme to steal credit card information and take out loans using a combination of malware tools on Android devices. The malicious operation involves phone calls, social engineering, and the exploitation of Accessibility Services permissions … Read more

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

Cybersecurity researchers have uncovered a sophisticated data theft campaign targeting organizations worldwide. Dubbed City-Forum by SaaS security firm Reco, the attacks exploit vulnerable configurations on Salesforce and ServiceNow portals, allowing attackers to steal sensitive information exposed to anonymous users. The City-Forum campaign has been linked to a single server hosted in Germany by Contabo, which … Read more

Walmart’s "Trusted Agent" Approach to Purple Teaming

Walmart’s groundbreaking approach to cybersecurity has just been revealed, and it’s a game-changer. The retail giant has ditched traditional siloed red and blue teams in favor of a collaborative “Trusted Agent” model, where both offensive and defensive security practitioners work together to improve the company’s overall security posture. At the heart of this innovative approach … Read more

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A Long-Running Data Theft Campaign Targets Salesforce and ServiceNow, Exposing Sensitive Information Worldwide A sophisticated cyber threat actor has been conducting a long-running campaign of data theft against organizations using Salesforce and ServiceNow platforms, compromising sensitive information from multiple sectors around the world. The campaign, dubbed “City-Forum” by researchers at AI cybersecurity firm Reco, has … Read more

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers are exploiting a critical vulnerability in Adobe Commerce and Magento e-commerce platforms, potentially allowing them to hijack customer accounts. The bug, identified as CVE-2026-71362, is an incorrect authorization vulnerability that can be leveraged without authentication or administrator privileges. This means that attackers do not need to have existing account information or interact with users … Read more

Android malware combo takes out loans and relays victims’ credit cards

Android Malware Combo Takes Out Loans and Relays Victims’ Credit Cards in Real-Time A disturbing combination of malware has been used by attackers to steal card data from unsuspecting Android users, taking out loans and making unauthorized purchases using their credit cards. The malicious duo, consisting of the SpyNote remote administration tool (RAT) and WindRelay … Read more