Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Tricks Marketing Pros into Handing Over Google Credentials** A sophisticated phishing campaign is targeting marketing professionals’ Google accounts by posing as major corporate brands, such as Coca-Cola and Netflix, in an attempt to steal sensitive credentials. The campaign uses a range of tactics, including nested redirects and browser-in-the-browser attacks, to evade … Read more

Webinar tomorrow: Why modern email attacks require a new approach to defense

Email attacks continue to plague organizations worldwide, with phishing, business email compromise (BEC), and account takeover (ATO) remaining among the most persistent threats facing security teams. Despite investments in secure email gateways, multi-factor authentication, and identity protection, these types of attacks persist due to their sophisticated nature. Attackers have shifted their tactics from relying on … Read more

Accenture confirms breach after hacker offers stolen data for sale

Accenture’s 35GB Data Heist Exposed, Company Remediates Breach with Minimal Impact A brazen cyberattack on IT services giant Accenture has left the company scrambling to contain the fallout. Threat actor “888” claims to have stolen a staggering 35 GB of sensitive data, including source code and personal access tokens, from Accenture’s systems in July. The … Read more

Microsoft to enable Windows settings backup by default for orgs

Microsoft has announced a significant change in its approach to data protection and device management, with far-reaching implications for enterprise users. As of the latest update to Windows 11, version 26H2, Microsoft will enable by default the backup and restore tool for organizations, previously known as “Windows Backup for Organizations,” on eligible devices. This tool … Read more

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A Critical Linux Flaw Allows Attackers to Escape Virtual Machines and Take Control of Hosts A recently patched vulnerability in the Linux kernel has been discovered to allow attackers to escape virtual machines (VMs) and execute arbitrary code on the host, potentially leading to a complete takeover. Dubbed “Januscape,” this flaw affects both Intel and … Read more

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese Hackers Expand Sophisticated ORB Network with New Malware Capabilities A highly advanced Chinese hacking group, tracked as “UAT-7810,” has been quietly expanding its Operational Relay Box (ORB) network by compromising internet-facing networking devices. The hackers are using a new malware called LONGLEASH to gain access and control over these devices, which serve as secure … Read more

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Google Dialogflow CX, a popular platform for building conversational interfaces, was recently found to have a critical vulnerability that could have allowed attackers to hijack chatbots and steal sensitive user data. The flaw, discovered by AI-powered security researchers, highlights the growing importance of artificial intelligence in identifying and mitigating software vulnerabilities. The rogue agent flaw, … Read more

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A sophisticated Android malware campaign has been uncovered, with attackers using a clever disguise to evade detection and pilfer sensitive financial information from unsuspecting users. The RedWing malware-as-a-service (MaaS) packages have been found to masquerade as a legitimate Telegram rental service, making it incredibly difficult for victims to discern the malicious intent behind the app. … Read more

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

The Hidden Dangers Lurking in Your GitHub CI Pipelines A recent revelation has exposed a worrying trend in software development: even when your Continuous Integration (CI) security scanners give you a clean bill of health, your pipeline might still be vulnerable to attack. Researchers at Novee Security have identified a class of weaknesses they call … Read more

Hidden backdoor in Tenda router firmware grants admin access

Hidden Backdoor in Tenda Router Firmware Grants Admin Access to Attackers A disturbing security vulnerability has been discovered in multiple versions of Tenda router firmware, potentially allowing malicious actors to gain full administrative access to affected devices. The issue, tracked as CVE-2026-11405, is caused by an undocumented authentication mechanism that can be exploited using a … Read more