Tag: business
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Tags: business, communications, credentials, crypto, cyber, data, email, infection, malware, phishing, powershellA sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake…
-
Patient Sues Abbott Labs, Exact Sciences in Data Theft
Class Action Suit Claims Labs Failed to Safeguard Data in ShinyHunters Hack. The first of what could be many more proposed class action lawsuits has been filed against clinical testing laboratory and medical device maker Abbott Laboratories and its cancer diagnostics business Exact Sciences following a data theft hack claimed by cybercrime gang ShinyHunters. First…
-
IBM Bets on Multi-Billion-Dollar Open-Source Patch Business
IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches. IBM is betting that AI can transform legacy open-source vulnerability remediation into a multibillion-dollar business by delivering validated, backported security patches for software versions enterprises continue to run years after upstream support ends. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ibm-bets-on-multi-billion-dollar-open-source-patch-business-a-32317
-
Shadow AI is becoming enterprise security’s biggest blind spot
Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/shadow-ai-security-risks/
-
Why Quantum Migration Starts With Security Infrastructure
IBM: Security Leaders Should Assess Supplier Adoption of Quantum-Safe Cryptography. IBM’s Suja Viswesan said organizations should begin post-quantum migration by evaluating security infrastructure vendors, prioritizing cryptography-heavy environments such as telecom and critical infrastructure, and treating quantum readiness as an ongoing business-driven modernization program. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quantum-migration-starts-security-infrastructure-a-32301
-
Cloud operations become the next big role for agentic AI
Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/agentic-ai-cloud-operations-report/
-
Estée Lauder customer data compromised in Oracle E-Business Suite breach
First seen on scworld.com Jump to article: www.scworld.com/brief/estee-lauder-customer-data-compromised-in-oracle-e-business-suite-breach
-
Services Firm ApolloMD Settles Hack Lawsuit for $4M
Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000. Revenue cycle management services firm ApolloMD Business Services has agreed to pay just over $4 million to settle proposed class action litigation stemming from a 2025 data theft claimed by ransomware gang Qilin that affected nearly a dozen physician practices and 627,000 of…
-
1 in 4 businesses hit by cyber attacks through their supply chain in the last year
One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have…
-
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder meldet Datenabfluss durch Oracle-Schwachstelle
Estée Lauder meldet einen Datenabfluss. Angreifer nutzten eine Sicherheitslücke in Oracle E-Business Suite zur Entwendung von Personal- und Kundendaten. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/estee-lauder-datenabfluss
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
Abbott discloses cyberattack on cancer diagnostics business
The cyberattack follows Abbott’s recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/abbott-discloses-cyberattack-on-cancer-diagnostics-business/825552/
-
“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware
An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows… First seen on hackread.com Jump to article: hackread.com/ttf-trap-phishing-fake-font-files-windows-malware/
-
Horizon3.ai boss talks of partner importance
Tags: businessSecurity player has seen its revenues via the channel continue to grow as it looks to ramp up its indirect business First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366645956/Horizon3ai-boss-talks-of-partner-importance
-
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
Tags: business, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite that can lead to a takeover of Oracle Payments. The agency added the issue to its Known Exploited Vulnerabilities Catalog on July 15, 2026, and directed affected federal civilian executive…
-
US unseals indictment against alleged operators of Russian bulletproof hosting service
The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud. First seen on therecord.media Jump to article: therecord.media/us-unseals-indictment-russians-bulletproof-hosting
-
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved…
-
US enterprises incorporate cyber risk into larger strategic focus
The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-enterprises-cyber-risk-strategic-focus/824707/
-
Phishing Attacks Targeted Facebook Users With Fake Verification Offer
Attacks also used a compromised chatbot in campaign to steal sensitive information from Business Users First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-facebook-fake-verification/
-
Webinar tomorrow: Why modern email attacks require a new approach to defense
Tomorrow’s webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-tomorrow-why-modern-email-attacks-require-a-new-approach-to-defense/
-
Boost City regulator’s powers to help protect UK consumers from AI, says watchdog
FCA’s review into how tech will reshape financial services warns about amplified risks of cyber-crime and fraud<ul><li><a href=”https://www.theguardian.com/business/live/2026/jul/06/sky-takeover-itv-broadcasting-media-deal-business-live-news”>Business live latest updates</li></ul>Ministers have been urged to toughen the City regulator’s powers to protect consumers against the potential risks of AI, according to a landmark review.The Mills review by the Financial Conduct Authority (FCA), which looked at…
-
How to prioritize AI agent security by business impact
Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/
-
Wenn der Notfallplan versagt: Was Unternehmen bei Cyberattacken besser machen müssen
Management Summary Cyberangriffe bleiben ein geschäftskritisches Risiko: Unternehmen müssen Incident Response, Business Continuity und Disaster Recovery als integrierte Management-Aufgabe verstehen. Die größten Schwachstellen liegen weniger in einzelnen Technologien als in fehlenden Notfallplänen, unklaren Zuständigkeiten, mangelnder Übung und unvollständiger Dokumentation. Regelmäßige Tests inklusive Backup- und Recovery-Prozessen sind entscheidend, um im Ernstfall schnell, koordiniert und mit… First…
-
SAESL turbocharges aircraft engine maintenance with data and AI
The world’s largest supplier of Rolls-Royce engine maintenance services is working with Kyndryl to modernise its IT infrastructure, build a single source of truth for data and scale up the use of AI across its business First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645474/SAESL-turbocharges-aircraft-engine-maintenance-with-data-and-AI

