Tag: corporate
-
AI Accounts Are Becoming the New Target for Infostealers
Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent…
-
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/
-
Network Segmentation Failures Are Expanding the Corporate Attack Surface
Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/segmentation-failures-expanding/
-
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installing malware, granting remote access, and stealing Windows credentials. These attacks exploit a simple vulnerability: employees tend to distrust suspicious emails but often do not apply the same caution to collaboration platforms like Teams. Attackers…
-
Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware. The campaign, tracked from May through August 2026, targeted organizations in the retail, construction, manufacturing, and IT sectors. BI.ZONE DFIR investigators found that the threat actor combined…
-
Iranian Hackers Dodging Corporate Defenses to Reach Critics
Joint Advisory Details Chosen Brick Spyware Used Against Iran’s Critics Abroad. Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture screens, record audio and steal messages, according to a joint advisory from British, U.S. and Dutch intelligence agencies. First seen on…
-
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and…
-
TRM Labs Lands $2B Valuation as AI Expands Investigations
TRM Platform Uses AI to Marry Blockchain Data With Registries, Threat Intelligence. TRM Labs reached a $2 billion valuation as it uses AI to combine blockchain transactions with ownership, corporate and threat intelligence data, giving investigators a broader view of criminal and nation-state networks and potential points for disruption. First seen on govinfosecurity.com Jump to…
-
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Threat actors are leveraging Microsoft’s Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-warns-shadow-ai-security-risks/
-
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks/
-
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks/
-
Fake Acquisition Scam Uses Forged NDAs to Demand Euro626,000 Corporate Payment.
Threat actors impersonated Gen executives and major consulting firms in a targeted business email compromise-style operation that used forged non-disclosure agreements to isolate a legal employee and pressure the company into transferring Euro626,735.45 to a Hong Kong entity. Dubbed Phantom Deal, the campaign shows how financially motivated actors can abuse legitimate M&A processes, corporate history…
-
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of…
-
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of…
-
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of…
-
PaperCut Zero-Day Exploitation Escalates to Active Intrusions
Enterprise print management systems are often treated as routine infrastructure, but attackers continue to demonstrate that any connected application can become an entry point into a corporate environment. According to SecurityWeek report, threat actors are actively exploiting two recently disclosed… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/papercut-zero-day-exploitation-escalates-to-active-intrusions/
-
AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the…
-
Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says
Russian-speaking hackers used Cursor AI during attacks on corporate networks, reportedly speeding reconnaissance, VPN access and exploitation attempts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cursor-ai-hackers-aur0ra-ransomware/
-
TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with…
-
Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a low-cost entry point for fraudsters looking to commit executive impersonation, business email compromise (BEC), and identity theft. Recent threat research from Rapid7 reveals an increasingly sophisticated >>identity-as-a-service<< ecosystem. In this environment,…
-
What IBM’s Latest Breach Report Says About Data Security in an AI-Centric World
<div cla IBM has been charting the data breach landscape now for over two decades. But you’d be hard pressed to find any point over the past 21 years as volatile as today. AI is rewriting the rules of the game for network defenders and their adversaries, simultaneously arming attackers and creating a dangerous new…
-
Claude, Codex, and Hermes installed unowned code inside corporate networks
227 install commands were found in corporate docs pointing at code nobody owns. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
-
Fake recruiter scams target corporate credentials on mobile devices
First seen on scworld.com Jump to article: www.scworld.com/brief/fake-recruiter-scams-target-corporate-credentials-on-mobile-devices

