Tag: corporate
-
Why Provision 29 is raising the bar for board accountability
By Tim Williams, CEO at Quod Orbis Under the 2024 UK Corporate Governance Code, the revised Provision 29 requires boards to demonstrate that their material internal controls are working effectively. Every business has hundreds of controls, however material controls have the potential to create an immense operational, security or regulatory impact. The message behind this…
-
Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/recruitment-scam-corporate-passwords-mobile/
-
Fake Recruiter Scams Target Corporate Credentials on Mobile
RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-recruiter-scams-corporate/
-
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint agent widely used across corporate environments on Windows, macOS, and Linux. The issues include local privilege escalation vulnerabilities that could allow a low-privileged attacker with access to an endpoint to gain full SYSTEM privileges on Windows…
-
Thousands of Leaked AWS Access Keys Are Still Active
Truffle Security found 9,308 leaked AWS keys still active, including 768 corporate credentials with full administrative control of cloud accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-leaked-aws-access-keys-still-active/
-
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
Tags: access, cloud, corporate, credentials, cyber, data, data-breach, iam, infrastructure, risk, theftA large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include 526 root access keys and 242 IAM user keys attached to AWS’s AdministratorAccess managed…
-
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/
-
Enterprise Network Security Solution
A traditional corporate network may once have consisted primarily of office computers, servers, switches, routers, and a centralized data center. Today, organizations operate across cloud platforms, remote offices, SaaS applications, mobile devices, IoT systems, endpoints, APIs, data centers, and operational technology environments. Employees can access business resources from almost anywhere. Applications may be distributed across…
-
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks
Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then monetized through ASTROPROXY potentially exposing corporate IP space and internally reachable resources. The relationship…
-
Google Mandiant AI Agents Find Over 100 Critical Vulnerabilities in Source Code Within Two Days
Tags: ai, breach, corporate, cyber, google, group, incident response, intelligence, mandiant, penetration-testing, RedTeam, threat, vulnerabilityGoogle’s Threat Intelligence Group has announced that its Agentic Vulnerability Discovery Harness (AVDH) identified over 100 critical true-positive vulnerabilities in stolen corporate source code repositories within just two days. This result highlights how agentic AI can significantly accelerate vulnerability discovery during incident response, red teaming, penetration testing, and proactive secure code reviews, especially when adversaries…
-
When AI Risk Becomes a Board Liability
CIOs Can Strengthen Oversight Through Reporting, Records and Insurance Reviews. AI failures can trigger financial, regulatory and reputational exposure that reaches the boardroom. Reed Smith partners Carolyn Rosenberg and Andy Moss explain how CIOs can document oversight, validate corporate claims and test insurance for coverage gaps. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/when-ai-risk-becomes-board-liability-a-32594
-
Hackers target Ukrainian agency managing assets seized from sanctioned Russians
The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages. First seen on therecord.media Jump to article: therecord.media/hackers-target-ukraine-agency-sanctioned-russians
-
Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as >>TheHatman<< claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/azure-data-leak-fortune-500-companies/
-
Clop Claims Data Theft From More Than 40 Companies
Victims Are Assessing Claims of Stolen Databases, CAD Files and Backups. Russia-linked Clop claims it stole databases, engineering files, backups and other sensitive corporate data from more than 40 organizations in a breach wave tied to exploitation of a critical remote code execution flaw in PTC Windchill and FlexPLM. First seen on govinfosecurity.com Jump to…
-
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Two security researchers bought cheap domains”, including noreply.net and deleteduser.com”, and set up email listening services. Hundreds of companies are sending them corporate secrets. First seen on wired.com Jump to article: www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/

