Tag: threat
-
7 Reasons Teams Add Email Security Beyond Microsoft 365 E5
<div cla Quick answer: why teams layer email security on top of Microsoft 365 E5 Microsoft 365 E5 is the ceiling of Microsoft native email security. It includes Defender for Office 365 Plan 2, which adds automated investigation, Threat Explorer, and Attack Simulation Training on top of the Plan 1 detection that now ships with…
-
China-Nexus Threat Actor Targeting Critical VMware Flaw
A China-nexus bad actor is likely behind the rapid exploitation of a critical flaw in VMware’s vCenter management software that has spread across 361 victim IP addresses in almost four dozen countries. Exploitation of the vulnerability tracked as CVE-2026-59310 started five days after VMware owner Broadcom first disclosed the security flaw July 29,.. First seen…
-
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/17/unprecedented-number-of-apple-users-received-recent-spyware-alert-say-investigators/
-
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
-
Adam Shostack Talks Hugging Face & PHANTOM-B
World-class threat modeler Adam Shostack shared he was blown away by OpenAI’s revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both lightweight yet still usable. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
-
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the First seen…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
FireTail State of AI Security 2026: Adoption Has Outpaced Control FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 17, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…

