Tag: security

Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices

McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific,…

Read More

Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it’s all thanks to this new malware

Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts Compromised routers act as operational platforms Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going…

Read More

New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks Security researchers from Microsoft are warning of an ongoing malicious campaign that uses…

Read More

How did Iran manage to knock a UK power generator offline for four days, and what does it mean for other critical infrastructure? The experts weigh in

Just days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US, a UK power generation plant was taken offline for four days after a cyberattack. The attack has been attributed to Iran, which has stepped up its offensive cyber warfare efforts since the…

Read More

Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks

Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals AI agents could install malware if they execute hallucinated or outdated documentation commands Fixes: clean documentation and restrict AI agents from treating docs as executable instructions Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation…

Read More

Carhartt data breach exposed information from 12.9 million user accounts

ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks Data stolen from Databricks platform included names, emails, phone numbers, and addresses Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption Millions of user records belonging to customers of clothing giant Carhartt has been…

Read More