New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable applicatio…
Telegram's t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown.
By Zac Amos - Artificial intelligence (AI) is helping healthcare organizations automate administrative tasks, improve workflows and support better decision-making. However, implementing AI without careful planning can create new challenges for employees, leading to AI burnout ins…
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separa…
O Projeto Debian lançou o Debian 13.6, nova atualização de manutenção da versão “Trixie”, com correções de segurança e ajustes para falhas importantes encontradas em diferentes componentes do sistema operacional. O pacote não representa uma nova geração do Debian. Trata-se de uma…
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]
A Agência de Segurança Nacional dos Estados Unidos recomendou que organizações desativem o Cisco Smart Install após identificar ataques de hackers ligados ao governo russo contra roteadores e switches vulneráveis. O alerta foi publicado em conjunto com outras 17 agências internac…
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configura…
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environment…
May 2026 Healthcare Data Breach Report The HIPAA Journal
Uma vulnerabilidade crítica no plugin miniOrange Social Login para WordPress pode permitir que invasores assumam contas de usuários, incluindo perfis administrativos, sem precisar conhecer a senha. A falha, identificada como CVE-2026-12761, recebeu pontuação CVSS 9.8 e afeta vers…
Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting […] The post May 2026 Healthcare Data Breach Report appeared first on The HIPAA Journal.
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]
Lucent Health Solutions to Pay Up to 1.95M to Settle Data Breach Litigation The HIPAA Journal
A settlement has been agreed to resolve a class action lawsuit against the Nashville, TN-based health plan administration service provider, […] The post Lucent Health Solutions to Pay Up to 1.95M to Settle Data Breach Litigation appeared first on The HIPAA Journal.
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]
Proofpoint details how attackers spoof OAuth client IDs to probe Microsoft Entra accounts, test credentials and bypass common sign-in detections at cloud scale.
xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, clone…
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First V…