"City-Forum" Attacks Steal Data via Salesforce, ServiceNow Portals
Ongoing campaign uses custom tools to pilfer information from customer-facing portals exposed to unauthenticated users.
Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

The popular encrypted email provider's primary domain is inaccessible after being targeted by the U.S. Treasury.
Researchers uncover hidden firmware implants designed for data exfiltration and remote control across multiple router models.
Thousands of Gitea instances are exposed and unpatched against a severe RCE vulnerability, leaving them open to compromise.
Ongoing campaign uses custom tools to pilfer information from customer-facing portals exposed to unauthenticated users.
Homeland Security drones are now surveying wildlife and livestock in South Texas to monitor the spread of the New World screwworm.

A compromised AI package led to the exfiltration of terabytes of user data from 2,500 accounts.
A severe vulnerability in Adobe Commerce and Magento allows attackers to compromise customer data and accounts.

Organizations must prioritize security and governance when selecting interactive demo platforms to protect sensitive data and meet compliance.

Hundreds of malicious Chrome extensions disguised as VPNs rerouted user data through a single proxy provider's infrastructure.

North Korean state-sponsored hackers are leveraging a new Windows zero-day, tracked as CVE-2026-68820, to target defense contractors in sophisticated phishing campaigns.

New honeypot simulates services and analyzes attacker behavior to identify type and intent, moving beyond simple log analysis.
New 'Plug and Pwn' exploit targets Windows Plug and Play to install malicious drivers and achieve SYSTEM privileges.
The popular ad blocker will no longer actively combat Facebook's ad delivery mechanisms, citing an unwinnable arms race.