Industry Spotlight

The Lock, Not the Alarm: How Palo Alto's Koi Acquisition Rewrites Endpoint Security

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

The acquisition of Koi Security isn’t just a product play — it’s a declaration that the agentic era has created an entirely new threat surface, and the vendor who governs it first will own the next decade of enterprise security. The Week That Rewrote the Threat Model One week after ... Read More
Use of XMRig Cryptominer by Threat Actors Expanding: Expel

Use of XMRig Cryptominer by Threat Actors Expanding: Expel

Security researchers last year wrote about a surge in the use by threat actors of the legitimate XMRig cryptominer, and cybersecurity firm Expel is now outlining the widening number of malicious ways they're deploying the open-source tool against corporate IT operations ... Read More
wormgpt, CaaS, Darktrace, Malware, cyberattacks, attacks, malware, environment data cyberattacks defend wiper hermeticwiper malware wiper file systems storage Zerologon

Malware Campaign Abuses Booking.com Against Hospitality Sector

Securonix is detailing a multi-stage campaign that starts with a bogus Booking.com message that runs through a ClickFix technique and a fake Blue Screen of Death before dropping the DCRat malware that gives the attackers full remote control of the victim's system ... Read More
Google Chrome Extension is Intercepting Millions of Users’ AI Chats

Google Chrome Extension is Intercepting Millions of Users’ AI Chats

A Chrome browser extension with 6 million users, as well as seven other Chrome and Edge extensions, for months have been silently collecting data from every AI chatbot conversion, packaging it, and then selling it to third parties like advertisers and data brokers, according to Koi Security ... Read More
National Public Data breach lawsuit

Hackers Steal Personal Data in 700Credit Breach Affecting 5.6 Million

A data breach of credit reporting and ID verification services firm 700Credit affected 5.6 million people, allowing hackers to steal personal information of customers of the firm's client companies. 700Credit executives said the breach happened after bad actors compromised the system of a partner company ... Read More
china, flax typhoon,

China Hackers Using Brickstorm Backdoor to Target Government, IT Entities

Chinese-sponsored groups are using the popular Brickstorm backdoor to access and gain persistence in government and tech firm networks, part of the ongoing effort by the PRC to establish long-term footholds in agency and critical infrastructure IT environments, according to a report by U.S. and Canadian security offices ... Read More
budget open source supply chain cybersecurity ransomware White House Cyber Ops

Cybersecurity Coalition to Government: Shutdown is Over, Get to Work

The Cybersecurity Coalition, an industry group of almost a dozen vendors, is urging the Trump Administration and Congress now that the government shutdown is over to take a number of steps to strengthen the country's cybersecurity posture as China, Russia, and other foreign adversaries accelerate their attacks ... Read More
stolen, credentials, file data, anomaly detection, data exfiltration, threat, inside-out, breach, security strategy, data breaches, data search, Exabeam, data, data breaches, clinical trials, breach, breaches, data, residency, sovereignty, data, breaches, data breaches, NetApp data broker FTC location data

Hack of SitusAMC Puts Data of Financial Services Firms at Risk

SitusAMC, a services provider with clients like JP MorganChase and Citi, said its systems were hacked and the data of clients and their customers possibly compromised, sending banks and other firms scrambling. The data breach illustrates the growth in the number of such attacks on third-party providers in the financial ... Read More
Google Uses Courts, Congress to Counter Massive Smishing Campaign

Google Uses Courts, Congress to Counter Massive Smishing Campaign

Google is suing the Smishing Triad group behind the Lighthouse phishing-as-a-service kit that has been used over the past two years to scam more than 1 million people around the world with fraudulent package delivery or EZ-Pass toll fee messages and stealing millions of credit card numbers. Google also is ... Read More
Human, risk, HRM, ISO/IEC 27001

Intel Sues Ex-Employee It Claims Stole 18,000 Company Files

Intel is suing a former employee who the chipmaker claims downloaded almost 18,000 corporate files days before leaving the company. The software engineer was told he was being let go effective July 31, likely part of Intel's larger effort to shed 15% of its workforce ... Read More