Aggregator
Qilin
You must login to view this content
ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
Salesforce customers have, once again, been targeted by the ShinyHunters group – or, at least, it’s what the group claims. Attackers modified and abused benign tool On Saturday, Saleforce confirmed that its security team has identified an attack campaign by unnamed malicious actors looking to access customers’ data. The attackers are not leveraging a vulnerability in the Salesforce platform, the company said, but are using a modified version of the open-source tool Aura Inspector – … More →
The post ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites appeared first on Help Net Security.
Stretching Cyber Resources in Rural Healthcare
Medical Device Concerns for a Post-Quantum World
Webinar | No More Siloed Security: Aligning SecOps and GRC for Real Impact
How US Ransomware Policy Aims to Break Global Crime Networks
U.S. cyber policy now treats ransomware gangs and fraud networks as transnational criminal organizations. Former FBI cyber leader Cynthia Kaiser explains how sanctions, infrastructure takedowns, and international cooperation could weaken cybercrime ecosystems and reduce attacks.
BlackSanta Malware Shuts Down Protections, Targets HR and Recruiting Operations
Russian threat actors for more than a year have targeted HR and recruiting operations in a sophisticated phishing and infostealing campaign that includes a component, dubbed BlackSanta, that can shut down antivirus tools and EDR protections before deploying the malware that exfiltrates data, Aryaka researchers say.
The post BlackSanta Malware Shuts Down Protections, Targets HR and Recruiting Operations appeared first on Security Boulevard.
VMware security advisory (AV26-221)
Роботы больше не боятся упавшей гайки: ИИ-оракул учит станки предвидеть будущее на миллисекунды вперед
Google Chrome security advisory (AV26-220)
Intel security advisory (AV26-219)
[Control systems] Hitachi security advisory (AV26-218)
Medtech giant Stryker offline after Iran-linked wiper malware attack
Researchers uncover AI-powered vishing platform
A vishing-as-a-service platform that helps scammers carry out so-called “press 1” scams is misusing text-to-speech (TTS) capabilities provided by AI voice technology company ElevenLabs, Mirage Security researchers claim. How “press 1” vishing scams work For “press 1” scams, fraudsters spoof phone numbers of trusted institutions (e.g., bank), call up potential victims and try to scare them with pre-recorded messages into sharing sensitive information. When impersonating banks, for example, the fraudsters first play a message that … More →
The post Researchers uncover AI-powered vishing platform appeared first on Help Net Security.