ShinyHunters and ReliaQuest trade blows over claimed breach

ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew’s social engineering attack only got as far as one employee identity before its defenses slammed the door. The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site Read More …

Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring

Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains. WordPress currently Read More …

Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants

Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems. The breach comes a month after security researchers sounded the alarm on a new hacking campaign Read More …

Securing the overlooked corners of the Software Development Lifecycle (SDLC) supply chain

While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are Read More …

Zombie Card: An expired Visa credit card can be used for purchases

Did you know there is still a good reason to physically destroy your expired credit card? Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering. University of Massachusetts Amherst researchers Read More …

The invisible passenger in your car

While monitoring Android threats in June 2026, Kaspersky discovered a new piece of Android malware. What struck the researchers as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: Read More …

Hackers are spending millions on expired domains to enable malware scams

A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about. New research from Read More …

Medical records, SSNs, and bank details exposed in CareCloud data breach

Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year. The New Jersey-based company, which provides electronic health record (EHR) and Read More …

Identity abuse through trusted communication channels

Identity has become a primary security boundary for most organizations, reducing the ability to solely trust other boundaries once associated with corporate networks. Users authenticate to cloud services using enterprise identities that provide access to collaboration platforms, business applications and Read More …

CareCloud confirms 3.7M patients had their medical records stolen in data breach

Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale Read More …