Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust

Palo Alto Unit 42 research uncovered a fundamental flaw in the AI supply chain that allows attackers to gain Remote Code Execution (RCE) and additional capabilities on major platforms like Microsoft’s Azure AI Foundry, Google’s Vertex AI and thousands of Read More …

TransUnion says hackers stole 4.4 million customers’ personal information

Credit reporting giant TransUnion has disclosed a data breach affecting more than 4.4 million customers’ personal information. In a filing with Maine’s attorney general’s office on Thursday, TransUnion attributed the July 28 breach to unauthorized access of a third-party application Read More …

UK: Thousands of Afghans, troops and civil servants may be victims of new data breach

Some 3,700 Afghans, British troops and civil servants may have fallen victim to a new data breach, after an incident involving a company linked to the Ministry of Defence. Stansted-based Inflite The Jet Centre Ltd suffered a data security incident Read More …

Google says UNC6040 hackers stole some of its data following Salesforce breach

Cybercriminals known as ShinyHunters (UNC6040) recently broke into Google and stole business customer information from one of its corporate Salesforce instances, the company has confirmed. In a blog post breaking down ShinyHunters’ modus operandi, the company somewhat played down the Read More …

Malicious Packages Across Open-Source Registries: Detection Statistics and Trends (Q2 2025)

In this previous blog, Fortiguard Labs highlighted a growing trend in the use of open source software (OSS) repositories as channels for malware distribution in supply chain security. With the continued reliance on third-party packages in development workflows, threat actors Read More …

UK: Arrests made after M&S, Co-op and Harrods cyber attacks

Four people, including three teenagers and a 20-year-old woman, have been arrested in connection with a wave of cyber attacks that crippled M&S, the Co-op and Harrods. The group allegedly unleashed ransomware that stole millions of customer records, shut down Read More …

Cyberattack on Brazil tech provider affects reserve accounts of some financial institutions

Brazil’s central bank said on Wednesday that technology services provider C&M Software, which serves financial institutions lacking connectivity infrastructure, had reported a cyberattack on its systems. The bank did not provide further details of the attack, but said in a Read More …

M&S cyber attack deepens as tech partner TCS denies blame

Tata Consultancy Services (TCS), the tech firm at the centre of speculation around the M&S cyber attack, has claimed that none of its systems or users were compromised in the incident. The statement, delivered at the company’s annual shareholder meeting, Read More …

Jaw-dropping security flaws found in open source code could allow hackers to spirit away entire projects

Experts have revealed several critical vulnerabilities in GitHub Actions workflows which could pose serious risks to some major open source projects. A recent investigation by Sysdig’s Threat Research Team (TRT) has exposed how misconfigurations, particularly involving the pull_request_target trigger, could Read More …