Google Mandiant uncovers North Korea linked UNC1069 using AI generated lures, fake Zoom meetings, and multiple malware families to target cryptocurrency organizations on Windows and macOS.
Security leaders are rethinking Secure Service Edge deployments as real world risks emerge. Key questions highlight gaps around SaaS visibility, deployment friction, and operational cost.
SmarterTools confirms a Warlock ransomware breach caused by an unpatched SmarterMail server, impacting internal systems and hosted SmarterTrack customers while core services remained secure.
Cybersecurity researchers uncover a supply chain attack where compromised dYdX npm and PyPI packages distributed wallet-stealing malware and remote access trojans, exposing developers and crypto users to major risks.
Cisco fixes a critical zero-day RCE vulnerability in AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager exploited by China-linked APT UAT-9686, urging customers to apply updates and follow hardening guidelines.
A misconfiguration in AWS CodeBuild allowed potential takeover of GitHub repositories including aws-sdk-js-v3, exposing cloud environments to supply chain risks. AWS has since remediated the issue.
Anthropic introduces Claude for Healthcare, enabling Pro and Max subscribers to connect lab results and health records for summaries, insights, and appointment guidance while maintaining privacy and security.
IBM discloses critical CVE-2025-13915 vulnerability in API Connect allowing potential remote authentication bypass. Users are advised to apply interim fixes immediately.
Trust Wallet reveals Shai-Hulud supply chain attack compromised Chrome extension, stealing $8.5 million in crypto assets from 2,520 wallets. Users urged to update to version 2.69.
TRM Labs finds stolen encrypted vaults from the 2022 LastPass breach are still being cracked in 2025, enabling crypto theft linked to Russian cybercriminal exchanges.