Phishing attack abuses QR codes to bypass FIDO keysLaura FrenchJuly 17, 2025A man-in-the-middle attack relays a cross-device sign-in mechanism via a fake login site.
MalwareMicrosoft Teams phishing spreads updated Matanbuchus malware loaderMatanbuchus 3.0 adds greater stealth and execution capabilities, and could lead to ransomware.
Network SecurityChina-linked Salt Typhoon infiltrated state National Guard networkSecurity officials touted victory over a second China-linked group on critical infrastructure networks.
DevOps67 malicious npm packages, novel loader spread North Korean malwarePackages that load BeaverTail malware were downloaded more than 17,000 times.
IdentityStolen identities a fear after Episource breach affects 5.4M patientsIn letter to customers, Episource said that the sensitive healthcare data potentially stolen.
MalwareNordDragonScan infostealer targets Windows with LOTL methodsThe campaign distracts victims from its malicious nature using benign decoy documents.
Application securityCatWatchful stalkerware breach reveals 62K users, 26K victimsAn SQL injection exploit exposed the users and owner of CatWatchful stalkerware.
RansomwareUS sanctions ‘bulletproof’ hosting provider Aeza for cybercrime opsRussia-based bulletproof hosting (BPH) service offers no-questions-asked access to servers.
AI/MLIncorrect links output by LLMs could lead to phishing, researchers sayAI models may fail to recognize social engineering content in training data and searches.
BreachQantas confirms cyberattack on third-party call center appWhile not confirmed, security pros say the attack resembles recent attacks on airlines and retailers by Scattered Spider.
RansomwareDragonForce ransomware variant tied to emerging DEVMAN threat actorThe ransomware sample contained “oddities” including encryption of its own ransom note.