Investigation into a possible data security incident has been launched by Nike after the WorldLeaks extortion group allegedly stole and exposed 1.4 TB of data obtained from the footwear and apparel giant's systems, Security Affairs reports.
Developers have had their data exfiltrated to China-based servers by a pair of illicit Microsoft Visual Studio Code extensions purporting to be AI-based coding assistants as part of the MaliciousCorgi campaign, BleepingComputer reports.
This incident, linked to a fraud indictment in Guam involving pandemic unemployment benefits, marks the first publicly known instance of Microsoft sharing BitLocker keys.
Cybercriminals are exploiting the tax season to perpetrate scams, primarily through text messages and emails that falsely claim a tax refund is due or that back taxes are owed.
The newly cataloged vulnerabilities include an improper access control flaw in Vitejs (CVE-2025-31125), an improper authentication bypass in Versa Concerto SD-WAN (CVE-2025-34026), a supply-chain compromise in eslint-config-prettier (CVE-2025-54313), and a PHP remote file inclusion vulnerability in Synacor Zimbra Collaboration Suite (CVE-2025-68645).
Segment 1: Interview with Thyaga Vasudevan. Hybrid by Design: Zero Trust, AI, and the Future of Data Control. AI is reshaping how work gets done, accelerating decision-making and introducing new ways for data to be created, accessed, and shared. As a result, organizations must evolve Zero Trust beyond an access-only model into an inline data govern...
Under Armour had 72 million email addresses stolen by the Everest ransomware gang in a November attack published to the Have I Been Pwned website earlier this week, according to TechRepublic.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.