Threat actors have been able to continuously conduct cryptocurrency heists using encrypted vault backups pilfered in a cyberattack against LastPass three years ago, Security Affairs reports.
IT Brew reports that a concerning and scalable social engineering threat dubbed "payroll pirate" attacks is targeting corporate help desks to hijack employee pay.
A highly sophisticated and industrialized cybercrime operation is threatening the 2025 holiday shopping season with a massive network of fraudulent retail websites, Cyber Security News reports.
Over 1,800 suspected North Korean scammers had their attempts to obtain remote IT work at Amazon quashed since April 2024 as the firm recorded a 27% quarter-over-quarter increase in North Korea-linked job applications, The Register reports.
BleepingComputer reports that automated credential-based intrusions were launched against Palo Alto Networks GlobalProtect and Cisco SSL VPN instances last week.
The UK's Information Commissioner's Office issued a 1.2 million penalty to password management company LastPass' British subsidiary following a 2022 security breach, reports The Record, a news site by cybersecurity firm Recorded Future.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.