top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Atomic Arch Supply Chain Attack Hits Arch Linux AUR With 1,500 Malicious Packages
A large-scale Linux supply chain attack has hit the Arch User Repository, exposing how quickly community package ecosystems can be turned into malware delivery networks when trust, automation and abandoned projects collide. The campaign, now tracked by researchers as Atomic Arch, began last week and had pushed more than 1,500 malicious packages into AUR by June 11. AUR is the community-maintained software hub used by Arch Linux users to share PKGBUILD scripts for software tha
Jun 16


Databricks Moves to Buy Panther as AI Reshapes the Security Operations Center
Databricks is moving deeper into cybersecurity with plans to acquire Panther, an AI-focused security operations platform built around detection-as-code, cloud-native telemetry, and automated SOC workflows. The deal would strengthen Databricks’ push into what it calls the security lakehouse, a model meant to challenge traditional SIEM platforms by bringing security, IT, cloud, identity, and business data into one governed analytics environment. The company’s thesis is straight
Jun 16


Why Executive Impersonation Is Becoming Harder To Detect - And What To Do About It
This guest post was contributed by Amit Shuster, VP Product, Vetric.io Cybercriminals have always targeted senior executives. What's changed is how effectively they can now impersonate them. Deepfake technology has matured to the point where an AI-generated video of a CEO endorsing a fraudulent investment scheme, or an audio clone directing an employee to wire funds, can be nearly indistinguishable from the real thing. Deloitte estimates deepfake-enabled fraud losses could r
Jun 11


GreatXML Windows Zero-Day Turns Defender Offline Scan Into a BitLocker Backdoor
The post-compromise technique abuses Windows Recovery Environment to create persistent access to BitLocker-encrypted data, with no patch currently available. According to the Cyderes Howler Cell team, a newly disclosed Windows zero-day called GreatXML can turn Microsoft Defender’s offline scanning process into a pathway for accessing BitLocker-encrypted data without a recovery key or user credentials. The technique targets the interaction between Windows Recovery Environment,
Jun 11


Kali365 Phishing Platform Turns Microsoft Logins Into an AI-Powered Fraud Pipeline
The phishing-as-a-service operation uses Microsoft device codes, stolen authentication tokens and AI-generated business email compromise messages to help attackers bypass traditional account defenses. A newly analyzed phishing platform known as Kali365 is giving cybercriminals an unusually complete toolkit for compromising Microsoft 365 accounts and converting stolen access into financial fraud. Huntress researchers uncovered the operation after detecting a spike in device co
Jun 11


University of Nottingham Cyberattack Exposes Student Financial and Personal Data
Hackers accessed a significant amount of personal data belonging to University of Nottingham students and alumni, potentially including financial records, National Insurance numbers and protected characteristics. The university detected unauthorized activity in its Campus Solutions student records system on Tuesday and took affected systems offline. It has contacted impacted individuals and reported the incident to Action Fraud, the Information Commissioner’s Office and other
Jun 10
bottom of page