top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Chick-fil-A Customer Accounts Hacked in Credential Stuffing Attack
Chick-fil-A is notifying customers that hackers accessed their loyalty accounts during an automated credential stuffing campaign targeting the company’s website and mobile app. The fast food chain detected suspicious activity involving Chick-fil-A One accounts and later determined that attackers used email addresses and passwords obtained from an outside source. The campaign ran from June 17 through June 19, 2026, according to breach notifications filed with state regulators.
Jul 22


ThreatDown Targets Shadow AI and Risky Machine Identities With New Security Tools
ThreatDown is expanding its cybersecurity platform to help organizations uncover unauthorized artificial intelligence tools and secure the growing number of machine identities operating across corporate networks. The company’s new AI visibility capabilities automatically identify shadow AI applications used by employees without formal approval. Security teams can view each tool’s vendor, category, version, platform and endpoint activity, helping them determine where corporate
Jul 22


Employees Think They Can Spot AI Payment Fraud. They May Be Wrong
U.S. employees are confident they can recognize fraudulent payment requests, but many are still relying on warning signs that generative AI can easily eliminate. A Trustmi survey of 1,000 U.S. workers involved in payment-related processes found that 78 percent believe they could identify a fraudulent request. Yet 70 percent said their top warning signs are typos, grammatical errors or unusual fonts. That creates a significant blind spot as attackers use AI to produce polished
Jul 22


North Korean Hackers Use Fake Job Interviews to Infect Windows and Macs
North Korean hackers are targeting cryptocurrency and Web3 professionals with fake job interviews that install remote access malware on Windows and macOS computers. Researchers at SOCRadar linked the campaign to Famous Chollima, also known as Wagemole. The group poses as recruiters, impersonates legitimate companies and directs victims to convincing online skills assessments. The sites collect personal information, present job-specific questions and pressure candidates with c
Jul 20


Hugging Face Breach Shows How AI Datasets Can Become a Cyberattack Vector
The AI platform says attackers turned a malicious dataset into an entry point for stealing credentials and moving through its internal systems. The incident raises new questions about AI supply chain security, autonomous hacking tools, and whether defenders can keep pace with machine-speed attacks. Hugging Face has disclosed a cybersecurity breach that exposed internal datasets and service credentials after attackers allegedly weaponized a dataset uploaded to its widely used
Jul 20


Pentagon Pauses CMMC Phase 2 as Defense Contractors Face New Compliance Uncertainty
The Pentagon has halted the next stage of its Cybersecurity Maturity Model Certification rollout, delaying a major expansion of independent cybersecurity audits for companies working across the defense supply chain. The Defense Department announced July 13 that it is suspending CMMC Phase 2, which had been scheduled to begin November 10, 2026. The phase would have significantly increased the number of contracts requiring assessments conducted by certified third-party organiza
Jul 14
bottom of page