top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


KDDI Cyberattack Exposes 12 Million Email Addresses and 7.6 Million Passwords in Japan ISP Breach
A cyberattack on an email platform operated by Japanese telecom giant KDDI exposed more than 12.2 million customer email addresses and 7.6 million passwords, marking one of the larger recent credential exposure incidents tied to shared internet service provider infrastructure in Japan. KDDI said the breach affected an email system it runs for five Japanese internet service providers. The platform supports customer email account management, webmail access and email storage. Th
5 days ago


China-Linked Hackers Target University Physics Departments in Roundcube Espionage Campaign
A previously unknown espionage group believed to be operating on behalf of China is targeting physics and engineering departments at universities in the United States and Canada, with a particular focus on research tied to national security, astrophysics, and particle physics. Security researchers at Proofpoint are tracking the activity as UNK_MassTraction. The group is exploiting a chain of vulnerabilities in Roundcube, a widely used open-source webmail platform, to steal cr
5 days ago


CrySome RAT Campaign Turns a Fake Freight Document Into a Full Remote Access Breach
A logistics-themed phishing campaign recently pushed the CrySome remote access trojan through a multi-stage Windows infection chain, showing how attackers are blending believable business lures, native system tools, open-source security-disabling utilities, and modular malware to gain persistent control of victim machines. Researchers with LevelBlue’s SpiderLabs said the incident began with a targeted spear-phishing email disguised as a freight rate confirmation. The message
6 days ago


Russian Hackers Bypass Signal and WhatsApp Encryption by Targeting Backup Keys
Russian military-linked hackers are intensifying phishing campaigns against Signal and WhatsApp users, not by breaking encryption, but by convincing targets to hand over account recovery details that can unlock private messages and group chats. A new alert from the FBI and the U.S. Cybersecurity and Infrastructure Security Agency warns that Russian intelligence services are posing as automated support bots for commercial messaging apps. The campaigns are aimed at high-value t
Jun 29


OpenAI Expands GPT-5.5-Cyber as AI Pushes Vulnerability Patching Into a New Era
OpenAI is expanding access to an improved version of GPT-5.5-Cyber, giving trusted defenders a more powerful AI model for finding, validating, and helping patch software vulnerabilities. The release is part of OpenAI’s Daybreak initiative and comes as AI is rapidly changing vulnerability research. The company says GPT-5.5-Cyber can analyze large codebases, identify security issues, validate findings in controlled environments, and generate patches for human review. OpenAI is
Jun 24


NCC Group Warns Ransomware, State Hackers, and AI Fraud Tools Are Colliding
Ransomware activity in May 2026 remained stuck at historically high levels, even as attacks dipped slightly month over month, according to a new cyber threat intelligence report from NCC Group and Fox-IT. The report recorded 749 ransomware victim listings in May, a 4 percent decline from the previous month but still part of an elevated 2026 baseline. Industrial organizations were hit hardest, accounting for 29 percent of ransomware attacks. Qilin remained the most active rans
Jun 24
bottom of page