top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


GhostCode Phishing Kit Targets Microsoft Accounts Through OAuth Device Codes
A new phishing campaign is exploiting Microsoft’s device authentication process to hijack accounts, giving attackers a way to bypass traditional multifactor authentication protections. Researchers at eSentire have named the phishing kit “GhostCode.” The campaign begins when attackers submit messages through corporate website contact forms while impersonating procurement representatives from legitimate organizations. These messages are designed to establish trust and steer emp
Sep 16


Veradigm Data Breach Exposes Patient Social Security Numbers Through Vendor API
Healthcare technology provider Veradigm has disclosed a data breach in which attackers used credentials stolen from a third-party vendor to access and copy sensitive patient information. The Chicago-based company, formerly known as Allscripts Healthcare Solutions, said the incident affected a limited number of customers and did not disrupt its operations. Veradigm supplies electronic health record, e-prescribing, patient engagement, practice management, and revenue cycle soft
Sep 13


ShieldCrash Exploit Reportedly Bypasses Microsoft’s Windows Defender ShieldBreak Fix
A newly released proof-of-concept exploit suggests Microsoft’s September 2026 security update may not have fully resolved ShieldBreak, a Windows Defender vulnerability that can allow attackers to access sensitive files with SYSTEM privileges. Security researcher Nightmare Eclipse published the new exploit, called ShieldCrash, on GitHub only days after Microsoft issued its ShieldBreak fix. According to the researcher, the proof of concept can read arbitrary files with the high
Sep 13


Fake Job Offers Deliver Fileless Malware Through Two Advanced Attack Chains
Cybercriminals are disguising sophisticated malware campaigns as routine recruiting outreach, using fake job descriptions and interview documents to compromise Windows computers with a single click. New research from Cyderes’ Howler Cell threat intelligence team details two separate nine-stage attack chains that exploit the trust surrounding online recruitment. Although the campaigns appear to involve different operators, both use fileless malware, hidden persistence and secu
Sep 13


EU Cyber Resilience Act Starts 24-Hour Security Reporting Clock
Manufacturers selling connected hardware and software in the European Union now face strict cybersecurity reporting deadlines under the EU Cyber Resilience Act. The requirements took effect on September 11, 2026, and apply to manufacturers of “products with digital elements” made available in the EU, including companies headquartered outside the bloc. Covered businesses must report actively exploited vulnerabilities and severe security incidents affecting their products throu
Sep 13


Florida DMV Data Breach Raises New Fears Over Driver’s License Security
Florida officials are investigating a cyberattack against the state agency responsible for driver and vehicle records, marking the second reported breach involving Americans’ driver’s license data this month. The Florida Department of Highway Safety and Motor Vehicles said an international cybercriminal organization carried out the attack. The agency said it has contained the breach and is working with law enforcement, but has not disclosed what information was accessed, how
Sep 13
bottom of page