top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Chick-fil-A Customer Accounts Hacked in Credential Stuffing Attack
Chick-fil-A is notifying customers that hackers accessed their loyalty accounts during an automated credential stuffing campaign targeting the company’s website and mobile app. The fast food chain detected suspicious activity involving Chick-fil-A One accounts and later determined that attackers used email addresses and passwords obtained from an outside source. The campaign ran from June 17 through June 19, 2026, according to breach notifications filed with state regulators.
Jul 22


North Korean Hackers Use Fake Job Interviews to Infect Windows and Macs
North Korean hackers are targeting cryptocurrency and Web3 professionals with fake job interviews that install remote access malware on Windows and macOS computers. Researchers at SOCRadar linked the campaign to Famous Chollima, also known as Wagemole. The group poses as recruiters, impersonates legitimate companies and directs victims to convincing online skills assessments. The sites collect personal information, present job-specific questions and pressure candidates with c
Jul 20


Hugging Face Breach Shows How AI Datasets Can Become a Cyberattack Vector
The AI platform says attackers turned a malicious dataset into an entry point for stealing credentials and moving through its internal systems. The incident raises new questions about AI supply chain security, autonomous hacking tools, and whether defenders can keep pace with machine-speed attacks. Hugging Face has disclosed a cybersecurity breach that exposed internal datasets and service credentials after attackers allegedly weaponized a dataset uploaded to its widely used
Jul 20


Underground Hacker Tutorials Are Becoming an Early Warning System for Defenders as AI Fuels a New Wave of Cybercrime
Threat intelligence teams have long monitored ransomware groups, malware marketplaces, and dark web chatter for signs of emerging cyber threats. A new report from Radware suggests security teams may be overlooking another valuable source of intelligence: the underground tutorials where cybercriminals teach one another how to attack organizations. After analyzing nearly 9,000 tutorial posts published across 24 deep and dark web forums over more than three years, Radware resear
Jul 13


AI-Generated PowerShell Script Helps Threat Actor Accelerate Active Directory Reconnaissance
Artificial intelligence is increasingly becoming an operational advantage for cybercriminals, and a newly documented intrusion demonstrates how attackers are using AI-generated code to speed up familiar attack techniques rather than invent new ones. Researchers at Huntress uncovered an intrusion in which an unidentified threat actor deployed what appears to be a large language model-generated PowerShell script to perform extensive Active Directory reconnaissance after gaining
Jul 13


KDDI Cyberattack Exposes 12 Million Email Addresses and 7.6 Million Passwords in Japan ISP Breach
A cyberattack on an email platform operated by Japanese telecom giant KDDI exposed more than 12.2 million customer email addresses and 7.6 million passwords, marking one of the larger recent credential exposure incidents tied to shared internet service provider infrastructure in Japan. KDDI said the breach affected an email system it runs for five Japanese internet service providers. The platform supports customer email account management, webmail access and email storage. Th
Jul 7
bottom of page