top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Klue Breach Exposes Salesforce Data Across Cybersecurity Vendors as Icarus Claims Attack
A breach at Klue has turned a market intelligence platform into the latest pressure point in a widening wave of SaaS supply chain attacks, after hackers used a compromised legacy credential to access customer-connected cloud environments and steal data from some of the cybersecurity industry’s most recognizable names. The Vancouver-based company, which provides competitive intelligence and market research tools, disclosed that attackers accessed its systems in June and obtain
Jun 24


Critical Shynet Flaw Let Attackers Turn Web Analytics Scripts Into a Sitewide Keylogger
A pair of security flaws in Shynet, the self-hosted web analytics platform used by developers and privacy-conscious website owners, shows how even lightweight tracking software can become a powerful attack surface when it sits inside the browser flow of multiple sites. Security researchers at Bishop Fox disclosed two vulnerabilities in Shynet version 0.13.1 that could allow unauthenticated attackers to compromise tracked websites or hijack user accounts. The most serious issu
Jun 24


Manufacturers Are Racing Into AI and Smart Factories. Cybersecurity Is Becoming the New Brand Test
U.S. manufacturers are moving fast into Industry 4.0, but the cyber risk is moving with them. A new report from Integris finds that manufacturers are rapidly adopting cloud infrastructure, AI, robotics, automation, and smart factory systems, even as many report serious security incidents across email, mobile devices, cloud environments, and databases. The findings suggest that the next phase of manufacturing competition will not be defined only by who can automate the fastest
Jun 24


DragonForce Ransomware Is Hiding in Microsoft Teams Traffic
A DragonForce ransomware attack has exposed a new problem for enterprise defenders: attackers are no longer just hiding behind disposable servers and shady domains. They are increasingly blending into the trusted cloud services companies rely on every day. Broadcom’s Symantec and Carbon Black threat hunters say they found a new Go-based backdoor, tracked as Backdoor.Turn, during an investigation into an attack on a U.S. services company. The malware is notable because it rout
Jun 17


Kodak Breach Adds to ShinyHunters’ Growing Data Extortion Wave
Eastman Kodak has confirmed it is investigating a data breach after the ShinyHunters extortion group claimed it stole more than 2.2 million records containing customer personally identifiable information and internal corporate data. Kodak said an unauthorized third party briefly accessed a limited amount of company data and that outside cybersecurity experts are helping determine what was accessed and copied. The company said it is working with law enforcement and does not be
Jun 17


Atomic Arch Supply Chain Attack Hits Arch Linux AUR With 1,500 Malicious Packages
A large-scale Linux supply chain attack has hit the Arch User Repository, exposing how quickly community package ecosystems can be turned into malware delivery networks when trust, automation and abandoned projects collide. The campaign, now tracked by researchers as Atomic Arch, began last week and had pushed more than 1,500 malicious packages into AUR by June 11. AUR is the community-maintained software hub used by Arch Linux users to share PKGBUILD scripts for software tha
Jun 16
bottom of page