New ransomware claim: Anubis group added US law firm Community Advocates to their leak site (July 12, 2026), stating client personal data was exposed. Another reminder that law firms remain prime targets for cybercriminals. If you worked with them, monitor for notifications and potential identity risks. #Ransomware #Anubis #DataBreach #LawFirmSecurity #CyberThreat
Major US law firm breach: Blank Rome exposed personal data of over 57,000 clients after a social engineering attack in May 2026. Hackers posed as IT support and tricked an attorney into uploading files. Exposed: Names, SSNs, addresses, birthdates & more. Multiple class-action lawsuits now filed. Stay vigilant if you’re a current/former client. #DataBreach #BlankRome #CyberAttack #LegalTech #Privacy
There has been a data breach involving a Canadian legal firm specializing in defending against traffic tickets and criminal charges. https://t.co/WRzYC3AVoh
🚨 UPDATE - A year after researchers flagged them, 3 popular free #Android VPN apps still let an attacker on your Wi-Fi silently reroute your "encrypted" traffic.
All 5 are still on the Play Store.
Google told @TheHackersNews that it takes such claims seriously but wouldn't say whether it will act.
Read: https://t.co/5XjexcKzC4
🛑 A new #Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk.
It poisons the cached copy of /bin/su in memory. The binary on disk stays untouched. File-integrity checks come back clean.
The root shell is already open.
Details here ↓ https://t.co/y2FDVjcSEq
For small businesses: Ransomware frequently targets SMBs due to weaker defenses; 43% of cyberattacks hit small businesses historically. Recovery costs and downtime can be devastating, with many closing within months of a major incident. Patching, segmentation, and vendor vetting are critical.
Ransomware activity surged (e.g., +48% in some reports for May), with attacks on diverse sectors including healthcare, education (e.g., Instructure/Canvas affecting millions of records), and critical operations. Supply chain and third-party risks remain a top concern, as seen in vendor compromises impacting downstream organizations.
Link to the articla 👇
#cybersecuritytips
For small businesses: These highlight risks from weak access controls, vendor dependencies, and human factors. Many SMBs rely on similar cloud services and have limited monitoring, making them vulnerable to quick compromise without advanced breaches.
In May-June 2026, most major incidents involved attackers using stolen or socially engineered credentials rather than exploiting technical vulnerabilities. Examples include help desk social engineering, phishing for SSO tokens, and inherited vendor access leading to large-scale data exfiltration from SaaS/CRM platforms like Salesforce and Microsoft 365. ShinyHunters continued extortion campaigns targeting these systems.
https://t.co/Gzx8BT1qOD
⚠️ Microsoft says 35,000 users were targeted in an April 2026 phishing campaign across 13,000 organizations in 26 countries.
Attackers used AiTM phishing, CAPTCHA pages, and trusted email services to steal credentials and bypass MFA.
Full story: https://t.co/86uHRxPV8J