A phishing attack at healthcare vendor Xsolis exposed 1,396,519 patient records, with clients notified months after detection.
We break down the business associate risk and the controls that reduce it.
Read more: https://t.co/bSAdPBluLd
#CyberSecurity#Healthcare#HIPAA
An attacker registers a domain that an AI model is likely to hallucinate for a legitimate brand. The domain has no history, so reputation-based defences miss it completely. The model then surfaces it to users and agents as if it were the real thing.
We cover phantom squatting and its detection before registration.
Read more: https://t.co/l0mx2w5Zqm
#CyberSecurity #AISecurity #ThreatIntelligence
A single actor planted trojanised exploits across at least 7 fake CVE proof-of-concepts, hiding a credential-stealing RAT one dependency down where a quick review never looks.
We broke down the ChocoPoC delivery technique and provide controls that reduce exposure.
Read more: https://t.co/FmNMh9HDcw
#CyberSecurity #SupplyChain #AppSec #DevSecOps
Over 4,300 fraudulent FIFA-themed domains have been registered since August 2025, built to impersonate ticket sales, merchandise stores, and streaming platforms ahead of the tournament.
We examined the World Cup 2026 fraud campaign, from banking trojans to weak email authentication at official partners.
Read more: https://t.co/DK2oYvQVgk
#CyberSecurity #WorldCup2026 #ThreatAnalysis #Fintech
A Google DeepMind study of prompt injection in AI agents covered multiple attack vectors and participants.
We break down the attack patterns and outline what security teams should change.
Read more: https://t.co/IANCPWLAw4
#CyberSecurity#PromptInjection#AIAgents #ThreatAnalysis
A compromised third-party AI tool gave attackers 22 months of access to Vercel, exposing customer environment variables not marked as sensitive.
We analysed the OAuth supply chain attack chain, why platform env vars are a systemic risk, and what teams running on Vercel should do now.
Read more: https://t.co/xPcGoRwnYx
#Vercel #OAuth #SupplyChainAttack #CyberSecurity
https://t.co/2RobY0YBkV disclosed a breach of reservation data. No payment credentials, no government IDs. Yet the leaked records carry enough context to power high-conversion phishing.
We examined how reservation hijacking works.
Read more: https://t.co/OcjuDuZnIs
#CyberSecurity #DataBreach #ThreatAnalysis
3.65TB of data from Instructure's Canvas LMS is on a leak site, with claims of 275 million users affected and billions of student-teacher messages exposed.
We analysed the Instructure disclosure and what the identity-layer attack pattern requires of defenders.
Read more: https://t.co/wjJPqEGPcL
#DataBreach #ThreatIntel #CyberSecurity #ShinyHunters
The mean time from CVE disclosure to working exploit fell from 56 days in 2024 to 10 hours in 2026.
We analyzed the collapse and what defensive programmes need to look like at this tempo.
Read more: https://t.co/zBuMBzRaYe
#cybersecurity#CVE
Microsoft's emergency mitigation for the Exchange OWA zero-day breaks Print calendar, inline images, and the legacy OWA interface. It's also the only protection on offer five days into active exploitation of CVE-2026-42897.
We broke down the attack mechanics, the patching gap, and five controls that hold the window.
Read more: https://t.co/ttLolplcnv
#CyberSecurity #Exchange #ZeroDay #ThreatAnalysis
A compromised npm maintainer, weaponised by the Mini Shai-Hulud worm, pushed 637 malicious versions across 323 packages.
We broke down the forgery technique and provide controls that reduce exposure.
Read more: https://t.co/tPCfhS1Dn2
#CyberSecurity#SupplyChain#npm #ThreatAnalysis
Stripe keys, SSH credentials, cloud tokens, and database strings were harvested from hundreds of web servers through one unpatched vulnerability.
We analysed how UAT-10608 exploits React2Shell (CVE-2025-55182) and how to address this.
Read more: https://t.co/Z7RHCh8nK4
#CyberSecurity #React2Shell #NextJS #ThreatAnalysis
A threat actor with a confirmed breach history claims 3TB of data from Remita and Sterling Bank, including 800GB of KYC documents, databases, and source code.
We analysed the alleged attack path, the cloud security gaps, and what financial institutions should do now.
Read more: https://t.co/iD5NeXFtLB
#CyberSecurity #DataBreach #Fintech #CloudSecurity
Attackers compromised Trivy, an open-source vulnerability scanner, and turned it into a credential-harvesting tool. GitHub Action tags were silently poisoned, and npm packages were compromised.
We broke down the attack chain and what CI/CD teams should fix now.
Read more: https://t.co/U92QYJSoYi
#CyberSecurity #SupplyChainAttack #DevSecOps #InformationSecurity
45% of AI-generated code introduces security vulnerabilities. That number hasn't improved as models have gotten more capable.
We examined how vibe coding is creating exploitable gaps, from prompt injection to supply chain poisoning.
Read more: https://t.co/9h7gdzm1z4
#CyberSecurity #VibeCoding #AISecurity #AppSec
A ransomware attack delayed $17 million in pension payments to 2.9 million Kenyans. A separate attack took South Africa's Land Bank offline for two months.
Both incidents highlight gaps common across public sector institutions: unmonitored assets, limited pre-encryption detection, and inadequate disaster recovery.
Read more: https://t.co/IFG5JCsBEf
#InformationSecurity #CyberSecurity #ThreatDetection #Ransomware
In a single month, one fraud syndicate used 100 stolen faces to launch 160,000+ verification attacks across Africa's fintech platforms. Some faces appeared over 12,000 times.
We examined how injection attacks, deepfakes, and identity farming are breaking KYC.
Read more: https://t.co/A04l3V8UXT
#CyberSecurity #KYC #BiometricFraud #Fintech #InformationSecurity
A West African payment processor handling 6M+ monthly transactions lost over $1M to a 3-country coordinated fraud.
We broke down the gaps and what every fintech needs to know.
Read more: https://t.co/yLSiIbTf4S
#InformationSecurity#CyberSecurity#ThreatDetection#fintech
A single ransomware attack on a U.S. payment gateway knocked card processing offline for thousands of merchants, cities, and hospitality brands for 72+ hours.
We examined the timeline and what the detection window really looked like.
Read more: https://t.co/eJqQMttdqv
#InformationSecurity #CyberSecurity #ThreatDetection #Ransomware