Whole Foods supplier UNFI restores core systems after cyberattack post, juni 27, 2025 American grocery wholesale giant United Natural Foods (UNFI) reports that it has restored its core systems and brought online the electronic ordering and invoicing systems affected by a cyberattack. UNFI, which is also a primary distributor for Amazon’s Whole Foods, said in a Thursday update that the incident has been contained and… Continue Reading
Beware the Hidden Risk in Your Entra Environment post, juni 25, 2025juni 27, 2025 A gap in access control in Microsoft Entra’s subscription handling is allowing guest users to create and transfer subscriptions into the tenant they are invited into, while maintaining full ownership of them. All the guest user needs are the permissions to create subscriptions in their home tenant, and an invitation… Continue Reading
WhatsApp verboden op telefoons Amerikaanse Huis van Afgevaardigden post, juni 23, 2025juni 24, 2025 Berichtendienst WhatsApp wordt per direct verboden op alle elektronische communicatiemiddelen van het Amerikaanse Huis van Afgevaardigden. Dat meldt de cybersecuritydienst van het Huis. De dienst maakt zich al langer zorgen over de cyberveiligheid. Werknemers is verzocht de app te verwijderen en een alternatief te gebruiken zoals Signal of FaceTime. Leden… Continue Reading
China Is Studying How to Hack and Crash Our Power Grids post, juni 19, 2025juni 23, 2025 Over the past several weeks, I’ve been conducting a large-scale bibliometric study on publicly available Chinese academic literature related to hacking and crashing Western power grids. In this article, I’m sharing the main findings of that study. EDIT (20.6.2025, 8:54 CET): All of the Chinese academic articles I examined are… Continue Reading
Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool post, juni 12, 2025juni 13, 2025 Cybersecurity researchers have uncovered a new account takeover (ATO) campaign that leverages an open-source penetration testing framework called TeamFiltration to breach Microsoft Entra ID (formerly Azure Active Directory) user accounts. The activity, codenamed UNK_SneakyStrike by Proofpoint, has targeted over 80,000 user accounts across hundreds of organizations’ cloud tenants since a surge in… Continue Reading
Google Cloud and Cloudflare hit by widespread service outages post, juni 12, 2025juni 13, 2025 Update June 12, 17:41 EDT: In new updates, Cloudflare said that all services have been restored and are now fully operational, while Google stated it expects “recovery to complete in less than an hour.” Update June 12, 15:29 EDT: Cloudflare says its services were impacted by Google Cloud’s outage. “This is a Google Cloud… Continue Reading
Scattered Spider: Three things the news doesn’t tell you post, juni 3, 2025 With the recent attacks on UK retailers Marks & Spencer and Co-op, so-called Scattered Spider has been all over the media, with coverage spilling over into the mainstream news due to the severity of the disruption — currently looking like hundreds of millions in lost profits for M&S alone. This… Continue Reading
Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion post, juni 3, 2025 Microsoft and CrowdStrike have announced that they are teaming up to align their individual threat actor taxonomies by publishing a new joint threat actor mapping. “By mapping where our knowledge of these actors align, we will provide security professionals with the ability to connect insights faster and make decisions with… Continue Reading
Tsjechië: China zit achter cyberaanval op ministerie van Buitenlandse Zaken post, mei 28, 2025juli 3, 2025 Tsjechië houdt een Chinese groep hackers verantwoordelijk voor een cyberaanval op het ministerie van Buitenlandse Zaken. Volgens de Tsjechen gaat het om een “kwaadaardige cybercampagne”, gericht op een netwerk dat gebruikt werd voor niet-geheime communicatie. Het land stelt dat de aan China gelinkte groep APT31 daar vermoedelijk achter zit. Die… Continue Reading
Een op de vijf bedrijven had vorig jaar schade door cybercriminaliteit post, mei 21, 2025 Veel meer bedrijven dan gedacht ondervinden schade door cybercriminaliteit. Een op de vijf bedrijven had vorig jaar jaar schade. Bij grote bedrijven was dat bijna 30 procent, zegt ABN Amro, dat onderzoek deed naar de impact van cyberaanvallen op het Nederlandse bedrijfsleven. Uit het onderzoek blijkt ook dat bedrijven zelf de risico’s nog… Continue Reading