Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries post, september 4, 2025september 5, 2025 The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new Microsoft Outlook backdoor called NotDoor in attacks targeting multiple companies from different sectors in NATO member countries. NotDoor “is a VBA macro for Outlook designed to monitor incoming emails for a specific trigger word,” S2 Grupo’s LAB52 threat intelligence team said…. Continue Reading
Internet Giant Cloudfare Confirms Breach: Hackers Access Customer Data Via Salesforce post, september 3, 2025september 4, 2025 Cloudflare is the latest to be impacted by the Salesloft Drift breach, which enabled an external actor to gain unauthorized access to their Salesforce environment. The attacker exfiltrated text fields from Salesforce case objects, which contained customer support communications and contact information. While no attachments or other Salesforce objects were… Continue Reading
Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s Response post, augustus 30, 2025september 4, 2025 Zscaler was made aware of a campaign targeted at Salesloft Drift (marketing software-as-a-service) and impacting a large number of Salesloft customers. This incident involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce to manage leads and contact… Continue Reading
Google Warns Salesloft Drift Breach Impacts All Drift Integrations Beyond Salesforce post, augustus 29, 2025september 4, 2025 Google has revealed that the recent wave of attacks targeting Salesforce instances via Salesloft Drift is much broader in scope than previously thought, stating it impacts all integrations. “We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially… Continue Reading
Onderzoek bewijst: smartphonegebruikers minder gevoelig voor phising post, augustus 29, 2025september 1, 2025 Onderzoek van de Carnegie Mellon University en de Ben-Gurion University wijst uit dat gebruikers van mobiele apparaten minder snel in phising-aanvallen trappen. Opvallend daarbij is dat dit niet komt omdat deze gebruikers de malafide links vaker herkennen. Continue Reading
The Scale of Russian Sabotage Operations Against Europe’s Critical Infrastructure post, augustus 22, 2025augustus 25, 2025 Russia is waging an unconventional war on Europe. Through its campaign of sabotage, vandalism, espionage and covert action, Russia’s aim has been to destabilise European governments, undermine public support for Ukraine by imposing social and economic costs on Europe, and weaken the collective ability of NATO and the European Union… Continue Reading
Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks post, augustus 21, 2025 Apple has released security updates to address a security flaw impacting iOS, iPadOS, and macOS that it said has come under active exploitation in the wild. The zero-day out-of-bounds write vulnerability, tracked as CVE-2025-43300, resides in the ImageIO framework that could result in memory corruption when processing a malicious image. Continue Reading
The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived post, augustus 14, 2025augustus 18, 2025 The breach of the US Courts records system came to light more than a month after the attack was discovered. Details about what was exposed—and who’s responsible—remain unclear. Continue Reading
Russian hackers took control of Norwegian dam, police chief says post, augustus 13, 2025september 1, 2025 The Norwegian Police Security Service suspects pro-Russian hackers sabotaged a dam in southwestern Norway in April. Norwegian daily newspaper VG reported that the hackers breached the dam’s control system, opening valves for four hours, sending large amounts of water gushing forth until the valves could be shut. Continue Reading
Russia Is Cracking Down on End-to-End Encrypted Calls post, augustus 13, 2025augustus 18, 2025 Russia has started restricting some Telegram and WhatsApp calls, accusing the foreign-owned platforms of failing to share information with law enforcement in fraud and terrorism cases, the digital development ministry said on Wednesday. Russia has clashed with foreign tech platforms for several years over content and data storage in a… Continue Reading