Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: 2025

Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries

post, september 4, 2025september 5, 2025

The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new Microsoft Outlook backdoor called NotDoor in attacks targeting multiple companies from different sectors in NATO member countries. NotDoor “is a VBA macro for Outlook designed to monitor incoming emails for a specific trigger word,” S2 Grupo’s LAB52 threat intelligence team said….

Continue Reading

Internet Giant Cloudfare Confirms Breach: Hackers Access Customer Data Via Salesforce

post, september 3, 2025september 4, 2025

Cloudflare is the latest to be impacted by the Salesloft Drift breach, which enabled an external actor to gain unauthorized access to their Salesforce environment. The attacker exfiltrated text fields from Salesforce case objects, which contained customer support communications and contact information. While no attachments or other Salesforce objects were…

Continue Reading

Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s Response

post, augustus 30, 2025september 4, 2025

Zscaler was made aware of a campaign targeted at Salesloft Drift (marketing software-as-a-service) and impacting a large number of Salesloft customers. This incident involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce to manage leads and contact…

Continue Reading

Google Warns Salesloft Drift Breach Impacts All Drift Integrations Beyond Salesforce

post, augustus 29, 2025september 4, 2025

Google has revealed that the recent wave of attacks targeting Salesforce instances via Salesloft Drift is much broader in scope than previously thought, stating it impacts all integrations. “We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially…

Continue Reading

Onderzoek bewijst: smartphonegebruikers minder gevoelig voor phising

post, augustus 29, 2025september 1, 2025

Onderzoek van de Carnegie Mellon University en de Ben-Gurion University wijst uit dat gebruikers van mobiele apparaten minder snel in phising-aanvallen trappen. Opvallend daarbij is dat dit niet komt omdat deze gebruikers de malafide links vaker herkennen.

Continue Reading

The Scale of Russian Sabotage Operations Against Europe’s Critical Infrastructure

post, augustus 22, 2025augustus 25, 2025

Russia is waging an unconventional war on Europe. Through its campaign of sabotage, vandalism, espionage and covert action, Russia’s aim has been to destabilise European governments, undermine public support for Ukraine by imposing social and economic costs on Europe, and weaken the collective ability of NATO and the European Union…

Continue Reading

Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks

post, augustus 21, 2025

Apple has released security updates to address a security flaw impacting iOS, iPadOS, and macOS that it said has come under active exploitation in the wild. The zero-day out-of-bounds write vulnerability, tracked as CVE-2025-43300, resides in the ImageIO framework that could result in memory corruption when processing a malicious image.

Continue Reading

The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived

post, augustus 14, 2025augustus 18, 2025

The breach of the US Courts records system came to light more than a month after the attack was discovered. Details about what was exposed—and who’s responsible—remain unclear.

Continue Reading

Russian hackers took control of Norwegian dam, police chief says

post, augustus 13, 2025september 1, 2025

The Norwegian Police Security Service suspects pro-Russian hackers sabotaged a dam in southwestern Norway in April. Norwegian daily newspaper VG reported that the hackers breached the dam’s control system, opening valves for four hours, sending large amounts of water gushing forth until the valves could be shut.

Continue Reading

Russia Is Cracking Down on End-to-End Encrypted Calls

post, augustus 13, 2025augustus 18, 2025

Russia has started restricting some Telegram and WhatsApp calls, accusing the foreign-owned platforms of failing to share information with law enforcement in fraud and terrorism cases, the digital development ministry said on Wednesday. Russia has clashed with foreign tech platforms for several years over content and data storage in a…

Continue Reading
  • Previous
  • 1
  • …
  • 4
  • 5
  • 6
  • …
  • 16
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes