More openness on the cards for Apple and Google’s mobile platforms
22
Oct
2025

More openness on the cards for Apple and Google’s mobile platforms

Following a nine-month investigation, the Competition and Markets Authority (CMA) has designated Google’s provision of its mobile platform with strategic…

CISA’s Joint Cyber Defense Collaborative takes major personnel hit
22
Oct
2025

CISA’s international, industry and academic partnerships slashed

The Trump administration has effectively closed the division of the Cybersecurity and Infrastructure Security Agency that coordinates critical infrastructure cybersecurity…

New Tykit Phishing Kit Mimics Microsoft 365 Login Pages to Steal Corporate Account Credentials
22
Oct
2025

New Tykit Phishing Kit Mimics Microsoft 365 Login Pages to Steal Corporate Account Credentials

A sophisticated phishing kit dubbed Tykit, which impersonates Microsoft 365 login pages to harvest corporate credentials. First detected in May…

Threat Actors Exploiting Azure Blob Storage to Breach Organizational Repositories
22
Oct
2025

Threat Actors Exploiting Azure Blob Storage to Breach Organizational Repositories

Threat actors are increasingly targeting Azure Blob Storage, Microsoft’s flagship object storage solution, to infiltrate organizational repositories and disrupt critical…

Attackers target retailers’ gift card systems using cloud-only techniques
22
Oct
2025

Attackers target retailers’ gift card systems using cloud-only techniques

A newly uncovered attack campaign mounted by suspected Morocco-based attackers has been hitting global retailers and other businesses issuing gift…

TARmageddon flaw in Async-Tar Rust library allows to smuggle extra archives when the library is processing nested TAR files
22
Oct
2025

TARmageddon flaw in Async-Tar Rust library allows to smuggle extra archives when the library is processing nested TAR files

TARmageddon flaw in Async-Tar Rust library allows to smuggle extra archives when the library is processing nested TAR files Pierluigi…

Card
22
Oct
2025

PhantomCaptcha ClickFix attack targets Ukraine war relief orgs

A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for…

Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts
22
Oct
2025

Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts

Since its emergence in August 2022, Lumma Infostealer has rapidly become a cornerstone of malware-as-a-service platforms, enabling even unskilled threat…

Take It from a Former Pen Tester: Zero-Days Aren’t the Problem. One-Days Are.
22
Oct
2025

Take It from a Former Pen Tester: Zero-Days Aren’t the Problem. One-Days Are.

Let’s set the record straight: the greatest risk to most companies isn’t breaking news. It’s known weaknesses that are left…

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters
22
Oct
2025

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters

Cybercriminals continue to evolve their email phishing arsenals, reviving legacy tactics while layering on advanced evasions to slip past automated…

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys
22
Oct
2025

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys

Oct 22, 2025Ravie LakshmananCryptocurrency / Software Integrity Cybersecurity researchers have uncovered a new supply chain attack targeting the NuGet package…

Atos boss ‘utterly determined’ not to allow GenAI to pull up career drawbridge
22
Oct
2025

Atos boss ‘utterly determined’ not to allow GenAI to pull up career drawbridge

Michael Herron, the UK head at French IT service provider Atos, has told Computer Weekly that ensuring future talent can…