Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is...
Read More
This newsletter is brought to you by Truffle Security, the makers of Trufflehog. You can subscribe to an audio version of this newsletter as a podcast by searching for “Risky Business” in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google...
Read More
ESET has released its SMB Cyber Readiness Index 2026, which found that 45% of small and medium-sized businesses experienced a cybersecurity incident in the past year. The report is based on responses from 4,400 cybersecurity decision-makers at businesses with 25 to 1,000 endpoints across 13 countries in North America, Europe and Asia. It found that...
Read More
Hackers took over famous Instagram accounts by tricking Meta’s AI support chatbot. The AI let them change account details without checking who they really were. This shows a big problem. Meta is trying to use AI to handle sensitive account tasks, but without enough human oversight. Here’s how the exploit worked and the steps you...
Read More
Ravie LakshmananJun 08, 2026Software Supply Chain / Malware Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats. “When automatic updates are enabled, new versions are auto-updated...
Read More
For many iPhone users, Apple’s “Find My” feature is a lifeline when a device goes missing. However, cybercriminals are now exploiting that trust by sending messages that appear to be part of the recovery process. Posing as Apple Support officials, scammers attempt to extract login credentials that can unlock cloud backups, personal photos, financial information,...
Read More
AI is changing the security landscape. More and more threat groups incorporate LLMs into their reconnaissance and exploitation workflows. The notion that some vulnerabilities are too complex to implement is now obsolete. Using LLMs, hackers can automatically find and exploit complex vulnerabilities. We have all heard of Claude Mythos and its ability to identify vulnerabilities...
Read More
The Greater Rochester Chamber of Commerce is excited to announce an upcoming session it its new Skill Up! Series, an educational program designed to support business growth and professional development within the Greater Rochester business community. The Skill Up! Series features sessions led by local business experts, providing insights into practical and timely topics relevant...
Read More
Summary The Gentlemen ransomware group has been active since July 2025 and follows a double-extortion model, combining file encryption with data theft and leak-site extortion. The malware is written in Go, supports Windows, Linux, and ESXi environments, and uses a hard-coded password argument during the encryption process. Operators also rely on broad reconnaissance, abuse of...
Read More
For the second time in just over two months, hackers are trying to infiltrate Signal accounts–this time by posing as the free messaging app’s support team in an attempt to gain access to private messages, photos, and files. “It’s not clear how effective the hacking campaign has been,” reports TechCrunch, an online industry news site....
Read More
1 282 283 284 285 286 1,506
National Cyber Security

FREE
VIEW