One Attacker Scrapes Salesforce and ServiceNow Portals Since 2025
A single threat actor has been systematically scraping data from Salesforce and ServiceNow customer portals for over a year, according to research…
A single threat actor has been systematically scraping data from Salesforce and ServiceNow customer portals for over a year, according to research…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
[ShinyHunters](https://attack.mitre.org/groups/G1057) is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. [ShinyHunters](https://attack.mitre.org/groups/G1057) has targeted…
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche technique…
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on July…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
A sophisticated threat actor tracked as O-UNC-066 by Okta is targeting organizations across multiple sectors with a voice-based phishing (vishing) scheme that…
The Com is a decentralized cybercrime collective that includes subgroups such as Scattered Spider, ShinyHunters, and LAPSUS$. Members of The Com have…
A critical security flaw in Oracle E-Business Suite, tracked as CVE-2026-46817 (CVSS 9.8), is now actively exploited in the wild. The vulnerability,…
The ShinyHunters extortion crew exploited an unpatched remote code execution vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach enterprise systems, primarily targeting universities.…