Substack Confirms Security Breach Involving User Data

Substack has revealed that an unauthorized party accessed user contact information months before detection, impacting email addresses and phone numbers.

Substack has revealed that an unauthorized party accessed user contact information months before detection, impacting email addresses and phone numbers.

A new cyber campaign, codenamed RedKitten, has emerged, targeting NGOs and individuals documenting human rights abuses in Iran. This operation is linked to a Farsi-speaking threat actor aligned with Iranian state interests.

This week's cybersecurity updates highlight significant incidents and vulnerabilities affecting various platforms and services.

A sophisticated phishing campaign has been identified, targeting users in Russia with ransomware and a remote access trojan known as Amnesia RAT. The attack employs social engineering tactics and multiple cloud services to distribute malicious payloads.

Google security leaders discuss the evolving landscape of cyber threats driven by AI, highlighting the potential for automated cyberattacks and the implications for organizations.

Microsoft has issued a warning regarding a sophisticated adversary-in-the-middle (AitM) phishing and business email compromise (BEC) campaign that is affecting organizations within the energy industry.