Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Meta is introducing an optional WhatsApp beta feature called Scam Alert that uses on-device machine learning to detect likely scam messages from people outside a user's contacts. The feature shows a warning banner but does not block anything, letting users block, report, trust, or continue the conversation.
Shell is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data from the oil giant. The company has not publicly confirmed the full scope or authenticity of the stolen information.
A new free service called DecryptAds makes public adtech disclosure files easy to search, showing which companies track users across websites and apps. It cross-references ads.txt, app-ads.txt, and sellers.json to expose data brokers, supply-chain relationships, and advertising firms based in high-risk countries.
Researchers at SpecterOps have detailed a post-exploitation technique that activates Chrome DevTools Protocol (CDP) inside a running Chrome or Edge process on Windows, enabling cookie theft, data exfiltration, and session hijacking. The method assumes the attacker already has code execution on the host and does not exploit a browser vulnerability; instead, it uses a Beacon Object File (CDP-Enable-BOF) to inject a debugging server into the existing process.
CTM360's RecruitTrap report reveals a large-scale phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials, and in advanced cases, relay multi-factor authentication (MFA) prompts in real time. The attack begins with unsolicited emails or meeting invitations impersonating real recruiters from over 50 organizations across 14 sectors, directing victims to counterfeit Calendly-style pages or brand-specific recruitment portals.
RingCentral is responding to a data breach that exposed personal information of 1.6 million accounts, with the ShinyHunters extortion group claiming responsibility for the July intrusion. Have I Been Pwned is helping notify affected users of the stolen data.