Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker.
<button class="btn-collapse" type="button" aria-expanded="true".
The CaptiveCrunch campaign by Midnight Blizzard targets travelers worldwide by compromising hotel Wi-Fi captive portals. Attackers deliver malware and steal credentials, and Microsoft advises using full-tunnel VPNs and avoiding portal updates.
The CaptiveCrunch campaign by Midnight Blizzard targets travelers worldwide by compromising hotel Wi-Fi captive portals. Attackers deliver malware and steal credentials, and Microsoft advises using full-tunnel VPNs and avoiding portal updates.
Microsoft has identified a cyberespionage campaign dubbed "CaptiveCrunch," conducted by Storm-2945, a sub-cluster of the Russian-linked threat group Midnight Blizzard. Since May 2026, the group has manipulated DNS and HTTP traffic on Wi-Fi networks using captive portals—common in hotels, conference centers, and other hospitality venues—to redirect users to malicious infrastructure.
This article announces AWS's release of a new guidance document for implementing HIPAA Security Rule Technical Safeguards on AWS. It details the five standards and nine implementation specifications, as well as proposed 2025 NPRM changes like mandatory encryption and MFA. The guidance provides a shared responsibility matrix, ePHI boundary architecture, and a foundation checklist for cloud architects and security engineers.