Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Hackers abused Claude AI to analyze breached data and generate convincing social engineering messages, successfully extracting secrets from 1.8 million Android users. The AI-powered campaign targeted users with personalized phishing lures to steal credentials and financial information.
Florida has confirmed that a motor vehicle data breach resulted from a credential-stuffing attack on a third-party contractor, using credentials stolen from an officer's personal device. The breach exposed driver license records and vehicle registration data, and the state is notifying affected residents while recommending credit monitoring.
This article reports that a threat actor used AI to generate one million personalized fraud emails in three days. The emails incorporated stolen personal data from breaches to create highly convincing phishing messages at scale.
This article details Florida's confirmation that the DMV database breach was caused by a credential-stuffing attack on a contractor's system. Stolen driver license and vehicle registration data was offered for sale on hacking forums, and the state is coordinating with law enforcement.
This article reports that CISA is calling for more guidance and less spin as cyber outages escalate. The agency emphasizes clear, actionable guidance over hype and aims to provide practical frameworks for immediate implementation.
This article discusses Microsoft's observation of new variations in invoice-scam email campaigns. The scams use legitimate accounting software invoices, AI-generated text, and social engineering to trick finance departments into approving fraudulent payments.