Tag Microsoft

Microsoft and Okta Acknowledge Breach Linked to LAPSUS$ Extortion Group

On Tuesday, Microsoft publicly acknowledged that the LAPSUS$ hacking group had achieved “limited access” to its systems, coinciding with a revelation from Okta, an identity authentication services provider, indicating that nearly 2.5% of its customer base may have been affected by the breach. Microsoft’s Threat Intelligence Center (MSTIC) confirmed that…

Read MoreMicrosoft and Okta Acknowledge Breach Linked to LAPSUS$ Extortion Group

Researchers Link LAPSUS$ Cyber Attacks to 16-Year-Old English Hacker

Okta, a prominent provider of authentication services, has identified security firm Sitel as a third-party entity involved in a critical security breach that occurred in late January. This incident permitted the LAPSUS$ extortion gang to gain unauthorized access to an internal account assigned to a customer support engineer. The breach…

Read MoreResearchers Link LAPSUS$ Cyber Attacks to 16-Year-Old English Hacker

Nevada State Hackers Eluded Detection for Several Months

Fraud Management & Cybercrime, Government, Industry Specific Statewide Cyber Breach Affects 60 Agencies Before Ransomware Implementation Chris Riotta (@chrisriotta) • November 6, 2025 Image: Shutterstock/ISMG Recent analyses reveal that a ransomware threat actor compromised Nevada’s statewide government systems for several months prior to executing a ransomware attack. An after-action report…

Read MoreNevada State Hackers Eluded Detection for Several Months

SolarWinds Hackers Compromise Microsoft Customer Support to Target Clients

In a recent development reflecting the persistent threat posed by Russian cyber actors, Microsoft has disclosed that the hackers behind the SolarWinds breach have resumed operations utilizing password spraying and brute-force methods to compromise customer accounts. This resurgence serves as a stark reminder that the attackers remain active and adept…

Read MoreSolarWinds Hackers Compromise Microsoft Customer Support to Target Clients

NSA and FBI Expose Hacking Techniques Employed by Russian Military Hackers

A persistent brute-force attack campaign, believed to be orchestrated by Russian military intelligence, has targeted enterprise cloud environments since mid-2019. This information is detailed in a joint advisory released by intelligence agencies in both the United States and the United Kingdom. The National Security Agency (NSA), Cybersecurity and Infrastructure Security…

Read MoreNSA and FBI Expose Hacking Techniques Employed by Russian Military Hackers

Unfixed Windows Vulnerability Paves the Way for State-Sponsored Cyber Hackers

Cyberwarfare / Nation-State Attacks , Fraud Management & Cybercrime Chinese Hackers Exploit Windows Vulnerability Against European Diplomats Akshaya Asokan (asokan_akshaya) , David Perera (@daveperera) • November 5, 2025     Image: AR Pictures/Shutterstock Security researchers have reported that Chinese nation-state hackers are actively using a Windows vulnerability to target European…

Read MoreUnfixed Windows Vulnerability Paves the Way for State-Sponsored Cyber Hackers

Zohran Mamdani Takes the Helm of the NYPD’s Surveillance System

The campaign of Mamdani did not provide a response to inquiries for comment regarding recent developments. The New York Police Department (NYPD) significantly expanded its mass surveillance programs under Commissioner Raymond Kelly following the September 11 attacks, supported by substantial federal anti-terrorism funding. However, Ferguson highlights that former commissioner William…

Read MoreZohran Mamdani Takes the Helm of the NYPD’s Surveillance System

T-Mobile Confirms Lapsus$ Hackers Breached Internal Tools and Accessed Source Code

T-Mobile has confirmed it fell victim to a security breach in March, attributed to the notorious LAPSUS$ hacking group, known for its sophisticated cyber exploits. This assertion comes following revelations by investigative journalist Brian Krebs, who disclosed internal communications from LAPSUS$ that corroborate multiple incursions into T-Mobile’s systems throughout March,…

Read MoreT-Mobile Confirms Lapsus$ Hackers Breached Internal Tools and Accessed Source Code

GitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

GitHub Security Updates Address Critical Vulnerabilities in Enterprise Server GitHub has announced crucial security updates for its Enterprise Server (GHES), responding to multiple vulnerabilities, including a severe flaw that could lead to unauthorized access. The updates aim to enhance user protection, particularly against a vulnerability identified as CVE-2024-9487, which has…

Read MoreGitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access