Data exfiltration stories
Proofpoint flags mailbox rule abuse in Microsoft 365
2 days ago
#
edutech
#
mfa
#
cloud security
Proofpoint says mailbox rule abuse is becoming a routine Microsoft 365 takeover tactic, helping attackers hide alerts, hijack threads and drive fraud.
Sonatype warns of surge in trusted open-source malware
3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
AI agents expose major API security gap, Salt warns
Last week
#
manufacturing
#
digital transformation
#
cloud security
Salt warns AI agents are widening the API security gap, with 92% of organisations still short of advanced defences and 47% delaying releases.
From DSPM to data protection: Closing the last mile on sensitive data in the era of AI
Last week
#
storage
#
data protection
#
cloud security
AI-era data security needs more than DSPM visibility, as firms must track how sensitive information moves and enforce controls in real time.
Small alert, big defense: Inside a SOC's early-morning response
Last week
#
vpns
#
ransomware
#
mfa
UK SOC spots Monday-morning conditional access failure from Germany, helps reset compromised Microsoft 365 account before attackers can strike.
Singapore cyberattacks rise 22% as global attacks fall
Last week
#
malware
#
firewalls
#
data protection
Singapore organisations hit by 22% more cyberattacks in March, with consumer-facing and public sectors most exposed amid rising GenAI data-leak risks.
Nutanix & NetApp launch virtualisation migration tie-up
Last week
#
storage
#
virtualisation
#
data protection
Nutanix and NetApp team up on migration tools to help enterprises modernise virtualised systems, cut complexity and bolster ransomware defences.
Claude Code flaw leaves deny rules vulnerable in long workflows
Last week
#
cloud security
#
application security
#
socs
Anthropic’s Claude Code is under scrutiny after researchers found deny rules can weaken in long workflows, raising fresh concerns for AI-driven development.
Microsoft warns of Storm-1175's rapid Medusa attacks
Last week
#
ransomware
#
cybersecurity
#
microsoft
Microsoft says Storm-1175 is exploiting newly disclosed flaws within hours, hitting organisations in the UK and elsewhere with fast-moving Medusa ransomware.
Permiso launches sandbox for AI agent skill security
Last week
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
ChatGPT flaw let hackers steal data via DNS queries
This month
#
firewalls
#
data protection
#
devops
ChatGPT flaw may have let attackers siphon sensitive user data via DNS queries, prompting OpenAI to issue a fix after researchers exposed the bug.
F5 & Forcepoint come together to secure enterprise AI
This month
#
data protection
#
hybrid cloud
#
digital transformation
F5 and Forcepoint have teamed up to link data discovery with runtime controls, aiming to curb AI risks as enterprises move systems into production.
Zscaler flags Xloader malware's tougher obfuscation
This month
#
malware
#
firewalls
#
encryption
Zscaler says Xloader malware has added layered encryption, decoy servers and new obfuscation tricks to hinder analysts.
Foxit adds PDF Action Inspector to spot hidden risks
This month
#
data protection
#
document management
#
ecm
Foxit's latest PDF Editor update adds Action Inspector to uncover hidden scripts and redaction-bypassing behaviour in business documents.
DeepLoad malware steals credentials via ClickFix campaign
This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.
Firms warned on ransomware amid backup & AI sprawl
This month
#
saas
#
firewalls
#
data protection
Experts warn firms must improve visibility and backup resilience as automated ransomware campaigns and hidden SaaS and AI assets widen exposure.
Codenotary launches AgentMon for AI agent oversight
Last month
#
data protection
#
digital transformation
#
application security
Codenotary unveils AgentMon to help Chief Information Officers and security teams track AI agent behaviour, costs and policy risks.
Microsoft 365 behind 32% of escalated security incidents
Last month
#
uc
#
ransomware
#
mfa
Microsoft 365 drives 32% of escalated incidents in Malaysia, with phishing, weak authentication and dark web credentials fuelling attacks.
Why AI-powered security needs network telemetry across the hybrid cloud
Last month
#
firewalls
#
private cloud
#
hybrid cloud
AI security tools are only as smart as the data they see, and network telemetry is emerging as the missing piece in hybrid cloud oversight.
F5 & Forcepoint join forces on enterprise AI security
Last month
#
data protection
#
digital transformation
#
application security
F5 and Forcepoint team up to give enterprises continuous AI security, linking data discovery with runtime controls to reduce risk in production systems.