It sounds counterintuitive. An adversary exploits a system, gains access, and then patches the very hole they used to break in. Yet that is exactly what Red Canary researchers observed in a recent campaign targeting cloud-based Linux servers. The logic is simple. By fixing the exploited vulnerability, a malefactor can lock out rivals and mask their method of entry. What looks like remediation is, in reality, persistence. The Red Canary Threat Intelligence team tracked a cluster of activity exploiting CVE-2023-46604 in Apache ActiveMQ, a widely deployed open-source message broker. Once inside, the adversary moved quickly. “It’s a great way to…
Kirsten Doyle
Britain has abandoned its demand that Apple build a “backdoor” into its encryption systems. The change follows months of quiet talks between London and Washington, Reuters reports. In a statement posted on X, U.S. Director of National Intelligence Tulsi Gabbard, said: “As a result, the UK has agreed to drop its mandate for Apple to provide a ‘backdoor’ that would have enabled access to the protected encrypted data of American citizens and encroached on our civil liberties.” She added that the U.S. government had been working with Britain “to ensure that Americans’ civil liberties are protected.” The discussions involved President…
Colt Technology Services has been dealing with a cyberattack that has disrupted parts of its business for more than a week. The UK-based telecommunications firm, which operates in 30 countries and runs nearly 50,000 miles of fiber connecting 900 data centers, confirmed that several internal support systems remain offline. The incident began on 12 August, when Colt detected unusual activity and took systems down as a protective measure. The move cut access to Colt Online, its Voice API platform, and hosting and porting services. Customers who normally use web portals have been told to rely on phone or email instead,…
Workday, a cloud-based platform used for human capital managment and financial management, has disclosed a data breach after attackers gained access to a third-party CRM platform in a recent social engineering attack. The company said bad actors contacted employees by text or phone, pretending to be from HR or IT. Their goal was to fool staff members into giving up account access or their personal information. “We recently identified that Workday had been targeted and threat actors were able to access some information from our third-party CRM platform. There is no indication of access to customer tenants or the data…
In April 2025, SAP patched a critical vulnerability in NetWeaver AS Java Visual Composer. The flaw, tracked as CVE-2025-31324, allows unauthenticated remote code execution through the Visual Composer “metadata uploader” endpoint. Within weeks, proof-of-concept code appeared in public forums. Now, the exploit is no longer theoretical. Full tooling has been released. Source code is out in the open, easy to download and run. It takes little skill to weaponize. With AI assistance, even non-specialists can cause damage to systems that remain unpatched. Pathlock researchers examined the leaked exploit code. Their analysis confirms that the attack chain is simple. An attacker…
A new survey has revealed the extent to which poor coding practices are leaving UK businesses exposed. Two-thirds of senior technology leaders admitted their organisations suffered at least one breach or serious security incident in the past year. The common cause: insecure code. SecureFlag’s research found that of the 100 executives surveyed, nearly half reported facing more than one incident in twelve months. Despite the scale of the problem, 40 percent of organisations still do not require their developers to undergo regular secure coding training. “This should be a wake-up call for every business that develops software,” said Andrea Scaduto, CEO and…
A threat actor is selling secrets. Big ones. Operating under the alias Chucky_BF, the attacker has surfaced on underground forums with a staggering claim: over 15.8 million PayPal credentials for sale. The haul includes email addresses, plaintext passwords, and direct URLs to PayPal services. It’s being marketed as the “Global PayPal Credential Dump 2025.” Hackread first reported this development. The numbers are staggering. The dataset spans 1.1GB and covers accounts from email providers worldwide. But size isn’t everything here. What makes this leak particularly dangerous is its laser focus on PayPal infrastructure. These aren’t just random credentials. The records include…
Huntress analysts have tracked a fresh ransomware incident involving KawaLocker, also known as KAWA4096. The variant is new, but the method is familiar. Attackers gained access, disabled defenses, and moved to encrypt files. Ransomware families surface often. A year ago, Huntress reported on ReadText34. Just last month, a never-before-seen strain called Crux appeared. KawaLocker joins the list. According to Trustwave SpiderLabs, KawaLocker first appeared in June 2025. Its ransom note echoes Qilin. Its leak site resembles Akira. Analysts believe the similarities are meant to draw attention, not signal collaboration. The attack began on 8 August. Threat actors entered a victim’s…
The House of Commons and Canada’s cybersecurity agency are investigating a significant breach of parliamentary employee data, CBC News reports. An internal email to CBC staff on Monday 11 August said a malicious actor exploited a recent Microsoft vulnerability to gain unauthorized access to a database used to manage computers and mobile devices. The data included names, job titles, office locations, email addresses, and technical details about House-managed equipment. Some of the information was not publicly available. The email warned employees and members of Parliament to remain vigilant, as stolen details could be used in scams or to impersonate parliamentarians.…
Ransomware and infostealer threats are evolving faster than most organizations can keep pace. Security teams have invested heavily in backup and recovery systems, yet today’s most damaging attacks often bypass encryption altogether. Picus Security’s Blue Report 2025 uncovered a shift: threat actors are targeting credential theft, data exfiltration, and lateral movement, founded on stealth and persistence rather than noise. The numbers are a wake-up call. In nearly half the environments tested, at least one password hash was successfully cracked. Attempts at preventing data exfiltration fell to a low of 3%, a steep decline from 9% in 2024. One stolen credential…
