Chanel has confirmed a data breach that affected its U.S. client care database. The news first came from WWD on Friday. The incident happened on July 25 and involved unauthorized access to a database managed by a third-party provider. A company spokeswoman confirmed the incident, saying: “The investigation indicates that there was unauthorized access to this database. There was no malware deployed to our systems, and our operations remain unaffected.” She added that Chanel immediately activated their incident response protocols and brought cybersecurity experts on board to aid their investigation. The information exposed was limited. Names, emails, mailing addresses, and…
Kirsten Doyle
In August, cybersecurity firm CTM360 uncovered a large-scale scam targeting TikTok Shop users. Called “FraudOnTok,” this campaign combines phishing with malware. It uses a complex web of fake sites and apps to trick victims into handing over their credentials, and their money. The bad actors set up more than 15,000 lookalike domains. They mimic TikTok Shop, TikTok Wholesale, and TikTok Mall, using cheap domain extensions like .top, .shop, and .icu. These sites fool users into believing they’re on the official platform. Once there, victims are hit with phishing pages that steal login info, and are prompted to download trojanized apps…
By 2024, AI had done more than disrupt industries. It had quietly supercharged one: data brokerage. Few consumers ever meet a data broker and even fewer understand what they do. But their work touches nearly every person with a smartphone, a loyalty card, or an internet connection. The Invisible Harvest Data brokers operate in silence. They gather, compile, and sort. According to vpnMentor: “They often do this indirectly and without explicit consent, instead maximizing public records, traceable online activity, or other openly accessible channels. Names, phone numbers, IP addresses. Birthdays, income brackets, voter registrations, browsing habits, shopping carts, and app…
New research from browser security firm Menlo Security reveals an alarming rise in unsanctioned generative AI (GenAI) use across enterprises, with growing concerns over data leakage, phishing, and regulatory compliance. According to The 2025 Report: How AI is Shaping the Modern Workspace, web traffic to GenAI sites spiked by 50% in under a year, culminating in 10.53 billion visits in January 2025 alone. At the heart of the findings is a sharp increase in what Menlo terms Shadow AI, or the use of unsanctioned GenAI tools by employees, often without their organization’s knowledge or oversight. AI Adoption Accelerates, Security Gaps…
A new name surfaced in Microsoft’s analysis of the ToolShell exploitation campaign earlier this year. Storm-2603. There was no history or track record. Just a cluster of activity, loosely linked to ransomware. Now, Check Point Research has filled in some of the blanks. Storm-2603, it turns out, was not born with ToolShell. It had been busy long before, targeting entities in Latin America and APAC. Its methods are like the hybrid DNA of advanced persistent threats and criminal ransomware crews. It moves with precision, using open-source tools and custom malware. It doesn’t bluff. An Unknown Name, Familiar Footsteps ToolShell is…
The UK has seen a steep rise in VPN usage following the enforcement of the Online Safety Act. On 25 July, Ofcom began implementing new age-verification rules designed to keep children away from adult content. In response, many users started using VPNs. Traffic spiked. So did downloads. Researchers at vpnMentor tracked a whopping 6,430% increase in VPN demand in the hours after the law came into effect. “It remained as such for almost two hours before it started dropping at the end of the day, but with spikes of 900% up to 4000% the following days,” researchers said. Several VPN…
Ransomware groups are ramping up pressure on the public sector. In the first half of 2025, 208 attacks were recorded against government entities worldwide. That’s a 65% increase over the same period in 2024, and a 25 percent rise from the second half of last year. These were some of the findings from Comparitech’s Map of worldwide ransomware attacks that is updated daily. Half of the incidents were confirmed by the targeted agencies. The rest remain unresolved or unacknowledged. This level of transparency is rare outside the public sector. In education, only 31% of incidents were confirmed. Healthcare: 32%. In…
A new draft from NIST, developed in collaboration with 14 industry partners, outlines how to build software with security baked in, not bolted on. This is part of a broader push to protect the software supply chain, and it’s open for public comment until 12 September 2025. The guidelines are a response to Executive Order 14306, issued in June, which called for sustained action to strengthen national cybersecurity. NIST’s National Cybersecurity Center of Excellence (NCCoE) is leading the work through a newly formed Software Supply Chain and DevOps Security Practices Consortium. The goal is simple, if ambitious: help organizations build,…
An investigation from Sonatype has exposed a cyber-espionage campaign by North Korea’s infamous Lazarus Group, this time targeting the tools developers rely on every day. Between January and July 2025, Sonatype blocked 234 unique malware-laden packages across the npm and PyPI ecosystems; a calculated assault on the trust that underpins open-source software. Disguised as popular developer utilities, these poisoned packages carried espionage implants designed to exfiltrate credentials, profile systems, and establish long-term backdoors. At last count, the campaign may have reached over 36,000 victims, and it’s still ongoing. “Open source has become the new attack surface,” Sonatype warns. “It’s not…
It starts with an ad. The branding looks familiar; Coinbase, Binance, OKX. The ad promises fast trading, high returns, or access to a new crypto platform. Click it, and you’re sent through a maze of redirects. At the end is a download: a Windows installer in .msi format. Behind this is JSCEAL, a malware campaign that’s been quietly active since March last year. It doesn’t use zero-days because it doesn’t need to. It hides in plain sight, behind sponsored ads and familiar logos. Check Point Research uncovered the campaign after tracking a spike in crypto-related malware infections across Europe. Their…
