TELUS Digital has fallen victim to a security incident in which unsanctioned actors accessed its systems. Upon learning of this incident, the company said it took immediate action to resolve it and prevent any future breaches of its systems and environment. “All business operations within TELUS Digital remain fully operational, and there is no evidence of disruption to customer connectivity or services. As part of our response, we have engaged leading cyber forensics experts to support our investigation, and we are working with law enforcement.” The notorious cybercrime group ShinyHunters has taken responsibility for the attack and has also claimed that the group…
Kirsten Doyle
Starbucks has disclosed a data breach attackers gained access to hundreds of employees’ Starbucks Partner Central accounts, which are used for managing employment information, personal data, benefits, and HR information. In a letter sent to affected staff members, the company said: “On or about February 6, 2026, Starbucks Corporation (“Starbucks” or “we”) became aware of potential unauthorized access to certain Starbucks Partner Central accounts.” Starbucks is the world’s largest coffee shop chain with 380,000 employees and nearly 41,000 shops in 88 countries. In a data breach notification filed with the Attorney General in Maine, Starbucks said 889 employees were affected. “Upon becoming aware, Starbucks commenced an investigation and began taking measures…
Security researchers have demonstrated how a growing class of AI safety controls (known as AI judges) can be manipulated into approving content they are supposed to block. In new research published by cybersecurity firm Palo Alto Networks’ threat intelligence team Unit 42, analysts describe how automated “fuzzing” techniques can uncover hidden weaknesses in the large language models that many organizations now rely on as automated gatekeepers. These models are increasingly used to evaluate whether AI-generated responses are safe, policy-compliant, or suitable for users. But the research suggests that these digital referees can themselves be fooled, sometimes by nothing more than harmless-looking formatting characters. Testing the AI Gatekeepers …
Stryker, a global medical technology company based in Michigan, has fallen victim to a data-wiping attack. A hacktivist group affiliated with Iran’s intelligence services is claiming responsibility for the incident. Reports coming from Ireland, Stryker’s largest base outside of the US, indicated that the company had sent home over 5,000 workers. Also, a voicemail message left on Stryker’s main US headquarters indicated that the company is currently dealing with a building emergency. The company remains offline. Stryker is a medical and surgical products company with global sales of $25 billion last year. In a statement posted on Telegram, an Iranian hacktivist collective known as Handala, also referred to…
Salesforce has warned customers that it has identified a campaign in which threat actors are exploiting customers’ overly permissive guest user settings to potentially access more data than targeted businesses intended. “Evidence indicates the threat actor is leveraging a modified version of the open-source tool Aura Inspector (originally developed by Mandiant) to perform mass scanning of public-facing Experience Cloud sites,” the statement read. Although the original Aura Inspector is limited to pinpointing vulnerable objects by probing API endpoints that these sites expose, the attacker has developed a custom version of the tool that can go beyond identification to exfiltrate data. All Eyes on ShinyHunters In screenshots from its leak site published on X, the notorious extortion gang ShinyHunters says it breached “several hundreds”…
A privacy controversy surrounding Meta Platforms’ Ray-Ban smart glasses has taken a new turn after security researchers uncovered dozens of exposed credentials linked to the company’s data-annotation contractor. Last week, Swedish outlets Svenska Dagbladet and Göteborgs-Posten reported that footage captured by Meta’s smart glasses (developed with Ray-Ban) was being reviewed by human annotators working for outsourcing firm Sama. According to those interviewed for the report, some of the clips included highly sensitive scenes filmed in bathrooms, bedrooms, and other private settings. The revelations prompted the UK’s data protection watchdog, the Information Commissioner’s Office, to open an investigation. Now, new research by Suzu Labs suggests the company responsible for…
Fake tech support scams are not new. Historically, the goal was simple: convince someone to hand over a few hundred dollars in gift cards or give attackers remote access to a computer. However, new research from Huntress highlights how familiar social-engineering tricks are evolving into something far more insidious. Instead of small-scale fraud, malefactors are using fake support calls to deploy sophisticated command-and-control malware inside business networks. In a campaign observed in February 2026, bad actors first flooded organizations with spam emails. Then they followed up with phone calls posing as IT support staff, offering to “fix” the problem. Victims were persuaded to approve remote-access sessions…
ReliaQuest’s 2026 Annual Threat Report reveals that 2025 saw an unparalleled escalation in AI- and automation-facilitated cyberattacks. Incident data from 2024 was compared to 2025, and ReliaQuest found that threat actors are now faster than ever. To remain ahead of the curve, security practitioners will need to adopt AI in their own defense or be left behind. AI Increased Attack Speeds Dramatically In 2025, AI not only increased attack speeds, but it also did so much more efficiently and intelligently. Malefactors were able to automate and deploy AI to create sophisticated phishing attacks at a scale previously unattainable. This resulted in achieving lateral movement within as few as four minutes (an…
A UK solicitor is under investigation for allegedly violating client confidentiality and waiving legal privilege after they confessed to uploading their clients’ confidential documents to ChatGPT. This is in line with a warning issued by the Upper Tribunal that the use of open AI tools in such a manner may violate client confidentiality and waive legal privilege. This is a concern for the legal profession regarding the misuse of AI. In a decision heard in November, but only published recently, the judgment said: “Legal professionals are obliged to ensure that legal arguments which are presented to the First-tier Tribunal or Upper Tribunal are factually…
New evidence indicates that the North Korean state-sponsored Lazarus Group has adopted the infamous Medusa ransomware in its extortion attacks, including those against the healthcare and nonprofit sectors. The Threat Hunter Team from Symantec and Carbon Black says these attacks have been increasing since Medusa’s launch in 2023 as a “ransomware-as-a-service” (RaaS) tool. The malware, operated by a cybercrime syndicate named Spearwing, has been used in over 360 known attacks, including against critical sectors, where it encrypts data and threatens to publish the data if a ransom is not paid. Analysis of Medusa’s leak site indicates that recently, attacks have been reported against four US healthcare…
