Stryker, a global medical technology company based in Michigan, has fallen victim to a data-wiping attack. A hacktivist group affiliated with Iran’s intelligence services is claiming responsibility for the incident. Reports coming from Ireland, Stryker’s largest base outside of the US, indicated that the company had sent home over 5,000 workers. Also, a voicemail message left on Stryker’s main US headquarters indicated that the company is currently dealing with a building emergency. The company remains offline. Stryker is a medical and surgical products company with global sales of $25 billion last year. In a statement posted on Telegram, an Iranian hacktivist collective known as Handala, also referred to…
Kirsten Doyle
Salesforce has warned customers that it has identified a campaign in which threat actors are exploiting customers’ overly permissive guest user settings to potentially access more data than targeted businesses intended. “Evidence indicates the threat actor is leveraging a modified version of the open-source tool Aura Inspector (originally developed by Mandiant) to perform mass scanning of public-facing Experience Cloud sites,” the statement read. Although the original Aura Inspector is limited to pinpointing vulnerable objects by probing API endpoints that these sites expose, the attacker has developed a custom version of the tool that can go beyond identification to exfiltrate data. All Eyes on ShinyHunters In screenshots from its leak site published on X, the notorious extortion gang ShinyHunters says it breached “several hundreds”…
A privacy controversy surrounding Meta Platforms’ Ray-Ban smart glasses has taken a new turn after security researchers uncovered dozens of exposed credentials linked to the company’s data-annotation contractor. Last week, Swedish outlets Svenska Dagbladet and Göteborgs-Posten reported that footage captured by Meta’s smart glasses (developed with Ray-Ban) was being reviewed by human annotators working for outsourcing firm Sama. According to those interviewed for the report, some of the clips included highly sensitive scenes filmed in bathrooms, bedrooms, and other private settings. The revelations prompted the UK’s data protection watchdog, the Information Commissioner’s Office, to open an investigation. Now, new research by Suzu Labs suggests the company responsible for…
Fake tech support scams are not new. Historically, the goal was simple: convince someone to hand over a few hundred dollars in gift cards or give attackers remote access to a computer. However, new research from Huntress highlights how familiar social-engineering tricks are evolving into something far more insidious. Instead of small-scale fraud, malefactors are using fake support calls to deploy sophisticated command-and-control malware inside business networks. In a campaign observed in February 2026, bad actors first flooded organizations with spam emails. Then they followed up with phone calls posing as IT support staff, offering to “fix” the problem. Victims were persuaded to approve remote-access sessions…
ReliaQuest’s 2026 Annual Threat Report reveals that 2025 saw an unparalleled escalation in AI- and automation-facilitated cyberattacks. Incident data from 2024 was compared to 2025, and ReliaQuest found that threat actors are now faster than ever. To remain ahead of the curve, security practitioners will need to adopt AI in their own defense or be left behind. AI Increased Attack Speeds Dramatically In 2025, AI not only increased attack speeds, but it also did so much more efficiently and intelligently. Malefactors were able to automate and deploy AI to create sophisticated phishing attacks at a scale previously unattainable. This resulted in achieving lateral movement within as few as four minutes (an…
A UK solicitor is under investigation for allegedly violating client confidentiality and waiving legal privilege after they confessed to uploading their clients’ confidential documents to ChatGPT. This is in line with a warning issued by the Upper Tribunal that the use of open AI tools in such a manner may violate client confidentiality and waive legal privilege. This is a concern for the legal profession regarding the misuse of AI. In a decision heard in November, but only published recently, the judgment said: “Legal professionals are obliged to ensure that legal arguments which are presented to the First-tier Tribunal or Upper Tribunal are factually…
New evidence indicates that the North Korean state-sponsored Lazarus Group has adopted the infamous Medusa ransomware in its extortion attacks, including those against the healthcare and nonprofit sectors. The Threat Hunter Team from Symantec and Carbon Black says these attacks have been increasing since Medusa’s launch in 2023 as a “ransomware-as-a-service” (RaaS) tool. The malware, operated by a cybercrime syndicate named Spearwing, has been used in over 360 known attacks, including against critical sectors, where it encrypts data and threatens to publish the data if a ransom is not paid. Analysis of Medusa’s leak site indicates that recently, attacks have been reported against four US healthcare…
Cyber Risk is now a standing item in most boardrooms. You’ll find it in annual reports, audit committees, and regulatory filings. And still, cyber risk is not being addressed. Not because boards don’t care, or because CISOs are not reporting. But because something fundamental is still not working between security and governance. We posed these three questions to six leading minds in the field of cyber security and risk: What we got back was convergence. But within that convergence were sharp distinctions about governance, AI, trust, financial modeling, and accountability. The Biggest Misunderstanding: Cyber Is Still Treated as an IT Problem Despite years of awareness…
PayPal has disclosed a data breach that exposed some of its customers’ personal information and led to fraudulent transactions. The company said it happed due to an error in its PayPal Working Capital (“PPWC”) loan application, an offering that gives businesses a cash advance based on their PayPal sales history. Between 1 July and 13 December 2025, the PII of a small number of customers was exposed to bad actors. PayPal added that it has since rolled back the code change responsible for this error. Types of data exposed include, full names, email addresses, phone numbers, mailing addresses, dates of birth, and SSNs. PayPal insisted that no financial account information, login credentials, passwords, and credit card…
Malware-fuelled ATM “jackpotting” attacks are surging across the United States, with the FBI warning that incidents have spiked sharply in 2025. In a recent alert, the Bureau said it has recorded around 1,900 ATM jackpotting incidents since 2020. Alarmingly, more than 700 of those cases (representing over $20 million in losses) have happened this year alone. The bureau is now urging financial institutions and ATM operators to review their security controls and implement stronger mitigation measures. Bypassing Authentication Entirely At the centre of many of these attacks is the Ploutus family of malware. Ploutus targets the eXtensions for Financial Services (XFS) layer, the software interface that tells…
