Data theft stories
The stealer's use of typosquatted npm packages has raised fears that bug bounty channels are being abused to monetise stolen developer data.
Defenders now have minutes, not hours, as attackers use agentic AI to automate credential theft, scanning and extortion across live operations.
Attackers are compressing intrusions into hours, leaving defenders less time to spot and stop credential-harvesting campaigns.
Families across Asia-Pacific are being lured by fake grants, scholarships and delivery alerts as scammers exploit rising education costs and AI tools.
More groups are now driving attacks, leaving victim numbers flat even as ransomware operations reached a record 93 active crews in the quarter.
Organisations still miss most stealthy intrusions after logins, as Picus found only 14% of simulated attacks triggered alerts and exfiltration defence was 7%.
Industrial firms face growing disruption as ransomware incidents rose 12% to 1,140 in the second quarter, Dragos said.
By blocking stolen-logins abuse at file level, the new feature aims to curb both data theft and ransomware even after an account is compromised.
Google says the campaign is shifting towards financial and legal firms, with rebranded extortion sites still stealing cloud logins and tokens.
Undisclosed attacks now dominate ransomware activity, with 2,027 incidents logged in the quarter and data theft reported in 97% of disclosed cases.
Organisations face a growing risk of silent data theft as criminals exploit cloud identities and credentials for extortion instead of encryption.
Malicious packages are now spreading faster across code repositories, with Google saying open source ecosystems face the sharpest rise in risk.
More than half of organisations in Australia and New Zealand suffered print-related security incidents last year, exposing document data to theft.
Ransomware-prone operators could cut integration costs as ATLAS pitches a single storage-and-security system to foreign buyers in Yekaterinburg.
Greater exposure to remote attacks is worrying carmakers, as high-severity automotive cybersecurity flaws jumped to 161 in the second quarter.
New Zealand users risk fake login pages and scam sites after ChatGPT search results were found pointing to unsafe links and downloads.
Victims are being pressured by increasingly convincing calls as scam losses across Australia hit AUD $2.18 billion in a year.
Most Canadians want tighter fraud controls as the new Real-Time Rail could leave less time to block deepfake-driven scams and impersonation.
Defenders facing faster credential theft and account takeovers now have a free, hands-on way to practise dark web intelligence before an incident escalates.
In Singapore, 68% of ransomware-hit organisations said AI made attacks more effective, as phishing and impersonation drove most incidents.