Data is being stolen by a threat actor who is targeting Microsoft 365 and Azure production installations using assaults that ...
What happens after MFA succeeds? How session token theft lets attackers move laterally through enterprise networks without ...
ESET Research uncovered and analyzed the latest activities and arsenal of China-aligned Webworm advanced persistent threat (APT) group.In 2025, ...
Microsoft says Storm-2949 targets Microsoft 365 and Azure environments using MFA abuse, password resets, and cloud data theft ...
EchoCreep, which uses Discord for C&C communication, and GraphWorm, which uses Microsoft Graph API for the same purpose. The ...
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate ...
Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft ...
An upcoming update for Exchange Server changes the fundamental communication technology in hybrid company networks. Microsoft is rigorously shutting down a two-decade-old interface. This has fatal ...
Instructure’s Canvas LMS breachOpens a new window is now one of the largest education data incidents ever recorded, tying together vendor risk, SaaS monoculture, and real harm to students and staff.
Solana and Google Cloud introduce Pay.sh, enabling AI agents to pay per API call, hinting at a shift from subscriptions.
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...