From point-in-time audits to continuous confidence: How Sophos IT transformed identity defense
“From logging in and connecting to Entra ID to seeing our first actionable findings — it took less than 45 minutes.”
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a vulnerability linked to the supply chain compromise of the GitHub Action, tj-actions/changed-files, to its Known Exploited Vulnerabilities (KEV) catalog. The high-severity flaw, tracked as CVE-2025-30066 (CVSS score: 8.6), involves the breach of the GitHub Action to inject malicious code that enables a remote
The threat actors behind the VexTrio Viper Traffic Distribution Service (TDS) have been linked to other TDS services like Help TDS and Disposable TDS, indicating that the sophisticated cybercriminal operation is a sprawling enterprise of its own that’s designed to distribute malicious content. “VexTrio is a group of malicious adtech companies that distribute scams and…
SK Telecom continues to deal with the substantial consequences of a data breach affecting its 23 million customers. In early April, the telecom reportedly discovered signs of a massive leak of customers’ universal subscriber identity module (USIM) data due to a cyberattack. They offered free replacement of the USIMs to all their 23 million users,…
From the U.S. Attorney’s Office, Eastern District of Arkansas: LITTLE ROCK—A Little Rock psychologist has been indicted for defrauding Medicare and Arkansas Blue Cross and Blue Shield (Blue Cross) and creating fictitious records to conceal her wrongdoing. Krameelah Banks, 48, of Little Rock, faces twenty-three counts of wire fraud, seven counts of making false……
Kevin Poireault reports: Keir Giles, a British expert on Russian information operations, has been targeted by a sophisticated spear phishing attack using novel social engineering techniques. The writer and senior consulting fellow at the UK think tank Chatham House was lured into sending app-specific passwords to someone impersonating a US State Department employee. The Google…
From: New York State Department of Financial Services To: All Individuals and Entities Regulated by the New York State Department of Financial Services Re: Impact to Financial Sector of Ongoing Global Conflicts The New York State Department of Financial Services (the “Department”) is issuing this guidance (“Guidance”) to all individuals and entities regulated by the…