
SmarterTools Reportedly Hacked Through Vulnerabilities in Its Own Product
Risky Business News reports that SmarterTools was hacked through vulnerabilities in its own product, though key technical and impact details remain unavailable.
Verified cybersecurity, fraud and digital-banking signals with decision context, affected audiences and practical actions.

Risky Business News reports that SmarterTools was hacked through vulnerabilities in its own product, though key technical and impact details remain unavailable.

Early testing reported by Schneier on Security suggests Opus 4.6 is finding high-severity vulnerabilities faster, without specialized tooling or prompting.

Palo Alto Networks reports that a new cyberespionage group compromised 70 government and critical infrastructure organizations across 37 countries and is reconnoitering more.

A court record reportedly shows the FBI could not extract a reporter’s iPhone while Lockdown Mode was enabled, offering a cautious case study in device protection.

CyberScoop says boards should treat ERP security as a business priority, citing the reported operational and financial impact of the JLR cyberattack.

A reported Notepad++ supply-chain incident redirected selected updates to malicious servers, highlighting older update-verification weaknesses and lingering provider credentials.

Eye Security’s 2026 report, as reported by CSO Online, highlights identity abuse, passwords, and familiar attack methods as continuing security concerns.

Krebs on Security describes an extortion group’s reported use of harassment, threats, and public pressure alongside demands involving stolen data.

The FCC is urging telecom providers to strengthen cybersecurity after reporting ransomware disruptions among a growing number of small and medium-sized companies.

Police questioned Coupang acting CEO Harold Rogers during an investigation into the retailer’s data breach and possible obstruction, according to The Record.

An Anthropic evaluation, reported by Schneier on Security, describes Claude models completing more capable multistage cyber tasks with standard open-source tools.

ShinyHunters claims to have released tens of gigabytes of files from four dating apps as researchers link its activity to rising voice-based social engineering.

CISA and researchers warn that a FortiCloud SSO flaw is under attack, weeks after a similar authentication-bypass vulnerability was found.

A new Eye Security report says identity-based attacks dominate, with password-related incidents and misuse of legitimate accounts central to the trend.

The Record reports that the FBI apparently seized RAMP, a Russia-based forum used by cybercriminals and particularly associated with ransomware groups and affiliates.

A reported Fortinet zero-day bypasses FortiCloud single sign-on authentication, with exploitation noted before patches were available for several products.

Nike says it is assessing a potential cyber incident after hackers claimed a data leak, but the company has not disclosed scope or possible customer exposure.

Researchers report an ongoing voice-phishing campaign targeting SSO credentials, with alleged data theft, extortion attempts and abuse of trusted third-party access.

Cybersecurity Dive reports a cybercrime group’s claim of voice-phishing attacks alongside Okta’s earlier disclosure of social engineering using custom phishing kits.

A reported screenshot may link Kimwolf’s operators to Badbox 2.0, an Android TV botnet under investigation by the FBI and Google.

A cybersecurity firm says a Restic-related clue led it to cloud storage that helped 12 US companies recover data encrypted by INC ransomware.

CyberScoop reports a guilty plea in a ransomware conspiracy case involving at least 50 reported victims and potential prison, fine, restitution and forfeiture penalties.

An Anthropic evaluation reportedly shows Claude models completing multistage network attacks with standard open-source tools, underscoring the value of prompt patching.

Prompt injection can make LLMs follow restricted instructions, expose private data, or produce forbidden content when requests are phrased to bypass safety guardrails.