Threat actors are spoofing big brand logos in recruiting scams to dupe individuals into believing they are working with real companies and to divulge their Google credentials.

The scam was first identified by a Team Cymru researcher, who discovered that threat actors were impersonating recruiters from big brands to target marketing professionals. The fraudulent emails

Threat group ShinyHunters continues its incessant campaign to torture companies trying to provide products and services to consumers, with no indication of letting up.

One of its latest victims, Medtronic, the manufacturer of medical devices, healthcare technologies, and therapies, confirmed that it was the victim of an April cyberattack where over nine million records from

LastPass has confirmed that a security incident with a vendor, a third-party market intelligence platform “which integrates with our Salesforce and Gong systems” has compromised some customers information. As a result, the threat actor was able to use credentials to access LastPass customer data within its Salesforce environment.

The compromised information includes “business contact information

June 15, 2026, was designated World Elder Abuse Awareness Day. One of the ways seniors are victimized is through financial scams. According to the Federal Trade Commission (FTC), “in 2025, [elderly] people reported losing about $16 billion to scams, compared to $12.8 billion the previous year. And because not everyone who experiences a scam

If you are a Signal user, be on the alert for a new phishing campaign that attempts to steal recovery keys used to access cloud backups.

If successful, the attackers could have access to entire message archives, conversations, photos and documents shared through the Signal platform. Signal is often used for highly sensitive communications, so

As you can tell, I am obsessed with Verizon’s Data Breach Investigations Report. It is worthy of full immersion, and I am picking it apart with precision (here and here). I always spend a lot of time delving into it as it informs and confirms strategies to assist others with prevention and resilience.

According to HaveIBeenPwned, ShinyHunters targeted fashion brand Zara in a cyber-attack  and claimed that it had stolen 197,000 unique email addresses, product SKUs, order IDs, and the originating market. The incident involved a former technology provider (AI analytics platform Anodot) for Zara’s parent company, Inditex, which resulted in the exposure of the personal information.