Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Pro-Ukraine Hacking Cat Group Deploys New Malware Against Russian Targets

  A pro-Ukraine hacktivist group known as Hacking Cat has significantly escalated its cyber operations against Russian targets by deploying ...

All the recent news you need to know

Japan Digital Agency Data Breach Linked to VPN Vulnerability


Government Solution Service (GSS) of Japan's Digital Agency was compromised by a vulnerability in a VPN device, resulting in unauthorized access to the shared government platform through an exploit of a vulnerability in the VPN device. In this incident, 246,000 records containing information regarding employees, public officials, contractors, and other individuals connected to organizations using the service may have been exposed. 

Upon discovering unusually large-scale access to files on a server through an account belonging to a maintenance and operations staff member on June 25, the agency first detected the breach. Following an investigation, the agency determined that the account activity was linked to an unauthorized access to a network-connected VPN device. 

By July 9, the agency determined that an external party had accessed the system by exploiting a vulnerability in the VPN equipment. Immediately after the incident, the maintenance account was suspended, and communication between the equipment and external networks was restricted to prevent further access. 

The investigation, conducted with the assistance of an external security company, revealed that some files that contained personal information could have been transferred outside the system. The VPN product used and the specific vulnerability that was exploited have not been disclosed by the agency. Through shared IT infrastructure, 23 Japanese ministries and government agencies are served by the affected GSS environment, which can have a greater impact on the incident. 

The exposed information consists of approximately 236,000 names, 231,000 e-mail addresses, 94,000 telephone numbers, and 1,000 physical addresses. The records relate to personnel and officials who work with GSS user organizations, as well as businesses and individuals who support those organizations. 

Data containing information belonging to the general public was not included in the affected data, according to the agency. Additionally, the compromised dataset is lacking My Number identification numbers, bank account information, or pension number information. Despite the fact that no confirmed cases of misuse have been identified, the exposed contact information could still be used for impersonation, phishing, or other forms of social engineering. 

VPN exposures were categorized as medium severity and were not zero-day vulnerabilities; however, the agency has failed to provide details regarding when the vulnerability was fixed or why the device was still exposed at the time of the intrusion. 

Known VPN Flaw Left Unpatched

Due to the fact that the Digital Agency was already aware of a VPN flaw when the breach occurred, but had not applied the required patch, the incident raises concerns about vulnerability management. According to the agency, the vulnerability has a medium severity and has been confirmed as not a zero-day, indicating that attackers exploited a known vulnerability rather than a newly discovered vulnerability. 

The information accessed is approximately 246,000 records. Over 189,000 of these people are government employees, public officials, or other personnel working for GSS-related organizations, while approximately 57,000 are private companies and individuals involved in government-related activities. 

A total of 236,000 names, 231,000 emails, 94,000 telephone numbers, and 1,000 physical addresses were included in the data. In addition, duplicate entries may be present in the data. More sensitive identifiers are not included in the dataset, such as My Number information, bank account details, and pension information.

Investigation Finds No Confirmed Misuse

The Digital Agency has not received any confirmations of misuse of the exposed information, however, the combination of names and contact information could facilitate targeted phishing or impersonation attempts against affected employees. Messages or phone calls from individuals pretending to represent the government have been warned by the agency, and official personnel will not contact affected parties via email or telephone for passwords or payment information. 

Japan's Personal Information Protection Commission was made aware of this incident on July 15. During the investigation, the agency determined that potentially affected information was likely to be identified and the individuals and organizations involved required a considerable amount of time, which contributed to the delay in public disclosure. 

Digital Agency officials indicated the impact was limited to the affected GSS environment with no evidence of other government systems being compromised or disrupted. As part of its effort to strengthen vulnerability management and review how external connections to the system are handled, the agency is also expected to provide direct notifications to the affected individuals. 

To prevent unauthorized access to sensitive government information and limit unauthorized access, VPN patches should be implemented on time, strict access controls should be implemented, continuous monitoring should occur, and rapid isolation should be instituted.

$13 Billion in Losses Since 2023, Treasury Asks Banks to File Cyber Scam Reports


The federal government has asked financial organizations to be more careful in detecting and reporting scams done by overseas scammers. 

The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) launched and alert to the financial industry besides a detailed study of over 33,000 cyber fraud cases reported between September 2023 and December 2025. According to the report, around $12.7 billion was stolen in a cryptocurrency investment scam from American victims in the US.

As per Treasury Department official Gene Lange, “The transnational criminal organizations behind these scams exploit both emerging technologies and human vulnerabilities, resulting in devastating financial losses for innocent American victims.”

The report is prepared on the basis of reports given by around 1,300 financial organizations and is linked to a 2023 alert from the Treasury about pig butchering scams. FinCen discovered that the rate of scam operations is rising as the schemes go beyond centers in Laos, Myanmar, and Cambodia. 

Scammers use distinct profiles, from financial adviser to romantic partner, and force people into sending money, either via cryptocurrency or with traditional bank transfers.

Significant reports were received from cryptocurrency firms, which found around $5.5 billion in suspicious scam activity. 

Traditional banks reported around $6.4 billion in possible friends, saying they “often detected schemes when a victim sent funds to an [financial institution] in the digital asset sector to purchase digital assets, or when a customer sent a wire transfer to a scam-affiliated beneficiary, frequently referencing digital asset investments.”

The report finds that few victims sent applications for second mortgages and loans as part of their involvement in a scam.

More financial institutions note thousands of incidents where targets liquidated their investment accounts to try wiring transfers or fund digital assess to scammer-related accounts. According to the report, “[A financial institution] involved in the digital assets sector reported an older adult victim transferred nearly $640,000 from her retirement fund to send to a suspected scammer in connection with an apparent digital asset investment scheme.”

“The victim stated she met an individual over social media who instructed her to invest in an apparently fictitious digital asset-related company.”

Another victim took out around $150,000 from his retirement account, withdrew credit on his home, and withdrew a personal loan to send the money to a scammer who pretended to be his digital romantic partner, and wanted to invest the money in a venture.

The filings noted the use of coins like USD Coin (USDC), Ethereum, and Tether (USDT), but 18 more coins were found in the reports.

Your Company's Phishing Tests Are Measuring the Wrong Thing

 



When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets renewed. But a major new study suggests that sense of relief may be completely misplaced.

Oslo-based cybersecurity firm Pistachio released its Phishing Behaviour Report 2026 this week, built from 2.47 million simulated phishing attacks sent to more than 123,000 employees across 1,200-plus organizations between June 2025 and May 2026. The finding that runs through all of it: the click rate, which most phishing programs live and die by, is the wrong thing to measure.

"A low click rate can create a false sense of security," said Joe Jones, CEO and co-founder of Pistachio. "What matters more is what happens next: does the employee hand over credentials, recognize the attack and stop, or report it so the wider business can act?"

A click alone does nothing. Credentials do.

Clicking a phishing link causes no damage on its own. The actual risk begins when an employee submits a password or other sensitive information into a fake login page after clicking. That is the moment a simulated test becomes a real-world breach scenario, and it is largely what most phishing programs do not track.

On their very first simulated phishing exercise, more employees in the Pistachio study reported the suspicious email than clicked it. That sounds like good news. The problem is that 1.57% handed over their credentials anyway. In a company with 500 employees, that works out to roughly eight people who will submit login details to a convincing enough lure with zero prior exposure. Click rate metrics would not flag any of them.


Tech workers are not the safe bet they are assumed to be

One of the more uncomfortable findings in the report concerns employees who are expected to know better. Tech development workers clicked at least one simulated phishing attempt at a rate of 30.27%. IT workers were not far behind at 28.53%.

The assumption that technical employees carry lower phishing risk because they understand how attacks work does not hold up against the data. Understanding how phishing operates and catching a convincing one under inbox pressure are two different things.

Construction carries the most risk. Financial services carry the least.

The gap between industries was wider than most organization-wide risk scores would suggest. Construction workers showed the highest click rate of any department at 41.31% and the highest credential leak rate at 16.47%. Design workers, by contrast, clicked at just 26.35%.

Financial services employees topped every resilience category in the study, which carries some irony. Financial services accounted for 27.7% of all observed phishing attempts in 2025, making it one of the most targeted sectors on the internet. That sustained pressure, combined with strict regulatory requirements and mandatory security training, appears to have produced genuinely more vigilant employees at the individual level.

Health workers showed the lowest reporting rate of any department at 13.17%, despite a relatively low click rate. Logistics workers combined an above-average click rate with a below-average reporting rate of 17.11%. In both cases, the click rate alone would present a more reassuring picture than the full data supports.


Things get worse before they get better

Organizations running 12-month programs saw click rates and credential submission rates both rise through the first six months before declining. That initial rise reflects harder and more frequent testing rather than employees regressing. At the six-month mark, employees were receiving an average of 3.5 simulations per person, with 50.4% classified as hard difficulty.

From that six-month peak to the 12-month stage, clicks declined by 27% and credential leaks by 41%. The report-to-click ratio increased from 1.3 at three months to 1.8 at 12 months, indicating that suspicious messages were reported nearly twice as often as they were clicked by the end of the program. 

Organizations that run a single phishing simulation and judge the program from that result are drawing conclusions from the noisiest and least reliable moment in the entire training cycle.


What to track instead

The report does not argue that click rates should be dropped entirely. It argues they should sit alongside credential submission rates and reporting rates, which together give a far more accurate picture of actual resilience. Making it easy for employees to report suspicious emails, through one-click tools and fast confirmation, converts the workforce into an active detection channel rather than a passive one.

NIST research found that 72% of organizations use phishing simulation click rates to gauge training effectiveness. By that measure, nearly three quarters of corporate security awareness programs are optimizing for an incomplete signal, in a threat environment where AI-driven phishing has pushed click rates among untrained employees to a record high of 54% in 2026. 

The click rate was never the whole story. At this point, relying on it alone is a liability.

Lost Phone Reporting Flaws Could Let Hackers Block Any Mobile Device for $4


A new security investigation has revealed serious weaknesses in the systems used by mobile carriers to block lost or stolen phones. Researchers found that an attacker could exploit these flaws to disconnect another person’s smartphone—or even a cellular-connected home alarm—from mobile networks for as little as $2.50 to $4. The attack reportedly took between 20 and 80 seconds, raising concerns about the reliability of a process designed to protect phone owners. 

When a customer reports a phone as lost or stolen, the carrier records the handset’s unique International Mobile Equipment Identity (IMEI) number in an Equipment Identity Register, or EIR. Mobile networks then use this database to reject the device and prevent it from registering for calls, messages and data services. The system is also designed to discourage theft because a blacklisted phone may become unusable, even if someone replaces its SIM card. However, researchers discovered that the process contains weaknesses across multiple layers. 

The study identified six flaws affecting devices, carrier reporting systems and the infrastructure used by telecom companies to exchange blocked-device lists. These weaknesses could allow criminals to submit fraudulent reports or manipulate information without proving that they own the targeted handset. In addition to smartphones, the problem may affect connected security systems and other Internet of Things devices that rely on cellular networks. A malicious actor could potentially disrupt a home alarm, surveillance system or other connected equipment by falsely reporting its IMEI as stolen. 

The findings highlight the risks of trusting a single identifier as proof of ownership. Although IMEI-based blocking can be useful, carriers may need stronger verification, better monitoring and faster recovery procedures for legitimate customers. Providers could require additional account checks, detect unusual reporting patterns and notify owners before permanently adding a device to a blacklist. They should also make it easier for customers to challenge fraudulent blocks and restore service quickly. 

For phone owners, the investigation is a reminder to secure accounts and keep evidence of ownership. If a device disappears, users should immediately activate Android’s Find My Device or Apple’s Find My service, remotely lock the handset and contact their carrier to suspend the SIM or eSIM. They should change important passwords, monitor banking accounts and report suspected theft to the police. Customers who discover that their device has been wrongly blocked should contact the carrier, request an investigation and provide purchase records, account details and the handset’s IMEI number.

Study Warns Enterprise AI Rollouts Are Outpacing Data Security Checks

 

Companies are adopting AI tools faster than they are testing whether their underlying data is appropriately secure, a new report from governance firm Syskit suggests. Based on a survey of 327 IT and security decision-makers at U.S. and U.K. organizations with at least 500 workers, Syskit's State of Microsoft 365 Governance Report, published Sept. 10, found that 76% of the companies surveyed had deployed or tested enterprise AI tools such as Copilot in their Microsoft 365 environments, but less than half (43%) had conducted a thorough review of file permissions and potential oversharing risks prior to deployment, and the rest skipped the review process or reviewed only partially.  

There was a similar gap for oversight over AI agents. While 91% of respondents said they were confident about their knowledge of what AI agents were and had access to, in practice, barely one in five companies (22%) had a formal policy outlining permitted agents' access, and roughly one in 10 (9%) had an agent that had inherited all the permissions of the person who had deployed it. "If you look at tools such as Copilot, you can see the value it can bring," said Syskit CEO Toni Frankola, noting that some content could be exposed purely based on permissions that had been set years ago and then simply forgotten about, and that AI had removed the friction that had previously prevented accidental exposure. 

"Permission audits may be the most critical and least desirable step in preparing a safe and secure AI deployment." The report also highlighted areas of weakness in Microsoft 365 environments overall. Roughly 41% of organizations had SharePoint sites that were publicly available with no access restrictions, 35% had visible files for past employees, and a third had files shared publicly with "Everyone." Ownerless content was the biggest concern, with 47% of organizations citing orphaned teams, groups and sites, which had no one accountable for reviewing or securing them, despite being accessible to an AI just as readily as any other content.  

"There seems to be a disconnect between confidence and reality with regard to the management and control of data and information," said Frankola. "While eight in 10 (83%) organizations feel confident that they know exactly who can access specific sensitive information, only 4% could provide a complete access report for an auditor within an hour if asked ... and more than half would need at least a day to prepare one." Perhaps most concerningly, 90% of organizations said they had suffered or suspected a security incident related to incorrectly configured permissions or excessive access in the last two years, and 39% confirmed that a security incident had definitely occurred.

Android Simplifies Secure Migration of Saved Logins


With the advent of Android's new credential transfer feature, passwords and passkeys can be transferred directly between supported password managers without the creation of an unencrypted file. This feature resolves a problem longstanding with migration. 

In the past, it was often necessary to export stored credentials into a text or CSV file that was unencrypted, so that a temporary copy could remain visible on the device while the password was transferred. Previously, users were not able to transfer passwords between password managers, requiring them to recreate them if they changed providers. 

The new transfer process is handled by Android itself. Migrations begin with the password manager receiving the credentials, and an import or transfer option is offered to initiate the migration. Upon identifying supported password managers installed on the device, Android passes control to the existing manager, allowing them to review and authorize credentials that have been selected for transfer. 

The new system facilitates the transfer of passwords and passkeys, eliminating the need to create plaintext credentials as part of the migration process. This approach aims to reduce the exposure of sensitive authentication data during the switch of password managers. 

With Android's new credential transfer feature, users can move passwords and passkeys directly between password management applications without having to create an unencrypted file in the process. This feature addresses the long-standing issue of migration between password management applications. 

Passwords were traditionally exported into an unencrypted text or CSV file when transferring stored credentials, creating a temporary copy that could remain exposed on the device while the passwords were being transferred. Passkeys, however, cannot be transferred between password managers, so users must recreate them when switching providers. New transfer procedures are managed by Android itself. 

When a password manager receives credentials, it will offer the option of importing or transferring credentials, which will initiate the migration process. Android identifies supported password managers on the device and passes control to those managers in order for the stored credentials to be reviewed and authorized for transfer. 

Passwords and passkeys can be transferred with this new system, removing the requirement to prepare a plaintext credential file during migration. This approach is intended to minimize the potential for exposing sensitive authentication information. 

Support Remains Limited

Four password managers are currently supported by the feature: Google Password Manager, 1Password, Bitwarden, and Dashlane Google has indicated that additional providers are planned, although no specific deadline has been announced. It will still be necessary to use conventional export and import methods when using password managers outside the supported group. This system utilizes a standardized credential exchange approach so that participating password managers can communicate through Android devices. 

Additionally, migration support for passkeys is now available, removing the barrier that previously existed when changing password management services. This feature is accessible on Android 8 or later devices, allowing older supported devices to benefit from this capability, rather than being restricted to recent releases. 

The change is part of a larger effort by Google to improve the security of account information and device migration. The Android platform also includes requirements that are intended to improve the way applications restore the state of their sign-ins when users switch devices. During device migration, eligible applications will use Android's Restore Credentials API to restore authentication under the Zero-Tap Sign-In standard. 

With the introduction of this system, supported applications will be able to recognize existing sign-in states on new devices without requiring additional login steps. Google plans to begin enforcing the Zero-Tap Sign-In requirement by April 2027 while that initiative focuses on application authentication during device upgrades, the password-manager feature allows credentials to be transferred between different password management services. 

There are currently limited provider support options, however, wider adoption could facilitate easier transitions between password managers while reducing the security risks associated with manually handling exported credentials.

Featured