Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Kimsuky Brings AI Closer to Its Malware and Phishing Operations

  North Korean cyber-espionage group Kimsuky appears to be moving beyond occasional use of public AI services by assembling a local artific...

All the recent news you need to know

Tanaka Emerges as Leading Data Leak Broker as Stolen Information Fuels Cybercrime

 

Ransomware attacks are undoubtedly one of the most notorious security threats today. Yet it seems that information itself has become a very popular target among cybercriminals. Particularly, the threat actor called Tanaka has appeared to be the most successful data dealer during the first half of 2026, according to the research conducted by Cyble. Overall, 367 confirmed cases of corporate data leaks or breaches happened worldwide during the first half of 2026, the experts from Cyble have found. 

While the activity of Tanaka appeared to be less prominent than that of many well-known ransomware groups, he has been the most active data dealer according to Cyble research. His activity has resulted in 25 leak posts, which is more than double than the number of posts of other famous data-leak organizations. The threat actor has been targeting organizations in various fields, pursuing different goals. While the Banking, Financial Services and Insurance sector remained the most attractive for criminals with 38 data breach incidents recorded, governments and technology companies have also been frequently targeted by Tanaka. 

It implies that data theft is no more limited by regional or economic factors and can happen to organizations of any size or any industry. In particular, Tanaka has been very active in North America, where 7 leak posts related to the criminal have been discovered this year. Meanwhile, Europe and the UK have witnessed 6 leak posts related to Tanaka, as well. In these regions, financial services, telecom, and retail companies have experienced the most significant challenges, as customer and financial data of these organizations are highly attractive to data prospectors. 

In general, data prospecting has become a significant threat to organizations worldwide, as there are now more opportunities to benefit from the data belonging to other organizations. It is a part of the ransomware attack chain, as ransomware criminals can use the data belonging to the victim as leverage to demand more significant ransoms. However, data extortion is not the only way to monetize data theft, as leaked databases can be further sold on dark web forums and marketplaces. 

In addition, the stolen data can be used for extortion, reconnaissance, and other nefarious purposes. It is necessary for companies to realize that the detection of one’s data being sold or showcased on underground forums should be treated as a serious security incident. It can be a sign of the potential ransomware attack, which should be responded to accordingly. Monitoring the dark web for signs of reconnaissance activities is one of the essential aspects of cybersecurity, which is why professionals may want to consider detecting their organization’s potential exposure to ransomware attackers.

Firefox 153 Bakes Multi-Account Containers Into the Browser for Smarter Privacy

 

Firefox has long been praised for its privacy-first approach, but managing multiple digital identities used to require workarounds. With the July 2026 release of Firefox 153, Mozilla has natively integrated one of its most powerful privacy extensions—Multi-Account Containers—directly into the browser. This move eliminates the need for separate profiles, constant sign-ins, or third-party extensions, offering a seamless way to isolate browsing sessions within a single window. 

The core innovation lies in how Firefox Containers handle cookies and site data. Each container operates with its own isolated storage, meaning logging into one Google account in a “Work” container won’t interfere with a personal Gmail session in another. This separation prevents websites from sharing login states or tracking users across different contexts. For professionals juggling multiple accounts—be it for work, banking, or shopping—this feature drastically reduces friction while enhancing privacy. 

Setting up native Containers is straightforward. Users can right-click any tab or long-press the new tab button to access options like Personal, Work, Banking, and Shopping. Each container is color-coded and icon-tagged for easy identification, even when dozens of tabs are open. Links opened within a container stay within that container, preserving session isolation automatically. This intuitive design ensures that once configured, Containers operate quietly in the background without disrupting normal browsing habits.

Despite its advantages, the native implementation is still in preview and lacks some features found in the original extension. Notably, automatic site assignment—where specific domains always open in a designated container—is absent. Cross-device sync and integration with VPN or proxy services are also missing. However, for most users, the built-in version offers sufficient functionality without the overhead of installing and maintaining an add-on. Mozilla’s decision to embed this tool natively lowers the barrier to entry, making advanced privacy accessible to a broader audience. 

Firefox’s native Containers represent a significant step forward in user-centric privacy design. By isolating digital identities at the browser level, Mozilla empowers users to compartmentalize their online lives without sacrificing convenience. While not a complete anonymity solution—Containers don’t hide IP addresses or prevent fingerprinting—they complement existing protections like Enhanced Tracking Protection and Private Browsing. For anyone seeking better control over their digital footprint, Firefox 153’s built-in Containers offer a practical, powerful, and privacy-respecting browsing experience.

Gen Threat Report Highlights H1 Global Threat Landscape


The Gen Threat Report is a twice-a-year analysis of the largest cyber threats impacting the digital threat landscape, providing a detailed insight into the trends impacting customers globally. The H1 report has provided some key insights. 

“The strongest pattern in the first half of 2026 was the way different threats converged around trust. Scams, account takeovers, malicious packages and AI agents all moved closer to the systems, workflows and permissions people already rely on,” said the report

46% of Gen threat findings were scams, whereas malvertising amounted for 30%. Gen stopped 114.2 million e-commerce scams and 20.3 million tech support scams.

These numbers are important, but they fit different kinds of scams into a few categories. A discovery does not reveal how the first trap became script execution, or how the script turned into a proxy change or browser, or how a wallet address was changed before the target verified a transaction.

Two important H1 findings

Two H1 investigations should be looked at in-depth. The first is a banking-malware campaign initiated with hacked corporate mailboxes and finished with browser manipulation and proxy. 

In the second finding, a cryptocurrency campaign deployed a Rust-based clipper and got C2 infrastructure pointers from Binance Smart Chain. 

The payloads are distinct, but none of the campaigns relied on breaking the genuine system at user end. The banking malware used a genuine account to set the trap whereas the clipper allowed the blockchain record an authentic transaction after modifying the local destination address.

Where did the business email come from

The banking campaign attacked users in Lithuania, Poland, Slovakia, and Czechia. The lures appeared to be genuine business emails such as invoice messages, scanned document verifications, and shipment notices. 

In various incidents, the texts were sent from hacked corporate mailboxes. The email was not designed to appear as if it came from an authentic organization. The emails were sent from an authentic account that threat actors had already hacked. 

DKIM and SPF can still sail through when a message is sent via genuine infrastructure, whereas reputation systems may spot a sender with an authentic history. 

The attachment deployed a JavaScript dropper, and then the chain travelled via PowerShell stages before reaching banking functionality and shellcode. The available signs indicate at GepyS.

The malware changed proxy settings and deployed a browser add-on, positioning itself nearby to the target’s banking session.

Levi Strauss & Co. Confirms Hackers Stole Corporate Data in Cyberattack

Levi Strauss & Co. (Levi’s) has announced a cybersecurity incident involving an unauthorized third party who used social engineering to access the company's systems and exfiltrate corporate information from the systems of three employees. The clothing giant disclosed the incident in its filing with the U.S Securities and Exchange Commission (SEC). According to the SEC's investigation, certain corporate information was accessed and exfiltrated during the attack. 

Several employees were targeted by the attackers through social engineering, which gave them access to their systems without their consent. Levi Strauss has not disclosed the precise social engineering technique used by the threat actor, or whether the threat actor made any extortion demands, but this incident specifically affected three company-provided computers. Levi Strauss stated that its security teams responded quickly to contain and terminate the unauthorized access. 

According to Levi Strauss' preliminary investigation, it is not believed that customer information has been stolen. In addition, the company stated that the incident did not disrupt operations for the company. Levi Strauss stated in its SEC filing that, based on preliminary findings from the Company's investigation, it believes that some corporate information has been accessed and exfiltrated as a result of the incident. Levi Strauss expects the incident to have no material impact on the company's financial position or business based on its preliminary findings so far. Levi Strauss will provide additional notifications as additional information becomes available. 

The Levi Strauss & Co. (Levi’s) apparel company, one of the world's most recognizable companies, employs approximately 19,000 people and operates over 3,300 stores. The products are also available through third parties and online platforms. Levi Strauss has not identified the threat actor responsible for the intrusion or revealed whether the company received any extortion demands from the attacker. Unconfirmed reports suggest that the hacker may have been associated with UNC6671, a hacking group that has been associated with recent voice phishing attacks. 

According to Levi Strauss, the attribution has not been confirmed, and it remains unclear what tactics were employed in the attack. There is a general indication that the Levi Strauss incident occurred at the same time as a broader wave of voice phishing and social engineering attacks targeting major organizations. 

According to Google and other internet intelligence sources consulted by Reuters, ransom-seeking attackers were attempting to compromise victims through phone calls in recent weeks by targeting dozens of prominent financial institutions and other organizations in the United States. Levi Strauss was among more than 200 companies targeted with digital traps over the course of five weeks with the same intelligence. Levi Strauss has not confirmed the possible connection, and the attackers, the specific corporate information stolen, and the method of targeting employees are still under investigation. 

Despite the company's assertion that customer information was not compromised, the incident demonstrates the continuing threat posed by social engineering and phishing attacks. Organizations continue to be vulnerable when attackers can manipulate employees into providing access to corporate systems and information. 

In response to the attackers' attempt to gain access to the compromised computers, the company immediately responded and contained them. Levi Strauss has not reported any interruption to its business operations and does not believe the incident has, or is reasonably likely to have, a material impact on its financial or business position at this time. 

Despite the breach, Levi Strauss has not reported any operational impacts and continues to investigate the incident. Levi Strauss' incident illustrates the growing threat of voice-phishing and social engineering attacks against large corporations. Although the company has indicated that the customer data was not compromised, the ongoing investigation emphasizes the need for employee awareness, access controls, and rapid response to targeted cyberattacks to limit their impact.

China's New Challenge: Fake AI Videos During Natural Disasters

 

As China grapples with intensified storms and flooding over recent months, authorities face an unexpected secondary crisis: a surge of AI-generated fake videos flooding social media platforms. These manipulated clips, ranging from fabricated rescue operations to false claims of casualties, are causing real-world panic and complicating emergency response efforts. 

The misinformation wave includes highly realistic but entirely synthetic content. Videos have depicted bodies floating in floodwaters, crocodiles escaping into rivers, and collapsed infrastructure in areas untouched by disasters. Some creators edit overseas or historical footage, stripping watermarks and altering subtitles to present old events as current emergencies. Others use generative AI tools to produce convincing scenes of overflowing dams, emergency vehicles, and even fictional witness interviews.

This deluge has tangible consequences. In certain regions, false videos claiming imminent power outages triggered panic buying of emergency supplies. Misleading content about rescue operations has undermined public trust in official responses. The Chinese government has identified specific cases, such as a flood rescue video and footage of "released crocodiles," as examples of AI-generated material deliberately misrepresenting the situation to mislead the public. 

Government crackdown and enforcement 

In response, Chinese authorities launched a nationwide campaign on July 23 to remove illegal and harmful disaster-related online content. The Cyberspace Administration of China and the Ministry of Emergency Management issued a joint notice targeting misleading footage, recycled reports, fabricated data, fake official announcements, and AI-generated material. Police have arrested and penalized numerous individuals, with punishments ranging from detention to fines. Under the "Clean Net 2026" campaign, the Ministry of Public Security's Cybersecurity Bureau detailed 20 cases involving AI tools used to create fake videos, repackaged flood footage from other regions, and fabricated disaster claims to attract online traffic. 

One notable case involved a 45-year-old man from Chengde, Hebei province, who created an AI-generated video claiming heavy rain caused ground collapse in Kuancheng county, sending vehicles into water. Posted on WeChat to gain followers, the video triggered widespread online discussion, caused local panic, and disrupted flood prevention efforts. 

Experts attribute the problem to dramatic advances in generative artificial intelligence. Modern AI systems can now generate highly convincing disaster scenes, imitate news broadcasts, and produce realistic content with minimal technical skill. As Professor Chen Bing noted in an article for the Central Party School's Study Times, the barrier to creating rumors has significantly lowered: content generators need only capture hot topics and use AI tools to rapidly produce text, images, audio, and video, with even "one-sentence commands" yielding deceptive information that fuels mass rumor production. 

Social media platforms face pressure to strengthen content review mechanisms. Authorities urge the public to approach disaster-related information from unknown sources with skepticism and rely on official announcements. Police emphasize trusting accredited sources during emergencies, though identifying AI-generated content remains increasingly difficult. As Typhoon Maysak and other recent weather events continue to affect regions like Guangxi province—where at least four died and 62,000 were evacuated—the battle against misinformation has become as critical as the physical disaster response itself.

Bank of Baroda Data Breach: What We Know About the Alleged 1TB Dark Web Leak

 



Bank of Baroda has confirmed a cybersecurity incident involving a compromised employee email account after reports emerged that nearly 1TB of data allegedly linked to the state-owned lender had been published on the Dark Web.

The bank said the compromised account resulted in unauthorised access to certain data, but clarified that its core banking systems were not accessed and continue to remain secure. It said the incident was identified promptly, containment measures were implemented, and a comprehensive forensic investigation has been launched in coordination with relevant authorities.

The confirmation followed reports from the X account DailyDarkWeb and cybersecurity researcher Srikanth Lakshmanan, founder of CashlessConsumer, who flagged an alleged large-scale data dump connected to Bank of Baroda.

According to the claims, the dataset contains personal and corporate banking records, including savings and current account information, loan records, NetBanking users, NRI and corporate banking services, customer-support documents, and records linked to branches and ATMs. Reports from researchers also said the material included customer details, identification documents and internal audit records.

Samples and download links were reportedly shared alongside the threat actor's claim of possessing approximately 1TB of data.

However, the size of the alleged dataset has not been independently established by Bank of Baroda. Reuters reported that the Dark Web listing was advertised as a cache exceeding 700GB based on metadata analysis conducted by Lakshmanan. The number of customers whose information may have been exposed also remains unknown.

This distinction is important. The appearance of a large archive online does not, by itself, establish that every file originated from Bank of Baroda or that the entire advertised volume was successfully exfiltrated from the bank.


What allegedly appeared in the data dump?

The initial claims described a wide range of banking information. This reportedly included savings and current account records, loan-related documents, NetBanking information, NRI and corporate banking records, customer-support material, and branch and ATM data.

Other reports said samples contained highly sensitive information such as Aadhaar details, customer names, loan documents and other identity-related records. Some reports citing the claims placed the number of customer application forms potentially involved between 100,000 and 300,000. These figures remain allegations and have not been confirmed by Bank of Baroda.

Lakshmanan also shared screenshots that he said showed the root folder of the alleged data dump and reported that the download link was active. He described the incident as a "cyber disaster" and called for the Reserve Bank of India (RBI) and National Payments Corporation of India (NPCI) to consider disconnecting the bank's systems while the extent of the compromise was investigated.

At the time of those warnings, the source and method of the alleged data theft were unclear.

Bank of Baroda's subsequent statement has now provided an important piece of that picture.


Employee email account was the confirmed entry point

According to the bank, the confirmed incident involved the compromise of an employee's email account. The account was then used to obtain unauthorised access to certain data.

Bank of Baroda has not disclosed how the email account was compromised, what specific files were accessed, or whether all of the data advertised on the Dark Web originated through that account.

The lender has, however, clearly stated that its core banking systems were not accessed and remain secure.

That distinction matters because compromising an employee's email account is not the same as compromising the systems that process customer transactions.

At the same time, an email account inside a large financial institution can provide access to highly sensitive material. Depending on the employee's role and permissions, an account may contain customer correspondence, loan documents, identity records, internal reports or links to shared resources.

The incident therefore demonstrates how an attacker may be able to obtain valuable financial information without directly breaching the core platform responsible for banking transactions.


Customer risk extends beyond stolen funds

There is currently no public evidence that the alleged incident allowed attackers to directly access customer balances or manipulate transactions. Bank of Baroda has specifically said that its core banking systems were not accessed.

The potential exposure of personal and financial records nevertheless creates a separate risk.

Information such as customer names, identity documents, account-related details and loan records could give criminals material for highly targeted phishing and impersonation attempts. A scammer with genuine information about a customer's banking relationship can make fraudulent calls, emails or messages appear far more credible.

Customers should therefore be particularly cautious of communications claiming to originate from Bank of Baroda and requesting OTPs, passwords, PINs, card information or remote access to devices.

The reported leak should not automatically be interpreted as evidence that customer funds have been compromised. The more immediate concern, if the exposed records are genuine, is the possibility of follow-on fraud using information that customers would normally expect their bank to protect.


Forensic investigation now underway

Bank of Baroda said it has initiated a comprehensive forensic investigation to establish the nature and extent of the incident. The bank also said it is working with relevant authorities in accordance with applicable regulatory requirements.

Several key questions remain unanswered.

Investigators will need to determine how the employee's email account was compromised, what information was accessible through it, how much data was actually accessed or exfiltrated, and whether the Dark Web archive corresponds to the confirmed incident.

The investigation will also need to establish how many customers, if any, were affected.

The incident has already generated financial implications for the lender. The Economic Times reported that Bank of Baroda notified a preliminary cyber-insurance claim under a programme with total coverage of approximately ₹750 crore, with National Insurance Company serving as the lead insurer. The notification is an intimation of loss while the forensic investigation continues and does not represent a confirmed ₹750 crore loss.

The financial consequences of a data breach can extend beyond direct theft. Forensic investigations, remediation, legal costs, regulatory responses, customer support and other incident-response expenses can all contribute to the eventual cost.


Regulatory questions remain

The incident also places renewed attention on cybersecurity controls within India's banking sector.

CERT-In's directions under Section 70B of the Information Technology Act establish requirements for information-security practices, incident response and cyber-incident reporting.

Bank of Baroda has said it is cooperating with relevant authorities, although the public details of its regulatory notifications have not been disclosed.

For now, the most important distinction is between what has been confirmed and what remains alleged.

Bank of Baroda has confirmed that an employee's email account was compromised and that the incident resulted in unauthorised access to certain data. It has also confirmed that its core banking systems were not accessed.

The claim that approximately 1TB of Bank of Baroda information was leaked, the precise contents of the Dark Web archive, and the number of customers potentially affected remain subject to investigation.

What began as an alarming Dark Web claim has therefore evolved into a confirmed security incident with an unresolved scope. The forensic investigation will determine whether the reported hundreds of gigabytes of banking information represent the full extent of the compromise, a smaller subset of genuine Bank of Baroda data, or a mixture of both.

Featured