From BleepingComputer · 19 stories
Kubota reveals month-long hacker access to employee data
Kubota North America announced that hackers accessed employee data for over a month this year. The breach exposed sensitive information such as Social Security numbers and bank details, prompting the company to enhance its security measures.
Criminal IP Enhances OpenCTI with Contextual Cyber Threat Intelligence
Criminal IP integrates with OpenCTI to enrich IP addresses, domains, and URLs with intelligence data. This enhancement allows security teams to better investigate, correlate, and prioritize potential cyber threats.
Delta Investigates Fake Wi-Fi Network Incident on Flight from Las Vegas
Delta Air Lines is investigating an incident on Flight 591 from Las Vegas to Atlanta where an unauthorized Wi-Fi network, allegedly created by a passenger, appeared mid-flight. The network, named "Delta WiFi Fast," reportedly spoofed the legitimate in-flight Wi-Fi and may have attempted to phish for credentials, leading pilots to alert air traffic control and temporarily disable the aircraft's Wi-Fi.
Modern Attack Chains Bypass Email as Primary Entry Point in Google Workspace
Recent breaches, including Vercel and Composio, demonstrate a shift in attack methodology where email is no longer the sole entry point into Google Workspace. Attackers are now using OAuth grants to access accounts, read sensitive data, and move laterally within the workspace, a pattern that also describes how AI agents operate.
Levi Strauss & Co. Reports Corporate Data Exfiltration After Social Engineering Attack
Levi Strauss & Co. disclosed that hackers accessed and exfiltrated corporate information from three employee computers through a social engineering attack. The company stated that the incident did not disrupt business operations and found no evidence of consumer data exposure, but the specific corporate data taken was not disclosed. The company believes the incident will not materially impact its business.
Analog Devices Discloses Data Breach, Files Exfiltrated
Semiconductor company Analog Devices reported a data breach detected on June 23, where an unauthorized party accessed systems and exfiltrated certain files. The company stated that operations were not disrupted and the incident is not expected to materially impact its business, though it is also assessing public reports of a separate cybersecurity matter from July 26.
Fake Remote Workers Exploit Hiring Processes to Infiltrate Corporate Networks
Security teams face a growing threat from fraudulent remote workers who exploit hiring processes to gain legitimate access to corporate networks. These individuals, sometimes linked to state-sponsored groups like those from North Korea, use various tactics to impersonate legitimate hires and exfiltrate sensitive data or conduct cybercriminal activities. This issue highlights a gap in identity verification during remote hiring, where traditional checks do not confirm the actual user of an account or device.
AI Increases Efficiency of Account Takeover Attacks, Device Trust Becomes Crucial
AI is making existing identity attacks, such as phishing and credential theft, more efficient and scalable, rather than creating new attack types. This development necessitates a shift towards device trust as a critical Zero Trust measure to validate login legitimacy beyond just credentials. The increased automation of personalized attacks makes it harder to distinguish malicious logins from legitimate ones, highlighting the need for stronger authentication methods.
AI-powered phishing renders traditional blocklists ineffective due to rapid infrastructure rotation
Attackers are using AI to generate phishing pages and rapidly rotate infrastructure, making traditional blocklists and indicator-based detection methods obsolete. Phishing domains now have an average lifespan of less than two days, outpacing the ability of blocklists to track them. This shift necessitates new defense strategies against evolving phishing tactics.
BTMOB Android RAT Malware Ecosystem Expands Beyond Original Operator's Control
Research reveals the BTMOB Android Remote Access Trojan (RAT) has evolved into a complex underground business with multiple resellers and independent operators, making it difficult for the original creators to control. This expansion signifies a growing challenge in tracking and mitigating the spread of this malware-as-a-service.
Attackers Establish Persistence and Reconnaissance After Initial Breach, Huntress Reports
Huntress investigated a June incident where an attacker, after gaining initial access via SQL injection, spent time establishing persistence and performing reconnaissance rather than immediately exfiltrating data or deploying ransomware. This behavior highlights the importance of post-breach cleanup and understanding attacker dwell time to prevent further compromise.
FedRAMP 20X Shifts from Narrative-Based to Continuous, Machine-Readable Security Evidence
FedRAMP 20X is replacing the previous Rev5 framework, moving from narrative-heavy control descriptions to requiring continuous, machine-readable evidence for Key Security Indicators (KSIs). This change fundamentally alters how organizations demonstrate security posture, demanding systems capable of producing trustworthy evidence continuously rather than just for annual audits.
Research Reveals Evolving Use of Residential Proxies in Carding Operations
Flare researchers analyzed 2,889 underground posts to understand how carders are utilizing residential proxies. The findings indicate that while residential IP addresses are critical, they are increasingly seen as unreliable and require careful selection and combination with other digital identity tools.
AI Tools Facilitate Service Desk Attacks, Highlights Need for Enhanced Security
IBM's report indicates that 16% of data breaches involved AI tools, often for social engineering attacks at service desks. This trend makes it essential for organizations to improve identity verification processes to protect sensitive operations from AI-enabled impersonation.
Rise of Vibe Coding Increases Software Development Speed, Raises Security Concerns
The emergence of Vibe Coding has accelerated software development, allowing real-time application creation. This shift toward rapid development challenges organizations to ensure security measures keep pace with accelerated deployment practices.
Former Brightly Software Analyst Sentenced to Prison for Data Theft and Extortion
A former data analyst contractor for Brightly Software received a two-year prison sentence for stealing sensitive company data and attempting to extort $2.5 million from his employer. The individual threatened to leak payroll information and personally identifiable information (PII) after his contract was not extended, leading to a federal investigation and conviction.
Webinar Highlights Behavioral AI for Modern Email Security Threats
BleepingComputer is hosting a webinar on July 8, 2026, focused on the limitations of traditional email security against evolving threats like phishing and business email compromise. Experts will discuss how behavioral AI can automate the detection and response process, addressing attacks that leverage trusted identities and legitimate workflows.
FileJump offers lifetime 2TB cloud storage plan for $59
FileJump has launched a lifetime plan providing 2TB of cloud storage for a one-time fee of $59. This plan includes zero-knowledge encryption and a drag-and-drop interface, making it an affordable option for new users seeking secure data storage.
Securing Single Sign-On Against Credential Attacks
Single Sign-On (SSO) systems, while convenient, concentrate risk, as demonstrated by the 2025 University of Pennsylvania breach where a compromised SSO account led to data theft. Organizations must secure SSO by implementing strong password policies and multi-factor authentication to mitigate these risks. This matters because proper SSO security is crucial for protecting multiple systems and user data from credential-based attacks.