City-Forum campaign targets exposed Salesforce and ServiceNow data
There is no evidence that City-Forum is operated by ShinyHunters, although some of the Salesforce techniques resemble earlier ShinyHunters campaigns.
In brief: Microsoft fixed a zero-day, Russian hackers targeted two power plants in Poland last year; and more.
There is no evidence that City-Forum is operated by ShinyHunters, although some of the Salesforce techniques resemble earlier ShinyHunters campaigns.
Researchers found that DeadLock uses the Polygon blockchain to store configuration data and information used by its leak site.
The attackers used path traversal techniques before installing a malicious cron job to maintain access.
Mozilla said the risk of a supply chain attack is low because access to the repository was limited to a small group of employees.
Check Point said the North Korean Lazarus group exploited CVE-2026-68820 to deploy the FudModule kernel-mode rootkit.
Gunra also exploits credential-exposure and SSH access control security flaws in internet-facing VPN gateways to gain remote access to victims' systems.