IBM’s annual Cost of a Data Breach Report finds that the average global breach now costs $4.44 million. For the first time, the study highlights a sharp gap between rapid AI adoption and lagging AI security and governance, with 13% of organizations reporting AI-related breaches. This signals that AI is becoming an attractive target for attackers, while oversight and controls remain underdeveloped in many organizations.
Source: Help Net Security
Lazarus Group Targets Developers with Malware-Laden Fake Open Source Software
North Korea’s infamous Lazarus Group has shifted tactics, distributing malicious open source software that infects developer devices. Security researchers warn that the group has crafted hundreds of "shadow downloads" posing as legitimate tools, drastically expanding the risk to the global supply chain and endangering organizations that trust community-contributed code.
Source: The Register
Akira Ransomware Exploits Suspected Zero-Day in SonicWall VPNs
The Akira ransomware gang is exploiting a likely zero-day vulnerability in fully patched SonicWall SSL VPN devices, according to Arctic Wolf Labs. Intrusions were observed during late July, demonstrating once again that even up-to-date perimeter devices can be vulnerable to novel and sophisticated exploits, with ransomware operators increasingly targeting VPN infrastructure.
Source: Security Affairs
Microsoft Windows Users Targeted by Malicious JPEG Images Disguised as Photos
A new warning for Microsoft Windows users: attackers are distributing JPEG images loaded with malware to compromise unsuspecting systems. These tainted image files, shared online or via phishing campaigns, can trigger remote code execution simply upon opening, emphasizing the need for secure media handling and updated anti-malware protections.
Source: Forbes Security
Massive Data Breach Impacts 350,000 Northwest Radiologists Patients
Northwest Radiologists has announced that a January 2025 data breach compromised the personal data of 350,000 Washington State residents. The breach highlights persistent threats targeting healthcare providers, where the sensitive nature of patient data makes the sector a perennial favorite for criminal actors.
Source: SecurityWeek
Mozilla Warns of Targeted Phishing Campaigns Against Extension Developers
Mozilla is alerting browser extension developers to a current phishing campaign targeting accounts on the official AMO (addons.mozilla.org) repository. Attackers seek to compromise developer accounts, potentially leading to the distribution of malicious browser extensions through trusted channels and expanding the threat to millions of end-users.
Source: Bleeping Computer
PlayPraetor Android Trojan Infects Over 11,000 Devices in Aggressive Campaign
The newly discovered PlayPraetor Android remote access trojan (RAT) has infected more than 11,000 devices worldwide, primarily across Europe and South America. Spreading rapidly through fake Google Play pages and Meta ads, this botnet underlines the evolving sophistication of malware targeting mobile platforms and the risks associated with third-party app downloads.
Source: The Hacker News
You May Also Be Interested In...