Hackers, dubbed “Scattered Spider”, are targeting insurance and financial enterprises with cloud service attacks to steal data and demand ransom. The hackers’ methods include searching services like GitHub for cloud access tokens accidentally left in source code by programmers. The stolen data is exfiltrated and a ransom demanded for its return. Admins can protect against such attacks by enabling multi-factor authentication (MFA) and ensuring staff can recognise phishing attempts.

Trend Micro Apex One Vulnerability Allow Attackers to Inject Malicious Code
Trend Micro’s Apex One platform has multiple critical vulnerabilities, allowing code injection and privilege escalation. Emergency patches were released on June 9, 2025, for five