A major security breach targeting executives via Microsoft’s Azure cloud service has compromised hundreds of accounts, exposing critical user data. The attackers employed a phishing campaign from a 2023 hack, utilising credential theft and cloud account takeover and geographical masking. They installed their own multi-factor authentication to secure prolonged access and removed traces of their activity where possible. The attack, thought to originate from Russia and Nigeria, aimed at data theft and financial fraud.

Hackers Launch Social Engineering Offensive Against Key Node.js Maintainers
Following the high-profile supply chain compromise of the widely used Axios package, a highly coordinated social engineering campaign has been uncovered targeting top-tier Node.js and


.webp?w=0&resize=0,0&ssl=1)