Binance founder Changpeng Zhao warned that a data breach at Trezor's shipping partner ShipMonk, which exposed 13,689 customers' names and addresses, hands attackers a ready-made list for phishing and physical targeting.
Shell Investigates Data Breach as Cl0p Claims 89GB Theft, Names Nearly 50 Companies
Cl0p's extortion gang claims to have stolen 89 gigabytes of engineering data from Shell and listed nearly 50 companies, including Philips and GE, on its leak site. The likely entry point: a critical, patched flaw in PTC Windchill and FlexPLM.
Phishing Service Spoofs RingCentral to Steal Microsoft 365 Accounts
A phishing-as-a-service kit called Greatness is spoofing RingCentral voicemail alerts to slip past whitelisted email filters, then stealing Microsoft 365 credentials through token relay attacks or device-code phishing that needs no fake login page.
Cyber Police Crack Down on Pension Fraud Gangs Preying on India’s Retirees
Cyber police in Haryana and Odisha have arrested eleven people across two gangs that impersonated pension officials to defraud retirees of their EPF, GPF and life certificate payouts, with one victim losing nearly $9,800 to a single fake call.
Australia’s ASD Warns of Ongoing Russian Zero Click Phishing Campaign Targeting Zimbra Webmail
Australia's ASD joined fifteen other nations warning that Russian group Laundry Bear is running a zero click phishing campaign against Zimbra webmail users, stealing up to ninety days of email without a single click, according to the UK's NCSC.




