A phished employee credential gave an attacker access to a Brooklyn defense supplier's Microsoft 365 mailbox, exposing engineering files and export-controlled data tied to Patriot and THAAD programs, IEH told the SEC.
Trezor Warns of Phishing Risk After ShipMonk Breach Exposes 14,000 Customers’ Data
Trezor says a breach at its shipping partner ShipMonk exposed contact details for nearly 14,000 customers via a Metabase zero-day, and is warning that the leaked names, emails and addresses raise the risk of convincing phishing attacks impersonating Trezor, banks and exchanges.
Adobe’s BPO Breach: One Phished Support Agent Extracted 13 Million Records and Unpublished Vulnerability Reports
A phished support agent at a third party BPO vendor allegedly let an attacker export 13 million Adobe support tickets and unpublished HackerOne vulnerability reports, exposing a bulk export flaw with no rate limits or alerts, according to Security Boulevard.
Megalodon: The GitHub Supply Chain Attack That Compromised 5,500 Repositories in Six Hours Flat
Six hours. 5,500 compromised repositories. The Megalodon campaign represents a massive escalation in supply chain attack velocity, targeting GitHub Actions workflows to silently exfiltrate production cloud secrets. Here is why your current security review process might be missing this critical automation blind spot.



