.png?width=720&quality=80&disable=upscale)
A former IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages. [...]
Adaptive Security recruited Conan O'Brien for cybersecurity training videos aimed at helping employees recognize phishing deepfakes and AI-enabled fraud.

Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]
Hidden inside a building in Alabama, the FBI has created its own small town as a dedicated cyber training ground for simulating cyberattacks.
Plus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more.
Researchers from Tokyo Metropolitan University have created a new paradigm for identifying online phishing campaigns. Their new system, PhishLumos, is triggered when links show signs of concealing information and looks for clues in the "infrastructure" of the website to uncover the whole campaign of which the site is only a tiny part. Real-world testing showed detection that was eight days faster…
No battery lasts forever. But it's often in your power to extend its life. Here's our checklist for identifying the causes of battery degradation - and how to fix each one.
A major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing gobs of data.

Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future. [...]
Vulnerability in the Oracle-owned PeopleSoft software is about as critical as they come.

Congress, afraid of empowering Bill Pulte, has allowed a decades-old spying law to lapse.

Iowan’s scheme undone after misplacing trust in former coworker
A 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators. [...]
A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. [...]
Millions of clients have valuable data exposed after drive goes missing.

Apple and Google have until September to either activate built-in features or implement new scanning tools. Privacy advocates are raising the alarm, but the government is ready to "change the law" if needs be.

Nightmare-Eclipse's vendetta against Microsoft and Windows continues apace — researcher publishes RoguePlanet and GreatXML local privilege escalation zero-day exploits

GitHub access sales, leaked repositories, and stolen API keys can all become supply-chain attack footholds. Flare explores how underground forums expose early signals tied to software supply-chain risk. [...]
Clinical trial participant data stolen, but pharma giant says exposed records were pseudonymized
Also covering:The Register
Also covering:The Register