Last week’s cybersecurity news highlighted infostealer-driven account takeovers, active exploitation of flaws in products like Microsoft Exchange, SonicWall SMA 1000, PaperCut, and Sangoma Switchvox, and major data breaches affecting McKesson and Thomson Reuters. It also showed attackers abusing OAuth phishing, Microsoft Teams vishing, fake Claude apps, and AI-related tricks to steal credentials, evade detection, and interfere with malware analysis. #Anthropic #Claude #McKesson #MicrosoftExchange #SonicWallSMA1000 #PaperCut #SangomaSwitchvox #ThomsonReuters #RevStealer #SpringRing
Keypoints
- Anthropic locked out Claude users after infostealers compromised login sessions.
- Attackers are exploiting flaws in Microsoft Exchange, SonicWall SMA 1000, PaperCut, and Sangoma Switchvox.
- McKesson and Thomson Reuters disclosed breaches exposing sensitive records and personal information.
- Threat actors used OAuth phishing and Microsoft Teams vishing to gain persistent access.
- Fake Claude apps, AI crawler impersonation, and malware analysis tricks show growing abuse of AI themes.