Microsoft announced that it will enforce mandatory multi-factor authentication (MFA) for all sign-in attempts to the Azure portal and other administrative interfaces. The new requirement, which builds on Microsoft’s long-standing commitment to security, aims to block unauthorized access to high-value cloud resources by adding an extra layer of verification beyond passwords. According to Microsoft’s own research, enabling […]
The Wireshark Foundation today announced the release of Wireshark 4.4.9, delivering critical stability improvements and updates to its protocol dissectors. This incremental release, the ninth maintenance update in the 4.4 series, addresses a high-priority security issue and resolves multiple decoder flaws affecting enterprise and academic users alike. Key Security and Stability Fix The release fixes a […]
A sophisticated new keylogger malware dubbed “TinkyWinkey” that is targeting Windows systems with advanced stealth capabilities and comprehensive data exfiltration features. First observed in late June 2025, this malware represents a significant evolution in keylogging technology, combining multiple attack vectors to maintain persistence and avoid detection. TinkyWinkey operates through a dual-component architecture that maximizes both […]
Cybersecurity firm Zscaler has disclosed a data breach affecting customer contact information after unauthorized actors gained access to the company’s Salesforce database through compromised third-party application credentials. The breach originated from a broader campaign targeting Salesloft Drift, a marketing automation platform that integrates with Salesforce databases to manage leads and customer relationships. Cybercriminals successfully stole […]
Cybersecurity researchers have discovered a malicious npm package that comes with stealthy features to inject malicious code into desktop apps for cryptocurrency wallets like Atomic and Exodus on Windows systems.
The package, named nodejs-smtp, impersonates the legitimate email library nodemailer with an identical tagline, page styling, and README descriptions, attracting a total of 347
Cybersecurity company Zscaler has confirmed it fell victim to a widespread supply-chain attack that exposed customer contact information through compromised Salesforce credentials linked to marketing platform Salesloft Drift.
The breach, disclosed on August 31, 2025, stems from a larger campaign targeting Salesloft Drift’s OAuth tokens that has impacted over 700 organizations worldwide.
Zscaler emphasized that the incident was confined to its Salesforce environment and did not affect any of its core security products, services, or underlying infrastructure.
The security incident originated from a sophisticated supply-chain attack orchestrated by threat actor UNC6395, which Google Threat Intelligence Group and Mandiant researchers have been tracking since early August 2025.
Between August 8-18, 2025, attackers systematically compromised OAuth tokens associated with Salesloft Drift, an AI-powered chat agent integrated with Salesforce databases for sales workflow automation.
UNC6395 demonstrated advanced operational capabilities by using these stolen tokens to authenticate directly into Salesforce customer instances, bypassing multi-factor authentication entirely. The threat actors employed Python tools to automate the data theft process across hundreds of targeted organizations.
Information Compromised at Zscaler
According to Zscaler’s official statement, the compromised data was limited to commonly available business contact details and Salesforce-specific content, including:
Names and business email addresses
Job titles and phone numbers
Regional and location details
Zscaler product licensing and commercial information
Plain text content from certain support cases (excluding attachments, files, and images)
“After extensive investigation, Zscaler has currently found no evidence to suggest misuse of this information,” the company stated. However, the breach highlights the vulnerability of third-party integrations in modern SaaS environments.
The Zscaler incident represents just one piece of what security researchers are calling the largest SaaS breach campaign of 2025. Google’s Threat Intelligence Group estimates that over 700 organizations have been impacted by this supply-chain attack.
Initially believed to target only Salesforce integrations, the campaign’s scope expanded significantly when Google confirmed on August 28 that OAuth tokens for Drift Email were also compromised, providing attackers with limited access to Google Workspace accounts. Most victims are technology and software companies, creating potential cascading supply-chain risks.
Zscaler acted swiftly to contain the incident by revoking Salesloft Drift’s access to its Salesforce data and rotating API access tokens as a precautionary measure. The company launched a comprehensive investigation in collaboration with Salesforce and implemented additional safeguards to prevent similar incidents.
On August 20, 2025, Salesloft and Salesforce collaborated to revoke all active access and refresh tokens associated with the Drift application. Salesforce also removed the Drift application from its AppExchange marketplace pending further investigation.
This incident underscores critical vulnerabilities in SaaS-to-SaaS integrations that often bypass traditional security controls. OAuth tokens, once compromised, provide persistent access without triggering authentication alerts or requiring passwords.
While no evidence of data misuse has been found, Zscaler urges customers to maintain heightened vigilance against potential phishing attacks or social engineering attempts that could leverage the exposed contact details. The company emphasizes that official Zscaler support will never request authentication details through unsolicited communications.
Organizations using third-party SaaS integrations are advised to review all connected applications, revoke overly broad permissions, and implement continuous monitoring for unusual query activity or large-scale data exports.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Cybersecurity researchers are calling attention to a new shift in the Android malware landscape where dropper apps, which are typically used to deliver banking trojans, to also distribute simpler malware such as SMS stealers and basic spyware.
These campaigns are propagated via dropper apps masquerading as government or banking apps in India and other parts of Asia, ThreatFabric said in a report
The Wireshark team has rolled out version 4.4.9, a maintenance release for the world’s most popular network protocol analyzer.
This update focuses on stability and reliability, delivering a series of important bug fixes and enhancing support for several existing protocols.
The new version is now available for all supported platforms, including Windows, macOS, and Linux.
Wireshark, an indispensable tool for network administrators, security professionals, and developers, allows for in-depth analysis of network traffic. It is used extensively for troubleshooting network issues, examining security problems, and for educational purposes.
The project is hosted by the non-profit Wireshark Foundation, which relies on community contributions and sponsorships to continue its work in promoting protocol analysis education.
This latest release addresses several vulnerabilities and operational bugs. A significant fix resolves a crash in the SSH dissector (wnpa-sec-2025-03), a critical issue for anyone analyzing secure shell traffic. Other notable corrections include:
An incorrect dissection of the RDM Product Detail List ID.
Failures in SCCP LUDT segmentation decoding.
An issue preventing Ciscodump from initiating captures on Cisco IOS devices.
A problem with the display of the closing context tag in BACnet WritePropertyMultiple.
A bug in the LZ77 decoder that caused it to read a 16-bit length instead of the correct 32-bit length.
While version 4.4.9 does not introduce support for any new protocols, it does bring updates to several existing ones. Users will find improved support for BACapp, LIN, MySQL, RDM, SABP, SCCP, sFlow, and SSH.
These enhancements ensure that Wireshark can more accurately parse and display data for these protocols, reflecting the latest standards and vendor-specific implementations.
The update does not include any new or updated capture file support or changes to file format decoding. The development team’s focus for this release has been squarely on refining the existing feature set and ensuring the tool remains stable and secure for its large user base.
Network professionals are encouraged to upgrade to version 4.4.9 to benefit from the recent fixes and protocol updates, ensuring a more secure and efficient network analysis experience.
The Wireshark Foundation has officially launched the Wireshark Certified Analyst (WCA-101) certification, marking a significant milestone in professional network analysis education.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
A group claiming to be a coalition of hackers has reportedly issued an ultimatum to Google, threatening to release the company’s databases unless two of its employees are terminated.
The demand, which appeared in a Telegram post, specifically named Austin Larsen and Charles Carmakal, both members of Google’s Threat Intelligence Group.
According to a post seen by Newsweek, the self-proclaimed hacking collective, calling itself “Scattered LapSus Hunters,” also insisted that Google suspend all investigations by its Threat Intelligence Group into the network’s activities.
The group’s name is an apparent reference to its composition, which it claims includes members from established hacking communities such as Scattered Spider, LapSus, and ShinyHunters.
Currently, the group has not provided any evidence to substantiate its claim of accessing Google’s databases. Furthermore, there have been no recent confirmed breaches of Google’s internal information systems.
This threat emerges in the wake of a separate incident disclosed by Google in August. The company confirmed that ShinyHunters, one of the groups allegedly part of the new coalition, had successfully obtained data from Salesforce.
Salesforce is a third-party vendor that provides various services to Google, and the breach occurred within the vendor’s systems, not Google’s own infrastructure.
The formation of a supergroup like “Scattered LapSus Hunters” would represent a significant escalation in the cyber threat landscape. Scattered Spider is known for its sophisticated social engineering tactics, while LapSus gained notoriety for its aggressive and high-profile attacks on major tech companies.
ShinyHunters has a long history of large-scale data breaches and selling stolen information on the dark web. The potential collaboration of these entities could pose a formidable challenge to even the most well-defended corporations.
Newsweek has reportedly reached out to Google for a statement regarding the alleged threats, but a response was not immediately received as the request was made outside of standard business hours.
The situation remains under observation as the tech community awaits Google’s official response and further developments.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
The telecommunications landscape is facing an unprecedented crisis as SIM swapping attacks surge to alarming levels, with the United Kingdom alone reporting a staggering 1,055% increase in incidents during 2024, jumping from just 289 cases in 2023 to nearly 3,000 cases.
This explosive growth in telecommunications fraud has prompted urgent calls for enhanced security measures, with embedded SIM (eSIM) technology emerging as a promising solution to combat this escalating threat.
As cybercriminals increasingly target the vulnerabilities inherent in traditional SIM card systems, eSIM technology offers advanced security features that could significantly reduce the success rate of these sophisticated attacks.
Understanding SIM Swapping Attacks
SIM swapping, also known as SIM hijacking, represents a sophisticated form of identity theft where attackers manipulate mobile carriers into transferring a victim’s phone number to a SIM card under their control.
The attack methodology follows a predictable pattern: cybercriminals first gather personal information about their targets through data breaches, social media reconnaissance, or phishing campaigns.
Armed with details such as names, addresses, birthdates, and account security questions, attackers then contact the victim’s mobile carrier, impersonating the legitimate customer and requesting a SIM transfer due to a “lost” or “damaged” device.
The attack’s effectiveness stems from its exploitation of SMS-based two-factor authentication (2FA) systems that many organizations still rely upon for security verification.
Once attackers control the victim’s phone number, they can intercept verification codes sent via SMS, enabling them to reset passwords and gain unauthorized access to banking accounts, cryptocurrency wallets, email services, and social media platforms.
The Princeton University study revealed that 80% of first attempts at SIM swap fraud were successful across major U.S. wireless carriers, highlighting the widespread vulnerabilities in current authentication processes.
Explosive Growth of SIM Swapping Threats
The scale of SIM swapping attacks has reached crisis levels globally, with multiple indicators pointing to an accelerating trend. The FBI investigated 1,075 SIM swap attacks in 2023, resulting in losses approaching $50 million.
In 2024, IDCARE reported a 240% surge in SIM swap cases, with 90% of incidents occurring without any victim interaction. The financial impact extends beyond individual losses, as demonstrated by T-Mobile’s $33 million settlement for a cryptocurrency-related SIM swap attack that occurred in 2020.
Several factors contribute to this dramatic increase in SIM swapping fraud. The widespread reliance on SMS-based 2FA creates enormous criminal ROI, as a single successful port grants access to an entire digital financial life.
Record data breaches have provided attackers with over 7 billion compromised credentials on dark web markets during 2024, supplying the personal information necessary to bypass carrier identity verification. The cryptocurrency bull market of 2025 has created attractive high-value targets, with individual attacks potentially netting multimillion-dollar scores.
SIM Swapping Attack on Raise
Additionally, cost-cutting measures by telecommunications companies have introduced new vulnerabilities. Global carriers have increasingly outsourced customer support operations, where agents facing time-to-answer pressure are statistically more prone to “verification bypass fatigue”.
AI-powered social engineering tools now enable attackers to create convincing voice-cloning impersonations and GPT-scripted call dialogues that defeat legacy knowledge-based verification systems.
eSIM Technology: A Technical Overview
Embedded SIM (eSIM) technology represents a fundamental shift in mobile connectivity architecture, moving from removable physical cards to integrated digital solutions.
An eSIM is a small chip (typically measuring 6mm × 5mm) that is soldered directly onto a device’s motherboard during manufacturing, utilizing the same electrical interface as traditional SIM cards as defined by ISO/IEC 7816 standards.
The technology operates through an embedded Universal Integrated Circuit Card (eUICC) that can be remotely programmed with carrier profiles.
eSIM architecture
The eSIM ecosystem relies on remote SIM provisioning (RSP) protocols developed by the GSMA, enabling secure over-the-air profile management.
When activating an eSIM, the Local Profile Assistant (LPA) software contacts a Subscription Manager (SM) service via HTTPS, using X.509 certificates validated by the GSMA certificate authority.
The system employs challenge-response authentication to establish secure channels between the eUICC and SM, ensuring that network authentication keys remain protected through end-to-end encryption.
Each eSIM contains a permanent eUICC ID (EID) programmed during manufacturing, which serves as the foundation for secure provisioning services.
The technology supports multiple carrier profiles on a single device, allowing users to switch between networks digitally without physical SIM card replacement.
This digital-first approach eliminates many vulnerabilities associated with physical SIM management while introducing new layers of cryptographic protection.
How eSIM Technology Strengthens Security Against SIM Swapping
eSIM technology addresses the fundamental vulnerabilities that enable traditional SIM swapping attacks by introducing several critical security enhancements. The most significant protection comes from eliminating physical access risks.
Unlike removable SIM cards that can be extracted and transferred between devices, eSIMs are permanently embedded in device hardware, making physical theft virtually impossible without sophisticated engineering tools. This embedded nature immediately eliminates the easiest method of SIM hijacking.
The digital activation process for eSIM profiles requires multi-layered authentication that is significantly more robust than traditional carrier verification procedures.
eSIM activation typically involves scanning QR codes or using secure in-app processes that must be confirmed directly on the target device.
This digital provisioning process, governed by GSMA security standards, adds multiple verification layers that make unauthorized transfers exceptionally difficult compared to the social engineering tactics used against call center representatives.
SIM Card vs eSIM
Advanced encryption protocols form another critical defense mechanism in eSIM technology. eSIMs employ end-to-end encryption for all data storage and transmission, making interception and manipulation significantly more challenging than traditional SIM cards. The cryptographic keys injected during manufacturing create secure authentication chains that cannot be easily replicated or compromised. Additionally, eSIM profiles cannot be cloned or duplicated, eliminating a major attack vector that affects physical SIM cards.
Remote management capabilities provide enhanced security control for both users and carriers. If a device is lost or stolen, eSIM profiles can be immediately deactivated remotely, severing the device’s connection to the network and preventing unauthorized usage. This rapid response capability is crucial for minimizing damage in security incidents and provides users with direct control over their mobile identity.
The biometric and device-based authentication requirements for eSIM management create additional security layers. Many eSIM implementations require biometric verification, device PINs, or other security measures that are tied directly to the physical device, making it much harder for remote attackers to manipulate carrier representatives into transferring services. This shifts authentication from knowledge-based systems vulnerable to social engineering to possession-based factors that require physical device access.
Regulatory Response and Industry Initiatives
The telecommunications industry and regulatory bodies have recognized the critical need to address SIM swapping vulnerabilities through comprehensive policy measures.
The Federal Communications Commission (FCC) approved new rules in October 2023 designed to establish uniform frameworks for protecting customers against SIM swap and port-out fraud.
These regulations require wireless providers to adopt secure customer authentication methods before redirecting phone numbers to new devices or providers, maintain detailed records of SIM change requests, and implement employee training programs for handling fraud attempts.
Protection layers
The FCC’s rules also establish safeguards preventing employees from accessing customer personal information until proper authentication is completed.
While the implementation timeline has faced industry pushback, with compliance deadlines extended pending Office of Management and Budget (OMB) review, the regulatory framework represents a significant step toward standardizing anti-fraud protections across carriers.
The FCC has indicated that OMB approval would likely come in late November 2024, with providers encouraged to use this timeline for system implementation and testing.
Industry initiatives complement regulatory efforts through technological solutions and best practices. The GSMA’s comprehensive eSIM security framework includes rigorous certification programs such as the eUICC Security Assurance (eSA) Scheme and Security Accreditation Scheme (SAS), which establish stringent security requirements for eSIM implementations.
These certification processes ensure that eSIM entities meet high security standards and reduce risks of data breaches and attacks through verified security controls.
Limitations and Considerations
Despite its significant security advantages, eSIM technology faces several limitations that must be acknowledged in comprehensive security strategies. Social engineering vulnerabilities remain a persistent threat, as eSIM activation can still be manipulated through sophisticated impersonation attacks targeting carrier customer service systems.
While eSIM activation processes are more secure than traditional SIM swaps, determined attackers with sufficient personal information about victims may still succeed in convincing carriers to provision new eSIM profiles.
Software-based vulnerabilities introduce new attack vectors that don’t exist with physical SIM cards. eSIMs rely heavily on software systems and cloud infrastructure, creating potential targets for sophisticated cyberattacks.
If carrier account credentials or email accounts are compromised, attackers might be able to activate eSIM profiles on devices they control. Additionally, eSIMs are vulnerable to specialized attacks such as memory exhaustion, locking profile attacks, and inflated profile attacks that exploit the digital nature of the technology.
Compatibility and adoption challenges also limit eSIM’s immediate impact on SIM swapping prevention. Many older devices and certain geographic regions have limited eSIM support, forcing continued reliance on physical SIM cards.
The transition period creates mixed security environments where some users benefit from enhanced eSIM protection while others remain vulnerable to traditional attacks. Furthermore, the complexity of eSIM management may create usability barriers for some consumers, potentially leading to security misconfigurations.
The dramatic surge in SIM swapping attacks, with incident rates increasing by over 1,000% in some regions, represents a critical threat to mobile communications security that demands immediate technological and regulatory intervention.
eSIM technology offers a promising solution through its embedded architecture, advanced encryption protocols, multi-layered authentication requirements, and remote management capabilities that directly address the vulnerabilities exploited in traditional SIM swapping attacks.
The combination of physical security improvements, cryptographic protections, and enhanced verification processes makes eSIM significantly more resistant to the social engineering tactics that have proven devastatingly effective against conventional SIM card systems.
However, the transition to eSIM technology must be accompanied by comprehensive security frameworks, regulatory oversight, and continued vigilance against evolving attack methodologies. While eSIMs represent a substantial improvement in mobile security architecture, they cannot eliminate all risks associated with telecommunications fraud.
The most effective defense strategy will combine eSIM adoption with multi-factor authentication systems that don’t rely solely on SMS verification, robust user education programs, and continued industry cooperation to identify and mitigate emerging threats.
As the telecommunications industry works to implement FCC regulations and advance eSIM adoption, the focus must remain on creating layered security approaches that protect users across all technology platforms while maintaining the accessibility and usability that modern mobile communications require.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.