SHOPIFY'S SHOP APP WEAPONIZED FOR PHISHING
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Threat actors are exploiting Shopify's Shop order-tracking app by injecting fake purchase receipts into user accounts. The attacks trick victims into revealing sensitive data or installing remote access malware.
■ MORE FROM THE SECURITY DESK
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability. The flaw was previously flagged as under active exploitation in April.
Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, citing widespread abuse by cybercriminals. The tool is being eliminated from Windows 11 versions 24H2 and 25H2.
Israel has established a fabricated think tank apparently designed to influence AI chatbot outputs and shape how these systems respond to queries about Israeli policy. The scheme highlights vulnerabilities in how large language models source and validate information.
A threat actor claims to have stolen employee databases from Microsoft Azure infrastructure across multiple Fortune 500 companies using compromised credentials. The stolen records are now being offered for sale.