✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Newspapers/Journalism
Breach intelligence, attack campaigns, and threat reports targeting the Newspapers/Journalism sector.
Explore Other Sectors
Newspapers/Journalism Threat Reports
Intellexa Exposed: Predator Spyware Vendor’s Secret Remote Access Unveiled (2024)
In 2024, investigative reporting revealed that Intellexa, a vendor of the Predator spyware, retained the ability to remotely access systems belonging to its own customers. Leaked training videos and multiple research publications uncovered that Intellexa could view customer surveillance logs, potentially monitoring surveillance operations and data on targeted individuals. Additional findings exposed that Intellexa exploited malicious mobile advertisements (notably the 'Aladdin' vector) to infect targets, and utilized domains imitating legitimate news sites, implicating Predator in surveillance of high-profile activists, journalists, and lawyers across Kazakhstan, Egypt, Greece, Iraq, and Pakistan. This raised serious concerns regarding human rights oversight and corporate accountability. This incident is particularly alarming due to the vendor’s persistent development of new zero-day exploits and its direct operational involvement in customer deployments. Such practices highlight significant shifts in spyware vendor behavior and raise urgent questions about regulatory readiness, digital rights, and the security of organizations relying on third-party surveillance tools.
6 months ago
Kill Chain
CopyCop: Unmasking Russia's AI-Driven Disinformation Offensive in 2024
In early-to-mid 2024, cybersecurity researchers uncovered the extensive "CopyCop" campaign, a Russian-connected influence operation leveraging AI technologies to scale disinformation globally. The operation orchestrated over 300 AI-generated fake news sites mimicking legitimate Western media outlets, flooding North America, Europe, and other regions with fabricated stories and deepfakes targeting public perception about the conflict in Ukraine. CopyCop used self-hosted large language models to mass-produce convincing articles, fake fact-checkers, and synthetic visuals, eroding trust in authentic journalism and amplifying Kremlin narratives. The sophisticated use of generative AI and automation enabled unprecedented speed, reach, and content variability, evading traditional detection tactics and spreading misinformation at scale. This incident highlights an accelerating trend: threat actors and nation-state proxies are operationalizing generative AI for influence campaigns, making synthetic media and coordinated digital manipulation a top concern for governments, enterprises, and critical infrastructure organizations worldwide.
6 months ago
Kill Chain
Clop Ransomware Hits Washington Post via Oracle Zero-Day in 2024
In July and August 2024, The Washington Post fell victim to a cyberattack orchestrated by the Clop ransomware group, which exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. Attackers accessed the company’s Oracle environment for over six weeks, ultimately stealing sensitive HR data on nearly 10,000 current and former employees and contractors, including names, bank account details, and Social Security numbers. The breach went undetected until late September when Clop contacted executives with extortion demands. The company confirmed the scope of stolen data in late October, after initiating an internal investigation. This incident underscores the growing trend of threat actors leveraging zero-day vulnerabilities in widely used enterprise software to facilitate mass data theft and extortion. With ransomware groups like Clop escalating the use of targeted campaigns against technology supply chains, organizations face heightened exposure to financial, regulatory, and reputational risk.
6 months ago
Kill Chain
The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024
In June 2024, The Washington Post began notifying nearly 10,000 employees and contractors that their personal and financial information had been exposed following a breach involving Oracle-managed systems. The incident stemmed from an attack on a third-party vendor, believed to be tied to the widespread theft of cloud-stored data, which granted unauthorized access to sensitive HR and payroll details. The compromise was discovered post-incident, and affected individuals include current and former staff spanning back several years. Although there is no evidence of active misuse, the breach has prompted heightened security reviews. This breach exemplifies escalating risks inherent in supply-chain and third-party systems, with attackers increasingly targeting service providers to access large pools of critical enterprise data. Organizations across all sectors are now under pressure to strengthen controls around third-party integrations to reduce exposure.
6 months ago
Kill Chain
Nikkei Data Breach: Slack Compromise Exposes Employee and Partner Information in 2024
In early June 2024, Japanese media conglomerate Nikkei disclosed a cybersecurity breach involving the unauthorized compromise of its Slack workspace. Attackers gained access to Slack accounts and chat histories, potentially exposing sensitive information belonging to thousands of employees and business partners. The incident is believed to have occurred via stolen Slack credentials, granting threat actors access to business communications and personal data. Nikkei swiftly launched an investigation, engaged incident response expertise, and notified affected individuals while reporting the matter to regulatory authorities. This attack highlights the continuing risk of platform-based credential compromises affecting collaboration tools. The frequency of SaaS-targeted breaches is growing, underlining the urgent need for robust identity, access management, and segmentation controls on corporate communication channels.
6 months ago
Kill Chain
Nikkei’s 2024 Slack Breach: How 17,000 Identities Were Compromised
In early June 2024, Japanese media giant Nikkei disclosed a significant data breach after its Slack messaging platform was compromised, exposing the personal information of more than 17,000 employees and business partners. Attackers gained unauthorized access to sensitive data such as names, email addresses, and potentially other details linked through Slack integration, by exploiting the company’s internal communications environment. The breach’s impact is broad, affecting both staff and partners, with Nikkei reporting the incident promptly to authorities and commencing investigation and notification processes. This incident highlights the growing risks posed by attacks on SaaS collaboration platforms like Slack, as organizations increasingly rely on these tools for internal and external communication. Threat actors are exploiting identity-based and third-party platform vulnerabilities, underlining the critical need for robust access controls and proactive monitoring of cloud communication systems.
6 months ago
Kill Chain
Medusa Ransomware’s Failed Insider Recruitment at BBC (2025)
In July 2025, cybercriminals claiming affiliation with the Medusa ransomware group attempted to compromise the BBC by recruiting a journalist as an insider. The threat actor contacted the BBC’s cybersecurity correspondent via Signal, offering a percentage of any ransom if the journalist would provide internal access. Their plan relied on leveraging the journalist’s BBC credentials to infiltrate systems, download sensitive data, and initiate a high-value ransomware attack. The attackers used multiple social engineering tactics, including MFA fatigue (MFA bombing), but the journalist reported the approach to BBC’s security team, preventing a breach and prompting immediate incident response measures. This incident highlights the increasing risk of ransomware groups seeking insiders for network access, as well as the sophistication of social engineering tactics. As double-extortion attacks and insider recruitment surge, organizations must enhance vigilance and reinforce controls to mitigate identity-driven threats.
6 months ago
Kill Chain
Apple 2025 Spyware Surge: Targeted Zero-Day Attacks Threaten High-Profile Users
In 2025, Apple issued multiple urgent notifications to users after detecting a series of targeted spyware attacks leveraging zero-day vulnerabilities on iOS devices. According to French CERT-FR, at least four documented incidents since the beginning of the year involved highly sophisticated, zero-click exploits that required no user interaction. Victims included journalists, politicians, lawyers, activists, and executives in sensitive sectors. Attackers used a combination of a patched Apple zero-day (CVE-2025-43300) and a WhatsApp vulnerability (CVE-2025-55177) to compromise devices, potentially granting remote access to communications and sensitive data. Apple recommended enabling Lockdown Mode and soliciting help from digital security hotlines, but did not attribute the attacks to a specific group or region. This incident underscores increasing use of mercenary spyware and zero-day exploits for high-profile targeting, reflecting the growing challenges of defending against advanced persistent threats. The case highlights the urgency for rapid patching, proactive security postures, and global awareness of targeted surveillance campaigns in both the public and private sectors.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports