Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Data Breaches Announced by Two Digestive Health Companies
Two digestive health organizations, Gastro Health and Spokane Digestive Disease Center, have disclosed separate data breaches resulting from phishing attacks and unauthorized email account access. Both incidents exposed sensitive patient information including Social Security numbers, medical records, and financial data, affecting thousands of individuals across multiple states. The breaches occurr
AIMicrosoft Exchange Flaw Lets Attackers Spoof Any Email Address
A vulnerability dubbed 'Ghost-Sender' has been discovered in Microsoft Exchange that allows attackers to spoof any email address. The flaw specifically affects Exchange Online or on-premises deployments running in hybrid mode when configured with third-party mail servers or spam filters, enabling sophisticated email impersonation attacks.
AIGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
A new malspam campaign is exploiting Google's DoubleClick domain to bypass security detection systems and deliver the DesckVB remote access trojan (RAT). The attack leverages the trusted reputation of Google-owned infrastructure to route malicious traffic before redirecting victims to attacker-controlled servers. This technique exploits the fact that many enterprise security tools whitelist or dep
AIGlobal Stock Exchange Hit by Monthslong Email Campaign
A sophisticated threat actor compromised a senior finance executive's email account at a global stock exchange, maintaining persistent access over several months. The attack leveraged legitimate Windows native tools to evade detection, providing the attacker with continuous visibility into sensitive financial communications and potentially market-moving information.
Patient Data Exposed in Cyberattacks on Dental Practices
Three dental practices—Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics—have disclosed data breaches affecting over 32,700 patients combined. The incidents involved unauthorized access to email accounts and network environments, exposing protected health information including names, Social Security numbers, medical records, and insurance details. All three organization
