Friday , September 25 2026
US defense

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real Microsoft sharing link. The hackers got into an employee’s email, which had a lot of private information.

IEH Corporation shared news of a security incident in an 8-K form with the Securities and Exchange Commission (SEC). The company said that someone unauthorized took access to one employee’s Microsoft 365 mailbox.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

IEH Corporation makes parts for satellites, fighter jets, ground radars, torpedoes, and airborne radars. Some of its products are used in guided missile systems like THAAD and Patriot.

According to the 8-K form, attackers managed to access the IEH Corporation employee’s mailbox after impersonating a “prospective business contact.” The fraudster sent a hyperlink disguised as a Microsoft document-sharing link.

“The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access,” reads the form.

According to the company, attackers may have accessed:

Email messages
Attachments
Customer communications
Purchase orders
Engineering-related documentation
Potentially export-controlled technical information

Export-controlled technical information usually includes blueprints, software, or engineering designs that the US government controls to keep the country safe. Considering the IEG Corporation profile, it is very possible that the leaked data is linked to making weapons.

“No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period,” the company said.

IEH said they got the account securie and turned off the affected mailbox. They are keeping digital evidence for the investigation. So far, there is no info that anyone downloaded or took sensitive details from the mailbox.

“As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations,” IEH said.

First American December data breach impacts 44,000 people

Check Also

France

727,000 data exposes: French hospital fined €500,000

France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for …