Tuesday , September 1 2026
US defense

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real Microsoft sharing link. The hackers got into an employee’s email, which had a lot of private information.

IEH Corporation shared news of a security incident in an 8-K form with the Securities and Exchange Commission (SEC). The company said that someone unauthorized took access to one employee’s Microsoft 365 mailbox.

CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two flaws in PaperCut NG and PaperCut MF in its...
Read More
CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

Fire Ant hackers convert Cisco routers into spy platforms

The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco...
Read More
Fire Ant hackers convert Cisco routers into spy platforms

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
Five Critical WordPress Flaws Lead to Site Takeover or RCE

700 AI agents united to hack Hugging Face after breaking isolation

700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
700 AI agents united to hack Hugging Face after breaking isolation

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
ServiceNow warns of three critical security vulnerabilities

100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

8.7 Million Customers data exposed from 3 Airports 

3 airports in the UK were affected by a "cyber security incident." Hackers got into data belonging to nearly nine...
Read More
8.7 Million Customers data exposed from 3 Airports 

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

IEH Corporation makes parts for satellites, fighter jets, ground radars, torpedoes, and airborne radars. Some of its products are used in guided missile systems like THAAD and Patriot.

According to the 8-K form, attackers managed to access the IEH Corporation employee’s mailbox after impersonating a “prospective business contact.” The fraudster sent a hyperlink disguised as a Microsoft document-sharing link.

“The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access,” reads the form.

According to the company, attackers may have accessed:

Email messages
Attachments
Customer communications
Purchase orders
Engineering-related documentation
Potentially export-controlled technical information

Export-controlled technical information usually includes blueprints, software, or engineering designs that the US government controls to keep the country safe. Considering the IEG Corporation profile, it is very possible that the leaked data is linked to making weapons.

“No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period,” the company said.

IEH said they got the account securie and turned off the affected mailbox. They are keeping digital evidence for the investigation. So far, there is no info that anyone downloaded or took sensitive details from the mailbox.

“As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations,” IEH said.

First American December data breach impacts 44,000 people

Check Also

cable

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside …