The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The threat actors behind a recently observed Qilin ransomware attack have stolen credentials stored in Google Chrome browsers on a small set of compromised end…
As many as 15,000 applications using Amazon Web Services' (AWS) Application Load Balancer (ALB) for authentication are potentially susceptible to a configurati…
As many as 15,000 applications using Amazon Web Services' (AWS) Application Load Balancer (ALB) for authentication are potentially susceptible to a configurati…
The popular flight-tracking tool FlightAware has alerted users about a data breach that has been…FlightAware Confirmed Data Breach Happened Due To Configuratio…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw impacting Jenkins to its Known Exploited Vulnerabilities (K…
The landscape of cyber threats and Linux vulnerabilities is evolving at an unprecedented pace, making it imperative for organizations to adopt advanced securit…
A large-scale extortion campaign has compromised various organizations by taking advantage of publicly accessible environment variable files (.env) that contai…
A large-scale extortion campaign has compromised various organizations by taking advantage of publicly accessible environment variable files (.env) that contai…
A cybercrime group with links to the RansomHub ransomware has been observed using a new tool designed to terminate endpoint detection and response (EDR) softwa…
A newly discovered attack vector in GitHub Actions artifacts dubbed ArtiPACKED could be exploited to take over repositories and gain access to organizations' c…
An ongoing social engineering campaign with alleged links to the Black Basta ransomware group has been linked to "multiple intrusion attempts" with the goal of…
A coalition of law enforcement agencies coordinated by the U.K. National Crime Agency (NCA) has led to the arrest and extradition of a Belarussian and Ukrainia…
As cybersecurity evolves, so too has its threats. Symantec recently identified an emerging threat aimed at Linux systems. This new type of ransomware (called d…
The U.S. Federal Bureau of Investigation (FBI) on Monday announced the disruption of online infrastructure associated with a nascent ransomware group called Ra…
At a time when security breaches have become increasingly sophisticated, an oversight that had persisted across major browsers for years has now been addressed…
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to ma…
By Josh Breaker-Rolfe Ransomware is the single most significant risk to modern business. The 2024…Ransomware Recovery: Steps to Take After an Attack on Latest …
Cybersecurity researchers have discovered a new "0.0.0.0 Day" impacting all major web browsers that malicious websites could take advantage of to breach local …
The ransomware strain known as BlackSuit has demanded as much as $500 million in ransoms to date, with one individual ransom demand hitting $60 million.That's …
The education MDM platform Mobile Guardian recently admitted to a cyberattack that disrupted its services.…Cyberattack On Mobile Guardian MDM Wiped Connected D…
Users in Russia have been the target of a previously undocumented Android post-compromise spyware called LianSpy since at least 2021.Cybersecurity vendor Kaspe…
The China-linked threat actor known as Evasive Panda compromised an unnamed internet service provider (ISP) to push malicious software updates to target compan…
A Taiwanese government-affiliated research institute that specializes in computing and associated technologies was breached by nation-state threat actors with …
Recently, open-source security was rocked by the discovery of an alarming Remote Code Execution (RCE) vulnerability within the Ghostscript document conversion …