The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Ransomware attacks have only increased in sophistication and capabilities over the past year. From new evasion and anti-analysis techniques to stealthier varia…
Ransomware attacks have only increased in sophistication and capabilities over the past year. From new evasion and anti-analysis techniques to stealthier varia…
The AvosLocker ransomware gang has been linked to attacks against critical infrastructure sectors in the U.S., with some of them detected as recently as May 20…
Microsoft on Wednesday said that a user containment feature in Microsoft Defender for Endpoint helped thwart a "large-scale remote encryption attempt" made byA…
Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades as a WordPress plugin to stealthily create administrator ac…
Passwords are at the core of securing access to an organization's data. However, they also come with security vulnerabilities that stem from their inconvenienc…
Multiple high-severity security vulnerabilities have been disclosed in ConnectedIO's ER2000 edge routers and the cloud-based management platform that could be …
A governmental entity in Guyana has been targeted as part of a cyber espionage campaign dubbedOperation Jacana.Theactivity, which was detected by ESET in Febru…
The recently patched TeamCity RCE flaw is now under active attack by numerous ransomware gangs.…TeamCity RCE Flaw Actively Exploited To Deploy Ransomware on La…
Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environmentthrough an SQL Server instance."The a…
Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer system…
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Prov…
The U.S. Federal Bureau of Investigation (FBI) is warning of a new trend of dual ransomware attacks targeting the same victims, at least since July 2023."Durin…
A novel side-channel attack calledGPU.ziprenders virtually all modern graphics processing units (GPU) vulnerable to information leakage."This channel exploits …
Data security is in the headlines often, and it’s almost never for a positive reason. Major breaches, new ways to hack into an organization’s supposedly secure…
Cybersecurity experts have shed light on a new cybercrime group known asShadowSyndicate(formerly Infra Storm) that may have leveraged as many as seven differen…
China's Ministry of State Security (MSS) has accused the U.S. of breaking into Huawei's servers, stealing critical data, and implanting backdoors since 2009, a…
A financially motivated threat actor has been outed as an initial access broker (IAB) that sells access to compromised organizations for other adversaries to c…
The maintainers of Free Download Manager (FDM) have acknowledged a security incident dating back to 2020 that led to its website being used to distribute malic…
Cybersecurity researchers have discovered a fresh batch of malicious packages in the npm package registry that are designed to exfiltrate Kubernetes configurat…
Targets located in Azerbaijan have been singled out as part of a new campaign that's designed to deploy Rust-based malware on compromised systems.Cybersecurity…
Software development company Retool has disclosed that the accounts of 27 of its cloud customers were compromised following a targeted and SMS-based social eng…
The financially motivated threat actor known asUNC3944is pivoting to ransomware deployment as part of an expansion to its monetization strategies, Mandiant has…
The threat actors behind RedLine and Vidar information stealers have been observed pivoting to ransomware through phishing campaigns that spread initial payloa…