The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Software development company Retool has disclosed that the accounts of 27 of its cloud customers were compromised following a targeted and SMS-based social eng…
The financially motivated threat actor known asUNC3944is pivoting to ransomware deployment as part of an expansion to its monetization strategies, Mandiant has…
The threat actors behind RedLine and Vidar information stealers have been observed pivoting to ransomware through phishing campaigns that spread initial payloa…
A download manager site served Linux users malware that stealthily stole passwords and other sensitive information for more than three years as part of a suppl…
There is a new battlefield. It is global and challenging to defend. What began with a high-profile incident back in 2007, when Estonia was hit by hackers targe…
A new ransomware family called3AMhas emerged in the wild after it was detected in a single incident in which an unidentified affiliate deployed the strain foll…
With the growing reliance on web applications and digital platforms, the use of application programming interfaces (APIs) has become increasingly popular. If y…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday warned that multiple nation-state actors are exploiting security flaws in Fortinet…
AMirai botnetvariant calledPandorahas been observed infiltrating inexpensive Android-based TV sets and TV boxes and using them as part of a botnet to perform d…
Microsoft on Wednesday revealed that a China-based threat actor known asStorm-0558acquired the inactive consumer signing key to forge tokens and access Outlook…
Microsoft on Wednesday revealed that a China-based threat actor known asStorm-0558acquired the inactive consumer signing key to forge tokens and access Outlook…
IBM's 2023 installment of their annual "Cost of a Breach" report has thrown up some interesting trends. Of course, breaches being costly is no longer news at t…
An unknown threat actor has been observed weaponizing high-severity security flaws in the MinIO high-performance object storage system to achieve unauthorized …
Threat actors are exploiting poorly secured Microsoft SQL (MS SQL) servers to deliver Cobalt Strike and a ransomware strain called FreeWorld.Cybersecurity firm…
Cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the U.K., and the U.S. on Thursday disclosed details of a mobile malware strain ta…
A new phishing attack likely targeting civil society groups in South Korea has led to the discovery of a novel remote access trojan calledSuperBear.The intrusi…
As cyber threats continue to evolve, adversaries are deploying a range of tools to breach security defenses and compromise sensitive data. Surprisingly, one of…
An open-source .NET-based information stealer malware dubbedSapphireStealeris being used by multiple entities to enhance its capabilities and spawn their own b…
How often do cyberattacks happen? How frequently do threat actors target businesses and governments around the world? The BlackBerry® Threat Research and Intel…
A coordinated law enforcement effort codenamedOperation Duck Hunthas felledQakBot, a notorious Windows malware family that's estimated to have compromised over…
A suspected Chinese-nexus hacking group exploited arecently disclosed zero-day flawin Barracuda Networks Email Security Gateway (ESG) appliances to breach gove…
Unpatched Citrix NetScaler systems exposed to the internet are being targeted by unknown threat actors in what's suspected to be a ransomware attack.Cybersecur…
Cloud hosting firm Leaseweb recently disclosed a security breach after its Customer Portal suffered downtime.…Leaseweb Hosting Provider Admits Security Breach …
Cyber attacks on e-commerce applications are a common trend in 2023 as e-commerce businesses become more omnichannel, they build and deploy increasingly more A…