The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A critical security vulnerability has been disclosed in the Open Authorization (OAuth) implementation of the application development framework Expo.io.The shor…
Email protection and network security services provider Barracuda is warning users about a zero-day flaw that it said has been exploited to breach the company'…
An unnamed government entity associated with the United Arab Emirates (U.A.E.) was targeted by a likely Iranian threat actor to breach the victim's Microsoft E…
The threat actors behind the nascentBuhtiransomware have eschewed their custom payload in favor of leaked LockBit and Babuk ransomware families to strike Windo…
The Iranian threat actor known asAgriusis leveraging a new ransomware strain called Moneybird in its attacks targeting Israeli organizations.Agrius, also known…
An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials asso…
The infamous Lazarus Group actor has been targeting vulnerable versions of Microsoft Internet Information Services (IIS) servers as an initial breach route to …
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks targeting state bodies in the country as part of an espionage campaign.Th…
The North Korean advanced persistent threat (APT) group known as Kimsuky has been observed using a piece of custom malware called RandomQuery as part of a reco…
The notorious cybercrime group known as FIN7 has been observed deployingCl0p(aka Clop) ransomware, marking the threat actor's first ransomware campaign since l…
The notorious cybercrime group known as FIN7 has been observed deployingCl0p(aka Clop) ransomware, marking the threat actor's first ransomware campaign since l…
In today’s digital landscape, where cyber threats are ever-evolving and increasingly sophisticated, data analysts play…Unveiling the Power of Threat Models: En…
A Russian national has been charged and indicted by the U.S. Department of Justice (DoJ) for launching ransomware attacks against "thousands of victims" in the…
Ransomware affiliates associated with the Qilin ransomware-as-a-service (RaaS) scheme earn anywhere between 80% to 85% of each ransom payment, according to new…
A new ransomware group known asRA Grouphas become the latest threat actor to leverage the leaked Babuk ransomware source code to spawn its own locker variant.T…
A new ransomware-as-service (RaaS) operation called MichaelKors has become the latest file-encrypting malware to target Linux andVMware ESXi systemsas of April…
Poorly managed Microsoft SQL (MS SQL) servers are the target of a new campaign that's designed to propagate a category of malware calledCLR SqlShellthat ultima…
In a threatening move, the notorious ransomware group Conti has demanded a $20 million ransom…Conti Ransomware Group Poses $20 Million Threat to Costa Rican Go…
The password management service 1Password assured users of no security breach after accidentally sending “Secret…1Password Confirms No Security Breach After “P…
U.S. cybersecurity and intelligence agencies have warned of attacks carried out by a threat actor known as theBl00dy Ransomware Gangthat attempt to exploit vul…
Multiple threat actors have capitalized on the leak of Babuk (aka Babak or Babyk) ransomware code in September 2021 to build as many as nine different ransomwa…
A nascent botnet calledAndoryuhas been found toexploita now-patched critical security flaw in the Ruckus Wireless Admin panel to break into vulnerable devices.…
The U.S. government on Tuesday announced the court-authorized disruption of a global network compromised by an advanced malware strain known asSnakewielded by …
Cybersecurity researchers have shed light on a new ransomware strain called CACTUS that has been found to leverage known flaws in VPN appliances to obtain init…