The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Are you concerned about ransomware attacks? You're not alone. In recent years, these attacks have become increasingly common and can cause significant damage t…
An ongoing phishing campaign with invoice-themed lures is being used to distribute the SmokeLoader malware in the form of a polyglot file, according to the Com…
Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw.The issue, assigned the…
The North Korean state-sponsored threat actor known asKimsukyhas been discovered using a new reconnaissance tool calledReconSharkas part of an ongoing global c…
IT and cybersecurity teams are so inundated with security notifications and alerts within their own systems, it’s difficult to monitor external malicious envir…
A Chinese state-sponsored hacking outfit has resurfaced with a new campaign targeting government, healthcare, technology, and manufacturing entities based in T…
The telecom industry has always been a tantalizing target for cybercriminals. The combination of interconnected networks, customer data, and sensitive informat…
A new ransomware binary targeting Linux systems has been attributed to the ransomware-as-a-service (RaaS) RTM group.
A little-known Russian-speaking cyber-espionage group has been linked to a new politically-motivated surveillance campaign targeting high-ranking government of…
The threat actors behindRTM Lockerhave developed a ransomware strain that's capable of targeting Linux machines, marking the group's first foray into the open …
Microsoft has confirmed that theactive exploitation of PaperCut serversis linked to attacks that are designed to deliver Cl0p and LockBit ransomware families.T…
The Chinese nation-state group dubbedAlloy Taurusis using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033.…
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) sof…
After wreaking havoc with Windows and Linux systems, the LockBit ransomware gang now intends to…Lockbit Ransomware Aims To Target macOS Systems – But May Not B…
Lazarus, the prolific North Korean hacking group behind the cascadingsupply chain attack targeting 3CX, also breached two critical infrastructure organizations…
The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophi…
Days after the horrifying cyberattack, more details about the 3CX incident surface online as Mandiant…3CX Cyber Attack: It Was The Aftermath Of Another Supply-…
A chain of two critical flaws has been disclosed in Alibaba Cloud's ApsaraDB RDS for PostgreSQL and AnalyticDB for PostgreSQL that could be exploited to breach…
Fortra, the company behind Cobalt Strike, shed light on a zero-day remote code execution (RCE) vulnerability in its GoAnywhere MFT tool that has come underacti…
The cyber espionage actor tracked asBlind Eaglehas been linked to a new multi-stage attack chain that leads to the deployment of the NjRAT remote access trojan…
Threat actors behind the LockBit ransomware operation have developed new artifacts that can encrypt files on devices running Apple's macOS operating system.The…
A new strain of malware developed by threat actors likely affiliated with the FIN7 cybercrime group has been put to use by the members of the now-defunct Conti…
Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the…
Cybersecurity researchers have detailed the tactics of a "rising" cybercriminal gang called "Read The Manual" (RTM) Locker that functions as a private ransomwa…