The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A 55-year-old Chinese national has been sentenced to four years in prison and three years of supervised release for sabotaging his former employer's network wi…
Cybersecurity researchers have disclosed details of a new malware loader called QuirkyLoader that's being used to deliver via email spam campaigns an array of …
CVE-2023-46604 is not just another box on your patching to-do list''it's a major remote code execution (RCE) vulnerability in Apache ActiveMQ that admins need …
A Russian state-sponsored cyber espionage group known as Static Tundra has been observed actively exploiting a seven-year-old security flaw in Cisco IOS and Ci…
Penetration tests are like fire drills for your network. They expose weak spots, test defenses, and help prevent real damage when threats come knocking. But no…
Cybersecurity researchers have demonstrated a new prompt injection technique called PromptFix that tricks a generative artificial intelligence (GenAI) model in…
Researchers discovered a major security flaw in Google Calendar that could allow hijacking Gemini agents…A Google Calendar Flaw Could Allow Hijacking Gemini Vi…
Microsoft has released the scheduled Patch Tuesday updates for August 2025. This month’s update bundle…Microsoft Fixed Over 100 Flaws With August 2025 Patch Tu…
North Korean threat actors have been attributed to a coordinated cyber espionage campaign targeting diplomatic missions in their southern counterpart between M…
A new Linux kernel vulnerability has surfaced, and if you're managing Linux systems, this flaw necessitates your immediate attention. CVE-2024-53141 is a criti…
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called …
After two decades of developing increasingly mature security architectures, organizations are running up against a hard truth: tools and technologies alone are…
The threat actors behind the Noodlophile malware are leveraging spear-phishing emails and updated delivery mechanisms to deploy the information stealer in atta…
Distributed Denial of Service, or DDoS, booters''or IP stressers, as they're also called''represent one of those shadowy operations that nearly seem like they …
Distributed Denial of Service, or DDoS, booters''or IP stressers, as they're also called''represent one of those shadowy operations that nearly seem like they …
Cybersecurity researchers have lifted the lid on the threat actors' exploitation of a now-patched security flaw in Microsoft Windows to deploy the PipeMagic ma…
Managing CPU security mitigations has always been one of those balancing acts that systems administrators live and breathe but rarely get applause for. After a…
Managing CPU security mitigations has always been one of those balancing acts that systems administrators live and breathe but rarely get applause for. After a…
Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior through a depend…
Cybersecurity researchers have detailed the inner workings of an Android banking trojan called ERMAC 3.0, uncovering serious shortcomings in the operators' inf…
A new malware campaign has affected users globally, stealing sensitive data. Identified as PXA stealer,…PXA Python Malware Targets Thousands Of Victims Globall…
Microsoft recently announced the launch of Project Ire – a dedicated AI agent for malware…Project Ire – Microsoft Launches AI Agent For Automated Malware Class…
The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads.Trustwave S…
A Chinese-speaking advanced persistent threat (APT) actor has been observed targeting web infrastructure entities in Taiwan using customized versions of open-s…