The U.S. National Institute of Standards and Technology (NIST) released a draft revision of NISTIR 8323 Rev. 2,... The post NIST revises PNT services cybersecurity guidance under CSF 2.0 to...
A cyber intrusion initially presented as a conventional Chaos ransomware attack has now been linked with moderate confidence... The post Rapid7 links Chaos ransomware campaign to Iranian...
Following its November move to become an official CVE Program Root, the European Union Agency for Cybersecurity (ENISA)... The post ENISA strengthens EU vulnerability coordination as four...
ALS Ltd (ASX: ALQ) has come under renewed investor scrutiny after disclosing a recent cyber security incident that temporarily disrupted some of its global operations. The company said it...
Arezzo, 10 maggio 2026 – Alla vigilia della grande mostra per i cento anni della sua storia e mentre Arezzo si preparava ad accendere le luci della fiera OroArezzo, il cuore digitale di Unoaerre è...
On May 11, 2026, TeamPCP launched coordinated software supply chain attacks targeting the npm and PyPI ecosystems. Over roughly six hours, the attacker published dozens of trojanized packages...
Alan Weissberger of the IEEE Communications Society (ComSoc) Techblog felt the ongoing culture and education gaps been network security and engineering needed to be highlighted as it is keeping...
Alan Weissberger of the IEEE Communications Society (ComSoc) Techblog felt the ongoing culture and education gaps been network security and engineering needed to be highlighted as it is keeping...
Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process...
The attack begins with unauthorized access to exposed Jenkins instances, often enabled by weak credentials. Threat actors abuse the scriptText endpoint, which allows execution of Groovy scripts,...
Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I’d come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat...
cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and denial-of-service....
Plus: Meta officially kills encrypted Instagram DMs, the Trump administration targets “violent left wing extremists,” leaked documents reveal Russia's school for elite hackers, and more.
A malicious Hugging Face repository that reached the platform's trending list impersonated OpenAI's "Privacy Filter" project to deliver information-stealing malware to Windows users. [...]
Previously, the attackers gained access to internal resources, and used it to extract sensitive credentials, including publishing credentials for Jenkins plugins. Using this access, they modified...
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being...
Evidence of them has been found by analyzing DNA in the seawater. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick...
All your compromised credentials are belong to us now instead of the other gang
cPanel security advisory (AV26-437)
AI models now find and exploit zero-days autonomously. This 4-pillar framework accelerates patching, analysis, and threat response.
AL26-011 - Vulnerabilities affecting Linux - CVE-2026-43284 and CVE-2026-43500
Insider trading is rife on Polymarket: Analysis by the Anti-Corruption Data Collective, a non-profit research and advocacy group, found that long-shot bets—defined as wagers of $2,500 or more at...
The Senate’s top Democrat is worried about smaller government entities being left behind as AI models advance hacking risks. The post Sen. Schumer seeks DHS plan on AI cyber coordination with...
The Senate’s top Democrat is worried about smaller government entities being left behind as AI models advance hacking risks. The post Sen. Schumer seeks DHS plan on AI cyber coordination with...
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems to establish a silent foothold as well as facilitate a broad range of post-compromise...
Microsoft Edge security advisory (AV26-436)
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report...
Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE
After years of insisting end-to-end encryption was the future of online comms, Zuckcorp has handed itself full visibility into user chats once again