IM
IronMonkey Threat Research
LIVE
|
Articles 28,671
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,639 articles — Page 145 of 955
Tenable Blog ·

AI-driven discovery, NIST’s retreat from universal enrichment, and the end of “good enough” vulnerability managementKey takeawaysAI-driven discovery tools are accelerating CVE volume, resulting in...

Information Technology
Wiz Blog | RSS feed ·

Unpatched kernel flaw chain (CVE-2026-43284, CVE-2026-43500) enables root escalation on major Linux distributions.

Information Technology
Security Latest ·

With the launch of the first 16 satellites, Russia begins construction of a network for satellite internet that aims to cover the entire country by 2030. But getting there won’t be easy.

Government Facilities Security Security / National Security
Vulnerabilities – The Cyber Express ·

A newly disclosed local privilege escalation (LPE) vulnerability known as Dirty Frag is raising serious concerns across the Linux ecosystem after researchers revealed that the flaw can grant root...

Information Technology Firewall Daily Cyber News
BleepingComputer ·

CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]

Information Technology Government Facilities Security
Securelist ·

During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.

Mustang Panda Bronze President HoneyMyte Information Technology Vulnerability reports Linux
Have I Been Pwned latest breaches ·

In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was...

ShinyHunters
BleepingComputer ·

Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned. [...]

ShinyHunters Commercial Facilities Security
eCrime.ch Ransomware News | RSS ·

Universities across the US reported widespread outages on Thursday after a cybersecurity incident affected the Canvas online learning platform used by colleges nationwide. The disruption involved...

Government Facilities Information Technology
Industrial Cyber ·

Industrial cybersecurity firm Dragos revealed details of an AI-assisted intrusion targeting a municipal water and drainage utility serving... The post Dragos details AI-assisted intrusion...

Information Technology Water Attacks and Vulnerabilities Control device security
Industrial Cyber ·

Researchers at Securelist by Kaspersky disclosed an ongoing supply chain attack targeting the official website of the widely... The post Kaspersky uncovers targeted DAEMON Tools supply chain...

Critical Manufacturing Information Technology Attacks and Vulnerabilities Control device security
Security Latest ·

Thousands of schools around the US were paralyzed on Thursday after education tech firm Instructure shut down access to its Canvas platform following a breach by hackers going by the name ShinyHunters.

ShinyHunters Information Technology Commercial Facilities Security Security / Cyberattacks and Hacks
BleepingComputer ·

A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor. [...]

Government Facilities Information Technology Security
BleepingComputer ·

A new Linux zero-day vulnerability, named Dirty Frag, allows local attackers to gain root privileges on most major Linux distributions with a single command. [...]

Information Technology Security Linux
www.theregister.com - Articles ·

Yet it remains unclear if Anthropic's uber model was effective, or if better model middleware is what makes the difference

Information Technology security
Recorded Future ·

Explore the different types of payment fraud and become aware of telltale signs and how to prevent them.

Financial Services Commercial Facilities Blog
The Hacker News ·

Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score:...

Silk Typhoon Information Technology Government Facilities
The Hacker News ·

Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the...

Silk Typhoon Information Technology Financial Services
www.theregister.com - Articles ·

Security biz Adversa AI argues users of AI tools need clearer warnings

Information Technology Critical Manufacturing security
Threats | CyberScoop ·

Attackers are hitting a frequent target in the network edge space, intruding victim networks through a defect in a widely used mobile endpoint security product. The post Ivanti customers confront...

Silk Typhoon Information Technology Cybersecurity Threats
Security Latest ·

Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns. The good news: You can easily uninstall it. The bad? You might not want to.

Information Technology Security Security / Privacy
The Hacker News ·

The hardest part of cybersecurity isn't the technology, it’s the people. Every major breach you’ve read about lately usually starts the same way: one employee, one clever email, and one "Patient...

Silk Typhoon Healthcare and Public Health
The Hacker News ·

Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in...

Silk Typhoon Information Technology Government Facilities
www.theregister.com - Articles ·

Happy World Password Day! Maybe it's finally time to kill this holiday in favor of World No-More-Passwords Day?

security
BleepingComputer ·

The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting another vulnerability to deface Canvas login portals for hundreds of colleges and...

ShinyHunters Information Technology Government Facilities Security
BleepingComputer ·

A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems. [...]

Financial Services Information Technology Security
Cisco Talos Blog ·

Cybersecurity concepts — logs, packets, DNS exfiltration, and more — are usually intangible, and its practitioners are prone to mental fatigue, Amy takes a second to yell at you to go touch grass.

Information Technology Communications Threat Source newsletter
The Hacker News ·

Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord...

Silk Typhoon Karakurt Chromium Critical Manufacturing Energy
The Hacker News ·

Having an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means someone will answer the phone....

Silk Typhoon Information Technology
Alerts and advisories ·

Ivanti security advisory (AV26-435)

Information Technology Government Facilities