IM
IronMonkey Threat Research
LIVE
|
Articles 28,672
|
CVEs 366,632
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,640 articles — Page 157 of 955
Threats | CyberScoop ·

CrowdStrike says The Com-affiliated threat groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion. The post Two new extortion crews...

Scattered Spider Silk Typhoon Transportation Systems Commercial Facilities Cybercrime Cybersecurity
BleepingComputer ·

A new phishing kit named Bluekit offers more than 40 templates targeting popular services and includes basic AI features for generating campaign drafts. [...]

Information Technology Financial Services Security Artificial Intelligence
The Hacker News ·

Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The high-severity vulnerability...

Silk Typhoon Information Technology
LevelBlue SpiderLabs Blog ·

Vect ransomware, a new group that emerged in January 2026, has recently begun attracting attention in the cybersecurity space for its strategic partnerships, which are helping it expand. One...

Information Technology Emerging Threats Vulnerabilities
Alerts and advisories ·

GitLab security advisory (AV26-406)

Information Technology
The Cloudflare Blog ·

Cloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet.

Post-Quantum IPsec
BleepingComputer ·

A Romanian national who led an online swatting ring that targeted more than 75 public officials, multiple journalists, and four religious institutions was sentenced to 4 years in federal prison. [...]

Government Facilities Security
The Register - Security ·

Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support'

Financial Services Information Technology security
Wiz Blog | RSS feed ·

When AI meets CI/CD: permission bypasses, prompt injection, and what to do about it.

Information Technology
Industrial Cyber ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and government partners have released a new guide to accelerate... The post New CISA guidance outlines zero trust roadmap for OT...

Volt Typhoon Critical Manufacturing Energy Attacks and Vulnerabilities Backup, recovery and Resilience
Industrial Cyber ·

Healthcare organizations recorded 120 ransomware attacks in the first quarter of this year, marking a 14% decline compared... The post Comparitech assesses healthcare ransomware decline in volume...

Healthcare and Public Health Information Technology Attacks and Vulnerabilities Control device security
Industrial Cyber ·

New research from RunSafe Security highlights growing operational and clinical impact of cyber threats targeting connected healthcare technology.... The post RunSafe Index reports that healthcare...

Healthcare and Public Health Information Technology Attacks and Vulnerabilities Control device security
The Register - Security ·

Just in time for the Trump-Xi summit

Salt Typhoon Earth Alux Transportation Systems Government Facilities security
Industrial Cyber ·

Claroty’s threat research team, Team82, uncovered two vulnerabilities in EnOcean’s SmartServer IoT platform affecting version 4.60.009 and earlier.... The post Research finds EnOcean SmartServer...

Information Technology Critical Manufacturing Attacks and Vulnerabilities Control device security
The Hacker News ·

Google has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini-cli" GitHub Actions workflow -- that could...

Silk Typhoon Information Technology
BleepingComputer ·

The U.S. Federal Bureau of Investigation (FBI) warned the transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada...

Transportation Systems Financial Services Security
The Register - Security ·

Emergency patches out now for those managing the millions of domains assumed to be affected

Information Technology security
Industrial Cyber ·

Northwood University has been designated as a National Center of Academic Excellence in Cybersecurity by the National Security... The post Northwood University earns NSA Cybersecurity Excellence...

Government Facilities Information Technology News The Skills Gap - Training & Development
CERT Polska ·

Cross-site Scripting vulnerability (CVE-2026-1493) has been found in LEX Baza Dokumentów software.

Information Technology CVE vulnerability
Tenable Blog ·

A flaw in the Linux kernel present since 2017 allows a local user to gain root access on virtually every major Linux distribution. A public exploit is available and reported to work reliably.Key...

Information Technology
The Register - Security ·

Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support' Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big...

Financial Services Healthcare and Public Health
BleepingComputer ·

The April 2026 KB5083769 security update breaks third-party backup applications from multiple vendors on systems running Windows 11 24H2 and 25H2. [...]

Information Technology Microsoft
The Register - Security ·

Just in time for the Trump-Xi summit Exclusive A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in...

Salt Typhoon Earth Alux Government Facilities Defense Industrial Base
Schneier on Security ·

Researchers have reverse-engineered a piece of malware named Fast16. It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet: “…the Fast16...

Government Facilities Defense Industrial Base Uncategorized cybersecurity
The Register - Security ·

Emergency patches out now for those managing the millions of domains assumed to be affected Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to...

Information Technology
Kaspersky ICS CERT (English) ·

This quarter, Australia and New Zealand ranked first in terms of the growth in the percentage of ICS computers on which web miners were blocked.

Critical Manufacturing Energy Publications
BleepingComputer ·

When a new asset goes live, attackers start scanning within minutes. Sprocket Security shows how automated attacks move from discovery to compromise in under 24 hours. [...]

Security
The Register - Security ·

Great idea, guys. Let's keep all of the data in an Excel file with weak password protection

Financial Services Information Technology security
Security Latest ·

Extremely sensitive personal data from a European celebrity that appears to have been compiled using spyware was publicly accessible until a researcher flagged the exposure.

Information Technology Communications Security Security / Privacy
SECURITY.COM ·

Part 4 of 6: Aligning co-marketing for conversion

Financial Services