Authority says attackers accessed systems holding data tied to millions of Oyster and contactless users Transport for London has confirmed that a 2024 breach exposed the data of more than 7...
President Donald Trump on Thursday said he would name Sen. Markwayne Mullin (R-Okla.) to be the next Homeland Security secretary, moving current DHS chief Kristi Noem to a special envoy role...
This report provides statistical data on published vulnerabilities and exploits we researched during Q4 2025. It also includes summary data on the use of C2 frameworks in APT attacks.
EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential and a global leader in applied cybersecurity education, today launched its Enterprise AI Credential Suite, with...
Threat actors are employing a new variation of the ClickFix social engineering technique called InstallFix to convince users into running malicious commands under the pretext of installing...
The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed
The MITRE Caldera for OT team introduced HVACSim, a software-only simulator that plugs into its open-source adversary emulation... The post MITRE Caldera releases HVACSim to train OT security...
Cyolo, provider of remote privileged access for operational technology (OT) and cyber-physical systems (CPS), announced the release of... The post Cyolo PRO v7.0 introduces AI session...
Microsoft will soon begin rolling out a significant upgrade to Microsoft 365 Backup to speed up recovery by allowing administrators to restore individual files and folders. [...]
A cyber attack on Passaic County’s IT systems has investigators scrambling to fix it and learn what caused it. According to officials, a malware attack is affecting the IT systems and impacting...
The Halcyon Ransomware Research Center observed a call to action for pro-Palestinian and pro-Iranian regime operators to move ransomware activity from Sicarii ransomware to Baqiyat 313 Locker also...
A Ghanaian national pleaded guilty to his role in a massive fraud ring that stole over $100 million from victims across the United States through business email compromise attacks and romance scams. [...]
The U.S. Federal Bureau of Investigation (FBI) confirmed on Thursday that it's investigating a breach that affected systems used to manage surveillance and wiretap warrants. [...]
Of the 90 zero-days GTIG tracked in 2025, 43 hit enterprise tech Zero-day exploitation targeting enterprise tech products reached an all-time high last year, with China-linked cyber-espionage...
As the conflict in the Middle East continues to escalate, more than a dozen countries in the region have reportedly been affected by strikes.
Cisco has disclosed that two more vulnerabilities affecting Catalyst SD-WAN Manager (formerly SD-WAN vManage) have come under active exploitation in the wild. The vulnerabilities in question are...
The bureau didn’t provide any further details on the incident, which reportedly targeted a network for managing surveillance activity. The post FBI targeted with ‘suspicious’ activity on its...
Donald Trump said he would replace the secretary of the Department of Homeland Security. Noem's tenure was marked by aggressive anti-immigration tactics and ICE's killing of two US protestors.
HHS has updated its free RISC 2.0 toolkit with a new cybersecurity module, asking hospitals to assess digital threats alongside hurricanes, power failures and other hazards. The post HHS updates a...
Some weeks in cybersecurity feel routine. This one doesn’t. Several new developments surfaced over the past few days, showing how quickly the threat landscape keeps shifting. Researchers uncovered...
From a press release by HHS OCR: Today, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced a settlement with MMG Fusion, LLC (MMG), a Maryland software...
Thor analyzes CVE data from 2025 and provides recommendations for where and how organizations should strengthen their defenses.
MOIS-linked MuddyWater crew has a new, custom implant An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US...
Most organizations assume encrypted data is safe. But many attackers are already preparing for a future where today’s encryption can be broken. Instead of trying to decrypt information now, they...
A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and...
A Greek court sentenced four Intellexa executives to prison for their role in a 2022 scandal that involved the use of Predator spyware against more than 90 public figures in the country. Citizen...
Executive Abstract Operational Technology (OT) convergence has eliminated the historical separation between digital compromise and physical consequence. As... The post The Decoupling Phase and the...
The 43-year-old Russian national ran a ransomware operation that impacted more than 1,000 victims globally. The conspiracy netted more than $39 million in extortion payments. The post Phobos...
New research from Macrium Software reveals that increased spending on cybersecurity in the manufacturing sector may be misplaced... The post Macrium reports manufacturers may be overinvesting in...
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy...