IM
IronMonkey Threat Research
LIVE
|
Articles 28,662
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,632 articles — Page 238 of 955
The Register - Security ·

Digital freedom needs a Kali Linux for the rest of us Opinion The hacker mind is a curious way to be. To have it means to embody endless analytical curiosity, an awareness of any given rule set as...

The Hacker News ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active...

The Register - Security ·

Kids profited from tools used to attack popular websites, say officials Polish police have referred seven suspected juvenile cybercriminals to family court over an alleged scheme to flog DDoS kits online.…

BleepingComputer ·

Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello. [...]

Defense Industrial Base Microsoft Security
BleepingComputer ·

A newly discovered botnet malware called KadNap is targeting primarily ASUS routers and other edge networking devices to turn them into proxies for malicious traffic. [...]

Transportation Systems Security
BleepingComputer ·

Malware is evolving to evade sandboxes by pretending to be a real human behind the keyboard. The Picus Red Report 2026 shows 80% of top attacker techniques now focus on evasion and persistence,...

Information Technology Energy Security
Securelist ·

Kaspersky researchers identified a new Android Trojan dubbed BeatBanker targeting Brazil, posing as government apps and Google Play Store, and capable of both crypto mining and stealing banking data.

Cloud Atlas Evasive Panda Mustang Panda Financial Services Critical Manufacturing GReAT research Malware descriptions
Unit 42 ·

Unit 42 research reveals AI judges are vulnerable to stealthy prompt injection. Benign formatting symbols can bypass security controls. The post Auditing the Gatekeepers: Fuzzing "AI Judges" to...

Malware Threat Research
SECURITY.COM ·

Part 3: Government-scale stakes demand IAM that keeps pace with the AI multiplier

Government Facilities Emergency Services
WeLiveSecurity ·

The resurgence of one of Russia’s most notorious APT groups

Fancy Bear Sednit Forest Blizzard Government Facilities Defense Industrial Base ESET research
Schneier on Security ·

Countries around the world are becoming increasingly concerned about their dependencies on the US. If you’ve purchase US-made F-35 fighter jets, you are dependent on the US for software...

Uncategorized DRM
eCrime.ch Ransomware News | RSS ·

The Community College of Beaver County is under a cyberattack, with unknown bad actors encrypting all college data and demanding ransom payments to lift it. "We came to campus this morning, the...

Industrial Cyber ·

A white paper from the Cyber Defense Assistance Collaborative (CDAC) finds that since the start of Russia’s full-scale... The post CDAC report examines cyber defense support to Ukraine as attacks...

Critical Manufacturing Energy Attacks and Vulnerabilities Control device security
Industrial Cyber ·

Darktrace, vendor of AI for cybersecurity, announced that Ed Jennings has been appointed President and Chief Executive Officer... The post Darktrace appoints Ed Jennings as president and CEO to...

Critical Manufacturing Energy News Vendors
BleepingComputer ·

CISA flagged a high-severity Ivanti Endpoint Manager (EPM) vulnerability as actively exploited in attacks and ordered U.S. federal agencies to patch systems within three weeks. [...]

Government Facilities Security
BleepingComputer ·

Microsoft will turn on hotpatch security updates by default for all eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API, beginning with the May 2026 Windows...

Microsoft
Tenable Blog ·

Tenable Research revealed "LeakyLooker," a set of nine novel cross-tenant vulnerabilities in Google Looker Studio. These flaws could have let attackers exfiltrate or modify data across Google...

Information Technology Financial Services
BleepingComputer ·

The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations. [...]

Fancy Bear Forest Blizzard Defense Industrial Base Government Facilities Security
The Hacker News ·

Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts....

Financial Services Healthcare and Public Health
TrustedSec ·

The Second Most Important Data Source You're Probably Not CapturingIn Part 2, we enabled process creation logging with command lines. That's a big step forward. But here's the thing about PowerShell:…

Information Technology
Maxwell Dulin's Resources ·

Zero Knowledge Proofs (ZKP) are a crazy but black-magic mechanism for knowing that something happened without revealing what happened. For instance, proving that a person voted without giving up...

Critical Manufacturing
Maxwell Dulin's Resources ·

CodeAnt AI is a AI assisted code review platform. They were scanning open-source repositories for CVE patches and checking whether the patches actually fixed the claimed vulnerability. Since...

Information Technology
The Register - Security ·

David and Goliath…but with AI agents Researchers at red-team security startup CodeWall say their AI agent hacked McKinsey's internal AI platform and gained full read and write access to the...

The Hacker News ·

The North Korean threat actor known as UNC4899 is suspected to be behind a sophisticated cloud compromise campaign targeting a cryptocurrency organization in 2025 to steal millions of dollars in...

Jade Sleet Slow Pisces Financial Services Information Technology
The Hacker News ·

Another week in cybersecurity. Another week of "you've got to be kidding me." Attackers were busy. Defenders were busy. And somewhere in the middle, a whole lot of people had a very bad Monday...

Transparent Tribe Arid Viper Financial Services Information Technology
Alerts and advisories ·

SolarWinds security advisory (AV25-613) – Update 1

BleepingComputer ·

Hackers contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called...

Information Technology Financial Services Security
The Register - Security ·

And they abused a Mandiant-developed open source tool in the attacks ShinyHunters told The Register that it has stolen data from about 100 high-profile companies in its latest Salesforce customer...

BleepingComputer ·

Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks shrinking from weeks to just...

Financial Services Information Technology Security Cloud
Threats | CyberScoop ·

The national cyber director is pitching an approach that blends cyber operations with diplomacy, law enforcement and pressure on CEOs to shore up their organizations. The post Sean Cairncross lays...

Healthcare and Public Health Government Facilities Financial Government