IM
IronMonkey Threat Research
LIVE
|
Articles 28,672
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,640 articles — Page 314 of 955
CERT Polska ·

CERT Polska has received a report about 2 vulnerabilities (CVE-2026-23796 and CVE-2026-23797) found in Quick.Cart software.

CVE vulnerability
The Register - Security ·

Right on cue, petulant hacktivists attempt to disrupt yet another global sporting event Italy's foreign minister says the country has already started swatting away cyberattacks from Russia...

Commercial Facilities
The Hacker News ·

A new, critical security vulnerability has been disclosed in the n8n workflow automation platform that, if successfully exploited, could result in the execution of arbitrary system commands. The...

Energy Information Technology
Cyble ·

Introduction France has released its National Cybersecurity Strategy for 2026-2030, and the document reveals an ambitious vision that extends far beyond traditional defense postures. Under the...

Financial Services Energy Cyber news Cybersecurity
The Register - Security ·

Patch meant to close a severe expression bug fails to stop attackers with workflow access Multiple newly disclosed bugs in the popular workflow automation tool n8n could allow attackers to hijack...

Information Technology Energy
Cisco Talos Blog ·

Cisco Talos uncovered “DKnife,” a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants.

Information Technology Commercial Facilities Threat Spotlight Cisco Talos Antivirus
Unit 42 ·

In 2025 a threat group compromised government and critical infrastructure in 37 countries, with reconnaissance in 155. The post The Shadow Campaigns: Uncovering Global Espionage appeared first on Unit 42.

Nation-State Cyberattacks Threat Actor Groups
The Register - Security ·

Businesses still chase the cheapest option, but politics and licensing shocks are changing priorities, says OpenNebula Interview Sovereignty remains a hot topic in the tech industry, but...

Government Facilities Information Technology
SECURITY.COM ·

BYOVD component included in ransomware payload itself, rather than as a separate tool.

Financial Services Transportation Systems
The Hacker News ·

Cybersecurity researchers have disclosed details of an active web traffic hijacking campaign that has targeted NGINX installations and management panels like Baota (BT) in an attempt to route it...

Energy
Research & Threat Intel News- Outpost24 Blog ·

Read about the top zero-day exploits in 2025 and the lessons learned, with analysis from Outpost24’s threat intelligence team. The post Lessons From 2025: Zero-Day Exploitation Shaping 2026...

Bronze Butler Violet Typhoon Linen Typhoon Information Technology Financial Services Research & Threat Intel
BleepingComputer ·

Conpet, Romania's national oil pipeline operator, has disclosed that a cyberattack disrupted its business systems and took down the company's website on Tuesday. [...]

Energy Critical Manufacturing Security
Vulnerabilities – The Cyber Express ·

A newly disclosed critical vulnerability, tracked as CVE-2026-25049, in the workflow automation platform n8n, allows authenticated users to execute arbitrary system commands on the underlying...

Healthcare and Public Health Communications Firewall Daily Cyber News
Securelist ·

We analyze the recent Stan Ghouls campaign targeting organizations in Russia and Uzbekistan: Java-based loaders, the NetSupport RAT, and a potential interest in IoT.

Cloud Atlas Evasive Panda Mustang Panda Critical Manufacturing Financial Services Research Targeted attacks
Tenable Blog ·

From school districts to state agencies, 2025 cyber incidents were a wake-up call about asset visibility. Discover five actionable lessons SLG leaders can use to close the cyber exposure gap and...

Information Technology Financial Services
Tenable Blog ·

From school districts to state agencies, 2025 cyber incidents were a wake-up call about asset visibility. Discover five actionable lessons SLG leaders can use to close the cyber exposure gap and...

Information Technology Financial Services
The Register - Security ·

It's a threat straight out of sci-fi, and fiendishly hard to detect Sleeper agent-style backdoors in AI large language models pose a straight-out-of-sci-fi security threat.…

The Register - Security ·

Picks chap who used to lead Redmond’s security, lures replacement from Google Microsoft CEO Satya Nadella has decided Microsoft needs an engineering quality czar, and shifted Charlie Bell, the...

DataBreaches.Net ·

Harvard University and the University of Pennsylvania (UPenn) have more in common than just being Ivy League universities. Both suffered data breaches involving donor information, and their stolen...

Nitro Healthcare and Public Health Energy Commentaries and Analyses Education Sector
Have I Been Pwned latest breaches ·

In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack. As part of the incident, Betterment customers...

Financial Services
Cloud Threat Landscape ·

TeamPCP’s operations center on abusing unauthenticated or weakly protected orchestration and management interfaces rather than exploiting traditional endpoints. Initial access is achieved via...

The Hacker News ·

Microsoft on Wednesday said it built a lightweight scanner that it said can detect backdoors in open-weight large language models (LLMs) and improve the overall trust in artificial intelligence...

Energy
The Hacker News ·

Threat hunters have disclosed details of a new, stealthy malware campaign dubbed DEAD#VAX that employs a mix of "disciplined tradecraft and clever abuse of legitimate system features" to bypass...

Energy
SECURITY.COM ·

The growing threat of automated attack infrastructure

Financial Services
The Register - Security ·

LLMs automated most phases of the attack A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI...

Security Latest ·

Suspected Chinese state-backed hackers hijacked the Notepadd++ update infrastructure to deliver backdoored version of the popular free source code editor and note-taking app for Windows.

Communications Defense Industrial Base Security Security / Cyberattacks and Hacks
The Hacker News ·

Threat actors affiliated with China have been attributed to a fresh set of cyber espionage campaigns targeting government and law enforcement agencies across Southeast Asia throughout 2025. Check...

APT 41 APT 4 APT 4 Energy Defense Industrial Base
DataBreaches.Net ·

If you noticed a lot of dark web leak site listings by a new group, 0apt, and have been concerned about whether they might be a dangerous and prolific group, the DataBreach[.]com team (no...

Nitro Healthcare and Public Health Defense Industrial Base Commentaries and Analyses Of Note
The Register - Security ·

US agencies told to patch by Friday Attackers are exploiting a critical SolarWinds Web Help Desk bug - less than a week after the vendor disclosed and fixed the 9.8-rated flaw. That's according to...

Government Facilities Defense Industrial Base
The Hacker News ·

An innovative approach to discovering, analyzing, and governing identity usage beyond traditional IAM controls. The Challenge: Identity Lives Outside the Identity Stack Identity and access...

Energy