IM
IronMonkey Threat Research
LIVE
|
Articles 28,659
|
CVEs 366,199
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,629 articles — Page 39 of 955
www.theregister.com - Articles ·

Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds

Laundry Bear Government Facilities Defense Industrial Base security
Tenable Blog ·

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure...

Energy Water
Wiz Blog | RSS feed ·

A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.

Information Technology Financial Services
Vulnerabilities – The Cyber Express ·

A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed CVE-2026-63077, a vulnerability that could allow...

Information Technology Firewall Daily Vulnerabilities
BleepingComputer ·

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]

Energy Information Technology Security
The Hacker News ·

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a...

Sapphire Sleet Alluring Pisces Information Technology Financial Services
BleepingComputer ·

American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]

Critical Manufacturing Healthcare and Public Health Security
Schneier on Security ·

This essay originally appeared in The Guardian. I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my...

Information Technology Government Facilities Uncategorized AI
Securelist ·

Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

Smoke Sandstorm Lurk Kimsuky GReAT research Malware descriptions
The Hacker News ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known...

Information Technology Communications
Security Latest ·

If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.

Information Technology Security Security / Cyberattacks and Hacks
BleepingComputer ·

Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and...

Energy Security
Unit 42 ·

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses...

Information Technology Threat Research Vulnerabilities
Cisco Talos Blog ·

Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.

Information Technology Humans of Talos
Security Latest ·

Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield.

Government Facilities Defense Industrial Base The Big Story Security
Security Latest ·

Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.

Information Technology Financial Services Security Security / Security News
www.theregister.com - Articles ·

Schools often don't prioritize or understand cybersecurity

Government Facilities security
WeLiveSecurity ·

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine

Financial Services Digital Security
www.theregister.com - Articles ·

If your AI goes rogue, better have a good lawyer

Information Technology legal
Securelist ·

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.

Smoke Sandstorm Kimsuky Cloud Atlas Malware descriptions Malware Technologies
Vulnerabilities – The Cyber Express ·

WordPress has released security updates to address the wp2shell vulnerability, a critical flaw that allowed attackers to achieve remote code execution (RCE) on vulnerable sites using a single...

Information Technology Firewall Daily Vulnerabilities
Recorded Future ·

Combat AI-generated extortion and fake ransomware leaks. Learn how organizations can verify data authenticity using robust governance and threat intelligence.

Blog
Recorded Future ·

Explore the 2026 US violent extremism threat landscape. This report analyzes rising risks from HVEs, DVEs, and Iran-nexus actors to public and private sector entities.

Government Facilities Research (Insikt)
The Hacker News ·

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads....

Information Technology
Threats | CyberScoop ·

Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was...

Stardust Chollima Sapphire Sleet Information Technology Financial Services Threats Amazon
The Hacker News ·

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated...

Information Technology
The Hacker News ·

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The...

Information Technology
www.theregister.com - Articles ·

"I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source

Information Technology ai and ml
SECURITY.COM ·

How independent analyst validation reinforces Symantec SSE’s approach to Zero Trust security

Information Technology
BleepingComputer ·

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated...

Reaper Void Blizzard Laundry Bear Information Technology Government Facilities Security