IM
IronMonkey Threat Research
LIVE
|
Articles 28,725
|
CVEs 366,928
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,694 articles — Page 401 of 957
The Register - Security ·

OBR says the scheme will cost £600M a year with no identified savings The UK government has finally put a £1.8 billion price tag on its digital ID plans – days after the minister responsible...

Financial Services
BleepingComputer ·

The French Football Federation (FFF) disclosed a data breach on Friday after attackers used a compromised account to gain access to administrative management software used by football clubs. [...]

Financial Services Security
Security Latest ·

It turns out all the guardrails in the world won’t protect a chatbot from meter and rhyme.

Nuclear Commercial Facilities Security Security / Cyberattacks and Hacks
Tenable Blog ·

Want to take a peek at your fellow cybersecurity practitioners’ thoughts on topics such as exposure response, patch management, and security tool sprawl? In case you missed them, we’re revisiting...

Information Technology Energy
Securelist ·

Kaspersky discloses new tools and techniques discovered in 2025 Tomiris activities: multi-language reverse shells, Havoc and AdaptixC2 open-source frameworks, communications via Discord and Telegram.

Cloud Atlas Mysterious Elephant ToddyCat Critical Manufacturing Government Facilities APT reports Malware Technologies
The Register - Security ·

Talk about buyer’s remorse South Korean web giant Naver has had an interesting week, after it acquired a cryptocurrency exchange that the next day revealed it had suffered a serious cyberattack.…

Financial Services Defense Industrial Base
The Hacker News ·

The threat actor known as Bloody Wolf has been attributed to a cyber attack campaign that has targeted Kyrgyzstan since at least June 2025 with the goal of delivering NetSupport RAT. As of October...

Information Technology Energy
The Hacker News ·

Microsoft has announced plans to improve the security of Entra ID authentication by blocking unauthorized script injection attacks starting a year from now. The update to its Content Security...

Information Technology Energy
The Register - Security ·

ReliaQuest finds fresh crop of phishing domains and toxic tickets Scattered Lapsus$ Hunters may be circling Zendesk users for its latest extortion campaign, with new phishing domains and...

Scattered Spider ShinyHunters Chemical Financial Services
Wiz Blog | RSS feed ·

How OAuth tokens, JWT fields and Entra sign-in logs reveal attacker behavior, and how to turn those signals into reliable detections.

The Register - Security ·

ChatGPT maker places other vendors under review following breach OpenAI says API users may be affected by a recent breach at its former data analytics provider, Mixpanel.…

The Hacker News ·

Hackers have been busy again this week. From fake voice calls and AI-powered malware to huge money-laundering busts and new scams, there’s a lot happening in the cyber world. Criminals are getting...

Salt Typhoon Financial Services Communications
CERT Polska ·

Remote Code Execution vulnerability (CVE-2025-12140) has been found in Wirtualna Uczelnia software.

CVE vulnerability
CERT Polska ·

Authorized shell command injection vulnerability (CVE-2025-8890) has been found in SDMC NE6037 routers.

CVE vulnerability
The Register - Security ·

Agency flags hijacks of insecure studio-to-transmitter gear after attackers pipe in fake alerts and vulgar audio Malicious intruders have hijacked US radio gear to turn emergency broadcast tones...

Communications
The Register - Security ·

Brewer finally tallies fallout from September attack as it pushes earnings into 2026 Asahi has finally done the sums on September's ransomware attack in Japan, conceding the crooks may have helped...

Critical Manufacturing Transportation Systems
The Hacker News ·

Gainsight has disclosed that the recent suspicious activity targeting its applications has affected more customers than previously thought. The company said Salesforce initially provided a list of...

Scattered Spider ShinyHunters Information Technology Energy
BleepingComputer ·

Unrestricted large language models (LLMs) like WormGPT 4 and KawaiiGPT are improving their capabilities to generate malicious code, delivering functional scripts for ransomware encryptors and...

Defense Industrial Base Financial Services Security
The Register - Security ·

Audit sympathetic toward Comhairle nan Eilean Siar as staff stretched to capacity trying to recover Auditors remain concerned about the cyber resilience of a Scottish council as some systems are...

Financial Services Government Facilities
BleepingComputer ·

GreyNoise Labs has launched a free tool called GreyNoise IP Check that lets users check if their IP address has been observed in malicious scanning operations, like botnet and residential proxy...

Information Technology Security
WeLiveSecurity ·

Online disagreements among young people can easily spiral out of control. Parents need to understand what’s at stake.

Chemical Communications Kids Online
BleepingComputer ·

OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed following a breach at its third-party analytics provider Mixpanel. [...]

Financial Services Security
Have I Been Pwned latest breaches ·

In 2011, the China Software Developer Network (CSDN) suffered a data breach that exposed over 6M user records. The data included email addresses alongside usernames and plain text passwords.

Financial Services
The Hacker News ·

The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry. The Socket Research Team said it...

Information Technology Critical Manufacturing
Maxwell Dulin's Resources ·

Blind XSS is a funny bug. You launch a payload, you walk away and eventually, the exploit is triggered when somebody loads the page. This article describes a similar type of exploit but with using...

Maxwell Dulin's Resources ·

Astro is a web framework that has gained a lot of popularity in recent years - 50K stars and 800K downloads per week. It renders components on the server side, similar to NextJS but sends...

Government Facilities
Threats | CyberScoop ·

OnSolve CodeRED was damaged by the attack and has been nonoperational since earlier this month. Dozens of agencies and their respective users have been impacted by the outage and data theft. The...

Salt Typhoon Communications Emergency Services Cybercrime Cybersecurity
Cybersecurity Blog | SentinelOne ·

Learn about the actions required to defend against Shai-Hulud Worm 2.0 and how our real-time detection posture is securing your environment.

Critical Manufacturing Information Technology Company npm
The Register - Security ·

Maybe if your hand has 200+ fingers... Gainsight CEO Chuck Ganapathi downplayed the victim count related to his company's recent breach, saying he's only aware of "a handful of customers" who had...

The Hacker News ·

South Korea's financial sector has been targeted by what has been described as a sophisticated supply chain attack that led to the deployment of Qilin ransomware. "This operation combined the...

Moonstone Sleet Financial Services Information Technology