IM
IronMonkey Threat Research
LIVE
|
Articles 28,672
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,640 articles — Page 445 of 955
BleepingComputer ·

The FinWise breach shows that when insider threats strike, encryption is the last line of defense. Penta Security's D.AMO platform unites encryption, key management, and access control to keep...

Financial Services Government Facilities Security
Schneier on Security ·

Interesting article on people with nonstandard faces and how facial recognition systems fail for them. Some of those living with facial differences tell WIRED they have undergone multiple...

Communications Financial Services Uncategorized biometrics
Tenable Blog ·

Tenable has been named a Continuous Threat Exposure Management (CTEM) Leader in Latio’s 2025 Cloud Security Market Report. This recognition is based on rigorous product testing conducted by Latio...

Information Technology Energy
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for remote code execution.

Financial Services Commercial Facilities
The Register - Security ·

That's a lot of extended warranties The Jaguar Land Rover (JLR) cyberattack could end up being the costliest such incident in UK history, billed at an estimated £1.9 billion and affecting over...

Critical Manufacturing Commercial Facilities
The Hacker News ·

TP-Link has released security updates to address four security flaws impacting Omada gateway devices, including two critical bugs that could result in arbitrary code execution. The vulnerabilities...

Energy Information Technology
Securelist ·

Kaspersky experts break down the recent BetterBank incident involving ESTEEM token bonus minting due to the lack of liquidity pool validation.

Mysterious Elephant Critical Manufacturing Financial Services Incidents SOC, TI and IR posts
Broadcom Software Blogs ·

The China-based actor behind the Warlock ransomware may not be a new player and has links to malicious activity dating as far back as 2019.

Violet Typhoon Linen Typhoon Defense Industrial Base Healthcare and Public Health
Broadcom Software Blogs ·

China-based threat actors also compromised networks of government agencies in countries in Africa and South America.

UNC5221 Earth Estries Violet Typhoon Communications Government Facilities
SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms. ·

SentinelLABS uncovers a coordinated spearphishing campaign targeting organizations critical to Ukraine's war relief efforts.

Commercial Facilities Critical Manufacturing Ukraine
eCrime.ch Ransomware News | RSS ·

Qilin n'est pas un groupe de pirates informatiques, mais une "franchise" qui permet d'utiliser ses services contre rémunération. Apparue en 2022, elle reste nimbée de mystère. Des lycées du nord...

Emergency Services Energy
eCrime.ch Ransomware News | RSS ·

NEW YORK – New York Attorney General Letitia James today announced a settlement with a public accounting firm, Wojeski & Company (Wojeski), to strengthen its data security to protect consumers’...

Financial Services Healthcare and Public Health
BleepingComputer ·

A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for the war relief effort in Ukraine, including the...

Star Blizzard Security
eCrime.ch Ransomware News | RSS ·

On October 15, 2025, Jewett-Cameron Trading Co. Ltd. (the "Company") learned that a threat actor had gained unauthorized access to portions of the Company's information technology ("IT")...

Commercial Facilities Financial Services
Tenable Blog ·

Think you know all there is to know about cybersecurity? Guess again. Shadow AI is challenging security leaders with many of the same issues raised by other “shadow” technologies. Only this time,...

Information Technology Energy
WeLiveSecurity ·

Here’s what to know about the malware with an insatiable appetite for valuable data, so much so that it tops this year's infostealer detection charts

Financial Services Information Technology Malware
The Register - Security ·

ICO says probe unnecessary after reviewing ministry's handling of leak The UK's data protection regulator declined to launch an investigation into a leak at the Ministry of Defence that risked the...

Government Facilities
BleepingComputer ·

Hackers believed to be associated with China have leveraged the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint in attacks targeting government agencies, universities,...

Salt Typhoon Violet Typhoon Linen Typhoon Government Facilities Security
Recorded Future ·

Top 10 Takeaways from Predict 2025: Turning Intelligence Into Action

Volt Typhoon Salt Typhoon Transportation Systems Communications Blog
Cloud Threat Landscape ·

Initial access leverages IIS apps configured with reused/public machineKey (ValidationKey/DecryptionKey) values, enabling __VIEWSTATE deserialization to run arbitrary commands. Following foothold,...

The Hacker News ·

Meta on Tuesday said it's launching new tools to protect Messenger and WhatsApp users from potential scams. To that end, the company said it's introducing new warnings on WhatsApp when users...

Financial Services Energy
The Hacker News ·

Cybersecurity researchers have shed light on the inner workings of a botnet malware called PolarEdge. PolarEdge was first documented by Sekoia in February 2025, attributing it to a campaign...

Energy Information Technology
Have I Been Pwned latest breaches ·

During 2025, Synthient aggregated billions of records of "threat data" from various internet sources. The data contained 183M unique email addresses alongside the websites they were entered into...

Financial Services
BleepingComputer ·

The operators of Vidar Stealer, one of the most successful malware-as-a-service (MaaS) operations of the past decade, have released a new major version to reflect massive improvements in the malware. [...]

Financial Services Security
BleepingComputer ·

TP-Link has made firmware updates available for a broad range of Omada gateway models to address four vulnerabilities, among which a critical pre-auth OS command injection. [...]

Security
Tenable Blog ·

Oracle addresses 170 CVEs in its final quarterly update of 2025 with 374 patches, including 40 critical updates.BackgroundOn October 21, Oracle released its Critical Patch Update (CPU) for October...

Information Technology Energy
The Hacker News ·

Artificial intelligence (AI) holds tremendous promise for improving cyber defense and making the lives of security practitioners easier. It can help teams cut through alert fatigue, spot patterns...

Energy Information Technology
Broadcom Software Blogs ·

It’s dominating the economy and shaping the threats we face and how we defend against them

Transportation Systems Financial Services
BleepingComputer ·

CISA has confirmed that an Oracle E-Business Suite flaw tracked as CVE-2025-61884 is being exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog. [...]

ShinyHunters Government Facilities Security
The Record from Recorded Future News ·

In a letter to Apple cited by the state news agency TASS, the Federal Antimonopoly Service (FAS) said Apple’s current setup gives preference to foreign search engines, putting local providers at a...

Food and Agriculture Critical Manufacturing Government News