IM
IronMonkey Threat Research
LIVE
|
Articles 28,670
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,639 articles — Page 44 of 955
LevelBlue SpiderLabs Blog ·

Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC)...

Information Technology Vulnerabilities
Articles – Threat Beat ·

The People’s Republic of China (PRC) has identified control over time, and the precision behind the “granting of time” as a critical capability. It seeks to weaponize “chronopolitics” to gain...

Defense Industrial Base Government Facilities Insight
Wiz Blog | RSS feed ·

See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit.

Information Technology
Articles – Threat Beat ·

Nvidia and a host of tech giants on Monday launched a new artificial intelligence safety initiative focused on open models, as the fallout from a cyberattack committed by rogue OpenAI models...

Information Technology Communications News
Articles – Threat Beat ·

After OpenAI enhanced the brain power of its chatbot last summer, hundreds of users worldwide began asking it how to make and deploy biological weapons and poisons. The models, operating largely...

Government Facilities Information Technology News
The Hacker News ·

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration...

CERT Polska ·

CERT Polska has received a report about 2 vulnerabilities (CVE-2026-57916 and CVE-2026-57917) found in proCertum SmartSign software.

Information Technology CVE vulnerability
Articles – Threat Beat ·

Over several weeks in June and July 2026, Europol supported an action targeting nihilistic violent extremist content online. Investigators from nine countries participated in these ‘Referral...

Information Technology Government Facilities News
Articles – Threat Beat ·

The Office of the Director of National Intelligence has shrunk more than is publicly known in recent weeks, losing about 200 personnel to firings and reassignments since June 1, according to data...

Government Facilities Energy News
Articles – Threat Beat ·

Previous U.S. foreign, security, and defense policies toward the People’s Republic of China (PRC) and the Chinese Communist Party (CCP) have failed. Contrary to the decades-long hopes and...

Information Technology Defense Industrial Base Insight
Articles – Threat Beat ·

Secretary of State Marco Rubio announced on Thursday a new visa restriction policy targeting foreign nationals responsible for or complicit in cybercrime and cyber-enabled crime. “This policy...

Defense Industrial Base Government Facilities News
CERT Polska ·

Integer overflow vulnerability (CVE-2026-16554) has been found in DaveGamble cJSON library.

Information Technology CVE vulnerability
Schneier on Security ·

Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops...

Communications Information Technology Uncategorized cell phones
Vulnerabilities – The Cyber Express ·

A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on...

Information Technology Firewall Daily Vulnerabilities
www.theregister.com - Articles ·

So much for Microsoft and CrowdStrike’s plans for consistent names across the industry

Seashell Blizzard Blue Echidna Government Facilities Information Technology security
The Hacker News ·

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete...

Financial Services Information Technology
The Hacker News ·

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can...

Information Technology
The Hacker News ·

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and...

Financial Services Information Technology
The Hacker News ·

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments...

Graceful Spider Lace Tempest Chubby Scorpius Information Technology
The Hacker News ·

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage...

Information Technology Financial Services
The Hacker News ·

Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary...

Information Technology
Security Latest ·

Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.

Scattered Spider Volt Typhoon Information Technology Nuclear Security Security / Security News
www.theregister.com - Articles ·

(Security) hole-ier than thou

Information Technology security
www.theregister.com - Articles ·

Stop the spread (of online recruiting and propaganda)

Information Technology Communications cyber-crime
Schneier on Security ·

Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Uncategorized squid
The Hacker News ·

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the...

Financial Services Information Technology
Alerts and advisories ·

Progress security advisory (AV26-746)

Information Technology
Threats | CyberScoop ·

Roughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint....

Scattered Spider Communications Information Technology Cybercrime Cybersecurity
The Hacker News ·

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that...

Information Technology
Alerts and advisories ·

HPE security advisory (AV26-745)

Information Technology