The attacker chained Ivanti CSA zero-days to execute a base64-encoded Python script, which extracted the admin password from a local PostgreSQL database. Using this access, the attacker created or...
A Vulnerability has been discovered in Google Chrome which could allow for arbitrary code execution. Successful exploitation of the the vulnerability could allow for arbitrary code execution in...
Threat actors with ties to North Korea have been observed targeting Web3 and cryptocurrency-related businesses with malware written in the Nim programming language, underscoring a constant...
Barracuda’s Managed XDR team recently helped two companies mitigate incidents where attackers had managed to compromise computers and install rogue ScreenConnect remote management software.
The campaign uses thousands of phishing websites that mimic the design and product listings of retailers like Apple, Nordstrom and Hermes to trick people into entering their credit card information.
Okta researchers found hackers could make a phishing site with AI in just 30 seconds. Here's how to protect your business.
The insurance giant is one of the largest insurers in India.
The Scattered Spider hacking group has caused chaos among retailers, insurers, and airlines in recent months. Researchers warn that its flexible structure poses challenges for defense.
Brett Leatherman told CyberScoop in an interview that while the group still poses a threat, the bureau is focused on resilience and victim support, and going on offense could be in the future. The...
Brett Leatherman told CyberScoop in an interview that while the group still poses a threat, the bureau is focused on resilience and victim support, and going on offense could be in the future. The...
A judge just approved the sale of 23andMe's DNA data to TTAM Research Institute. So far, 15% of users have already requested that their data be deleted. Here's how you can, too.
With nearly 80% of cyber threats now mimicking legitimate user behavior, how are top SOCs determining what’s legitimate traffic and what is potentially dangerous? Where do you turn when firewalls...
Cybersecurity researchers are calling attention to phishing campaigns that impersonate popular brands and trick targets into calling phone numbers operated by threat actors. "A significant portion...
New Android malware Qwizzserial has infected 100,000 devices, primarily in Uzbekistan, stealing SMS data via Telegram distribution
North Korean state-backed hackers have been using a new family of macOS malware called NimDoor in a campaign that targets web3 and cryptocurrency organizations. [...]
Qantas has confirmed a data breach after attackers gained access through a third-party call centre platform, affecting millions…
An ex-ransomware negotiator is under criminal investigation by the Department of Justice for allegedly working with ransomware gangs to profit from extortion payment deals. [...]
You'll have to update Chrome to the latest version to fix a security hole that's already been exploited in the wild.
Understanding the risks and impact of deploying dev-mode in production environments
A third of AI-generated login URLs lead to incorrect or dangerous domains, according to Netcraft
In times of uncertainty, your best defense is to lock down your fundamentals
ASEC Blog publishes Ransom & Dark Web Issues Week 1, July 2025 A new ransomware group named Kawa4096 Tonga’s Ministry of Health hit by INC RANSOM ransomware attack User data from three...
Smarter TV operating systems offer added convenience - but they also introduce new privacy concerns, particularly around automatic content recognition (ACR).
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has levied sanctions against Russia-based bulletproof hosting (BPH) service provider Aeza Group to assist threat...
The spyware operation's exposed customer email addresses and passwords were shared with data breach notification service Have I Been Pwned.
The Nuki smart lock comes with an array of features and works with your existing deadbolt, so you can still use a key.
Using stalkerware is creepy, unethical, potentially illegal, and puts your data and that of your loved ones in danger.
Spain’s Interior Ministry said the suspects were responsible for stealing and leaking personal data belonging to high-ranking political figures, including Prime Minister Pedro Sánchez, President...
The Spanish police have arrested two individuals in the province of Las Palmas for their alleged involvement in cybercriminal activity, including data theft from the country's government. [...]
Cisco has removed a backdoor account from its Unified Communications Manager (Unified CM), which would have allowed remote attackers to log in to unpatched devices with root privileges. [...]