SilverRAT Source Code leaked on GitHub, exposing powerful malware tools for remote access, password theft, and crypto attacks before removal.
As many as 60 malicious npm packages have been discovered in the package registry with malicious functionality to harvest hostnames, IP addresses, DNS servers, and user directories to a...
Are your web privacy controls protecting your users, or just a box-ticking exercise? This CISO’s guide provides a practical roadmap for continuous web privacy validation that’s aligned with...
Cisco Talos warns of active exploitation of a zero-day vulnerability (CVE-2025-0994) in Cityworks supposedly by Chinese hackers from…
Cyber threats don't show up one at a time anymore. They’re layered, planned, and often stay hidden until it’s too late. For cybersecurity teams, the key isn’t just reacting to alerts—it’s spotting...
We were thrilled by the remarkable interest in speaking at TechCrunch Disrupt 2025, taking place October 27–29 at Moscone West in San Francisco. After an in-depth review process, we’ve selected 20...
2025-05-22 • Recorded Future • Insikt Group • py.cherryspy, vbs.hatvibe Open article on Malpedia
2025-05-22 • Recorded Future • Insikt Group • py.cherryspy, vbs.hatvibe Open article on Malpedia
2025-05-26 • Yonhap News Agency • Kim Boram • elf.bpfdoor Open article on Malpedia
2025-05-22 • Sekoia • Félix Aime, Jeremy Scion Open article on Malpedia
Researchers have released PoC for CVE-2025-32756, a severe security flaw, that is actively being exploited in Fortinet products…
2025-05-22 • Cisco Talos • Asheer Malhotra, Brandon White • win.tetra_loader Open article on Malpedia
The U.S. National Telecommunications and Information Administration (NTIA) supports efforts to enhance submarine cable security but urges the... The post US NTIA backs submarine cable security...
Cleartext Storage of Sensitive Information vulnerability (CVE-2025-4053) has been found in Be-Tech Mifare Classic cards software.
Nova Scotia Power has confirmed it was the victim of a ransomware attack, weeks after initially alerting customers to a cybersecurity breach. The utility, owned by Emera Inc., revealed that the...
Cisco Talos reported that a Chinese group has deployed web shells and malware in local government networks post-exploitation
Hackers. AI data scrapes. Government surveillance. Thinking about where to start when it comes to protecting your online privacy can be overwhelming. Here’s a simple guide for you—and anyone who...
Cyber-physical systems (CPS) protection company Claroty signed a strategic partnership with Ignition Technology, a specialist cloud and SaaS... The post Claroty and Ignition Technology join forces...
Finite State has expanded its executive team with the appointments of Tim Quock as chief operating officer and... The post Finite State appoints Tim Quock and Beth Linker to drive growth, product...
The International Society of Automation (ISA), a professional society for automation, announced that the Utilities Technology Council (UTC)... The post UTC joins ISASecure to strengthen...
2025-05-23 • TechCrunch • Lorenzo Franceschi-Bicchierai • osx.careto, win.careto Open article on Malpedia
2025-05-20 • KrebsOnSecurity • Brian Krebs • elf.airashi, elf.aisuru Open article on Malpedia
2025-05-22 • KrebsOnSecurity • Brian Krebs • win.danabot Open article on Malpedia
2025-05-22 • Flashpoint • Flashpoint • win.danabot Open article on Malpedia
2025-05-22 • ESET Research • Tomáš Procházka • win.danabot Open article on Malpedia
The US National Institute of Standards and Technology (NIST) published a white paper introducing a new metric called Likely Exploited Vulnerabilities (LEV)
Each Monday, the Tenable Exposure Management Academy provides the practical, real-world guidance you need to shift from vulnerability management to exposure management. This week, we look back on...
Google AI mode and AI Overviews now have ads, which, according to the search engine giant, are "helpful." [...]
Five major banking associations have formally petitioned the U.S. Securities and Exchange Commission (SEC) to repeal a rule that mandates public companies to disclose material cybersecurity...
OpenAI is planning to ship a new ChatGPT-powered product by 2026, but we aren't looking at yet another model. [...]