This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q1 2025. It was last updated on May 15, 2025.JanuaryWe terminated 12 YouT…
A vulnerability has been discovered in Google Chrome which could allow for arbitrary code execution. Successful exploitation of this vulnerability could allow for arbitrary code execution in the...
Imagine this: Your organization completed its annual penetration test in January, earning high marks for security compliance. In February, your development team deployed a routine software update....
Steel manufacturer Nucor Corporation disclosed that it recently identified a cybersecurity incident involving unauthorized third-party access to certain... The post Nucor reports cybersecurity...
Reddit Struggles After Google's New Focus on Expertise
A new report from DTEX Systems is the deepest look at how North Korea’s remote IT workforce schemes are the tip of the iceberg when it comes to its cyber operations. The post North Korea’s...
A new report from DTEX Systems is the deepest look at how North Korea’s remote IT workforce schemes are the tip of the iceberg when it comes to its cyber operations. The post North Korea’s...
Ransomware has evolved into a deceptive, highly coordinated and dangerously sophisticated threat capable of crippling organizations of any size. Cybercriminals now exploit even legitimate IT tools...
A Russia-linked threat actor has been attributed to a cyber espionage operation targeting webmail servers such as Roundcube, Horde, MDaemon, and Zimbra via cross-site scripting (XSS)...
Coinbase is offering a $20m reward to help catch the threat actor behind a cyber-attack that could cost it between $180-$400m
Cybersecurity researchers have discovered a malicious package named "os-info-checker-es6" that disguises itself as an operating system information utility to stealthily drop a next-stage payload...
A new wave of attacks uses PowerShell and LNK files to secretly install Remcos RAT, enabling full remote…
Hackers are running a worldwide cyberespionage campaign dubbed 'RoundPress,' leveraging zero-day and n-day flaws in webmail servers to steal email from high-value government organizations. [...]
A stealthy fileless PowerShell attack using Remcos RAT bypassed antivirus by operating in memory
ASEC Blog publishes “Mobile Security & Malware Issue 3st Week of May, 2025”
Recently, AhnLab SEcurity intelligence Center (ASEC) has identified cases of the ModiLoader (DBatLoader) malware being distributed via email. ModiLoader ultimately executes SnakeKeylogger....
This report provides statistics, trends, and case information on the distribution of Infostealer malware, including the distribution volume, methods, and disguises, based on the data collected and...
Trends of major APT groups by country 1) North Korea Since November 2024, the North Korean APT group has been exploiting the vulnerability of South Korean Internet financial security software....
The SANS Institute has announced a major expansion of its Cyber Academies, aiming to triple the number of... The post SANS Institute ramps up cybersecurity workforce development, triples cyber...
In order to stay connected and in touch with customers and employees, businesses of all sizes are transforming their communication platforms to stay ahead. However, to fully embrace the AI...
The FBI warned that cybercriminals using AI-generated audio deepfakes to target U.S. officials in voice phishing attacks that started in April. [...]
The critical vulnerability is being exploited by BianLian, RansomwEXX and a Chinese nation-state actor known as Chaya_004
Dior confirmed a data breach compromising customer personal information, discovered on May 7
FrigidStealer malware targets macOS users via fake browser updates, stealing passwords, crypto wallets, and notes using DNS-based data…
Operation RoundPress targets webmail software to steal secrets from email accounts belonging mainly to governmental organizations in Ukraine and defense contractors in the EU
Kaspersky ICS CERT shares trends and statistics on industrial threats in Q1 2025.
Exploited CVEs are a leading cause of cloud breaches. Learn how to effectively mitigate them through context-aware risk prioritization.
Researchers discovered over 3000 Linux vulnerabilities in 2024, the most of any category
Nova Scotia Power confirms it suffered a data breach after threat actors stole sensitive customer data in a cybersecurity incident discovered last month. [...]
The voluntary cybersecurity charter asks NHS suppliers to commit to eight cybersecurity pledges, amid rising attacks on healthcare