IM
IronMonkey Threat Research
LIVE
|
Articles 28,662
|
CVEs 366,425
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,632 articles — Page 807 of 955
The Hacker News ·

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing kit that's capable of Microsoft 365 accounts with an aim to steal credentials and two-factor authentication...

Information Technology
The Hacker News ·

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and four entities for their alleged involvement in illicit revenue generation schemes for the...

Nickel Tapestry Financial Services Transportation Systems
infosecurity-magazine ·

SecurityScorecard identified a new campaign in which the North Korean Lazarus group aims to steal source code, secrets and cryptocurrency wallet keys from developer environments

Lazarus Group Financial Services Critical Manufacturing
BleepingComputer ·

Hotel management platform Otelier suffered a data breach after threat actors breached its Amazon S3 cloud storage to steal millions of guests' personal information and reservations for well-known...

Commercial Facilities Communications
Lumen Blog ·

Security for the Internet of Things (IoT) is any process used to protect a network of over 18 billion interconnected devices worldwide that collect and share data. These smart devices can be found...

Critical Manufacturing Information Technology
CyberScoop ·

As the incoming Trump administration prepares to take office, it confronts a critical juncture for cybersecurity. The escalating digital threats from state-sponsored adversaries like China, Iran,...

Volt Typhoon Salt Typhoon Communications Government Facilities
BleepingComputer ·

A malicious package named 'pycord-self' on the Python package index (PyPI) targets Discord developers to steal authentication tokens and plant a backdoor for remote control over the system. [...]

Commercial Facilities Communications
Industrial Cyber ·

Outgoing U.S. President Joe Biden issued an Executive Order aimed at enhancing the nation’s cybersecurity, focused on defending... The post Biden issues executive order to further strengthen...

Salt Typhoon Government Facilities Energy
Hackread – Latest Cybersecurity, Tech, AI, Crypto & Hacking News ·

Explore how AI tools like OpenAI’s Sora face restrictions in Europe due to GDPR, with insights on bypassing…

Financial Services
infosecurity-magazine ·

Microsoft highlighted a new Star Blizzard campaign targeting WhatsApp accounts, as the group adapts its TTPs following the takedown of its infrastructure by law enforcement

Star Blizzard Midnight Blizzard Salt Typhoon Healthcare and Public Health Information Technology
BleepingComputer ·

​Microsoft has fixed a known issue that caused Microsoft 365 applications and Classic Outlook to crash on Windows Server 2016 or Windows Server 2019 systems. [...]

Communications
BleepingComputer ·

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has sanctioned Yin Kecheng, a Shanghai-based hacker for his role in the recent Treasury breach and a company...

Flax Typhoon Silk Typhoon Salt Typhoon Communications Financial Services
BleepingComputer ·

The Federal Communications Commission (FCC) has ordered U.S. telecommunications carriers to secure their networks following last year's Salt Typhoon security breaches. [...]

Salt Typhoon Communications
CyberScoop ·

The agency has embraced performance goals, provided resources to small systems and improved coordination, its deputy secretary writes. The post How HHS has strengthened cybersecurity of hospitals...

Healthcare and Public Health Government Facilities
infosecurity-magazine ·

AliExpress, Shein, Temu, TikTok, WeChat and Xiaomi are accused of operating unlawful data transfers to China

Salt Typhoon Healthcare and Public Health Energy
Securelist ·

Kaspersky experts analyzed the Mercedes-Benz head unit, its IPC protocols and firmware, and found new vulnerabilities via physical access.

BleepingComputer ·

​Microsoft has started the forced rollout of Windows 11 24H2 to eligible, non-managed systems running the Home and Pro editions of Windows 11 22H2 and 23H2. [...]

Hackread – Latest Cybersecurity, Tech, AI, Crypto & Hacking News ·

Silverfort has discovered that a misconfiguration can bypass an Active Directory Group Policy designed to disable NTLMv1, allowing…

Financial Services
The Hacker News ·

Austrian privacy non-profit None of Your Business (noyb) has filed complaints accusing companies like TikTok, AliExpress, SHEIN, Temu, WeChat, and Xiaomi of violating data protection regulations...

Financial Services
infosecurity-magazine ·

The EU’s DORA regulation is in effect as of January 17, with mixed evidence around compliance levels among financial firms

Financial Services Government Facilities
Tenable Blog ·

Shopping for OT systems? A new CISA guide outlines OT cyber features to look for. Meanwhile, the U.S. government publishes a playbook for collecting AI vulnerability data. Plus, a White House EO...

Critical Manufacturing Healthcare and Public Health
Malpedia Library (Latest) ·

2025-01-13 • Sekoia • Amaury G., Erwan Chevalier, Félix Aime, Maxime A. • vbs.hatvibe Open article on Malpedia

The Record from Recorded Future News ·

The federal government and multiple cybersecurity firms warned of a zero-day vulnerability in FortiGate firewalls that hackers are actively exploiting.

Government Facilities Information Technology
Unit 42 ·

CVE-2025-0282 and CVE-2025-0283 affect multiple Ivanti products. This threat brief covers attack scope, including details from an incident response case. The post Threat Brief: CVE-2025-0282 and...

Security Latest ·

A breach of AT&T that exposed “nearly all” of the company's customers may have included records related to confidential FBI sources, potentially explaining the Bureau's new embrace of end-to-end...

Salt Typhoon Communications Financial Services
Cloud Threat Landscape ·

An Otelier employee's workstation was infected with an infostealer, leading to compromise of their Jira credentials. The threat actor abused these to gain access to the Jira server, which...

Commercial Facilities
The Hacker News ·

The Russian threat actor known as Star Blizzard has been linked to a new spear-phishing campaign that targets victims' WhatsApp accounts, signaling a departure from its longstanding tradecraft in...

Blue Callisto Star Blizzard Gossamer Bear
CyberScoop ·

The North Korean office responsible for the scheme, Department 53, was created to funnel money back into the country’s weapons programs. The post Treasury sanctions North Korea over remote IT...

Salt Typhoon Fancy Bear Communications Critical Manufacturing
Krebs on Security ·

Residents across the United States are being inundated with text messages purporting to come from toll road operators like E-ZPass, warning that recipients face fines if a delinquent toll fee...

Transportation Systems Communications
CyberScoop ·

At least one key Republican told CyberScoop that he wasn’t happy about the last-minute nature of the EO. The post Biden cyber executive order gets mostly plaudits, but its fate is uncertain...

Government Facilities Critical Manufacturing