IM
IronMonkey Threat Research
LIVE
|
Articles 27,601
|
CVEs 353,753
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 53 articles on Jul 31, 2026
The Hacker News ·

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint...

Schneier on Security ·

The Squid is a new scientific machine: One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan...

Government Facilities Uncategorized squid
Threats | CyberScoop ·

The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign. The post Trump blames Minnesota for cyberattacks on water sector, drawing...

Government Facilities Water Geopolitics Government
The Hacker News ·

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same...

Communications Information Technology
Siemens ProductCERT Security Advisories ·

SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version.

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information. Siemens has released a new version for SIMATIC WinCC Unified PC...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities. Siemens has released a new version for SINEC INS and recommends to update to the latest version.

Critical Manufacturing Information Technology
Siemens ProductCERT Security Advisories ·
Critical Manufacturing
Siemens ProductCERT Security Advisories ·

Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build...

Critical Manufacturing Information Technology
Siemens ProductCERT Security Advisories ·

Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: SICAM A8000 Device firmware CPCI85 for CP-8031/CP-8050 SICORE for CP-8010/CP-8012...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens...

Water Critical Manufacturing
Siemens ProductCERT Security Advisories ·

Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for...

Critical Manufacturing Information Technology
Siemens ProductCERT Security Advisories ·

Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised...

Energy Critical Manufacturing
Siemens ProductCERT Security Advisories ·

Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system’s host, user, and display name. Siemens...

Critical Manufacturing
Siemens ProductCERT Security Advisories ·

SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new...

Critical Manufacturing Energy
Siemens ProductCERT Security Advisories ·

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has...

Critical Manufacturing Information Technology
Siemens ProductCERT Security Advisories ·

Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules...

Critical Manufacturing Information Technology
Siemens ProductCERT Security Advisories ·

SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures...

Critical Manufacturing Energy
The Citizen Lab ·

Earlier this month, the Canadian government announced that it had signed the United Nations Convention against Cybercrime. Speaking with Michael Geist of Law Bytes, senior research associate Kate...

Government Facilities Information Technology
www.theregister.com - Articles ·

Hopefully the company secures houses better than it locks down SaaS systems

ShinyHunters Information Technology security
The Hacker News ·

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones...

Information Technology
BleepingComputer ·

Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service...

Healthcare and Public Health Security
BleepingComputer ·

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]

Information Technology Security
The Record from Recorded Future News ·

The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).

Kimsuky Laundry Bear Government Facilities Defense Industrial Base Government Industry
The Hacker News ·

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks...

Information Technology Government Facilities
Schneier on Security ·

The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1...

Information Technology Uncategorized AI
BleepingComputer ·

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors'...

Information Technology Financial Services Security CryptoCurrency
www.theregister.com - Articles ·

Whoever wins, we lose

Information Technology security
The Hacker News ·

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months....

ShinyHunters Information Technology Critical Manufacturing
The Hacker News ·

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction,...

Information Technology Communications
www.theregister.com - Articles ·

A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff

Financial Services Information Technology security
BleepingComputer ·

OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]

Information Technology Artificial Intelligence Technology
SECURITY.COM ·

How unified visibility and enforcement can help organizations protect their data in the AI era

Financial Services Information Technology
CERT Polska ·

CERT Polska has received a report about 5 vulnerabilities (from CVE-2025-67649 to CVE-2025-67651 and from CVE-2026-46593 to CVE-2026-46594) found in PHP Jabbers scripts.

Information Technology CVE vulnerability
BleepingComputer ·

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]

Information Technology Security Artificial Intelligence
Cybersecurity Blog | SentinelOne ·

Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.

Government Facilities Information Technology Company cyber
BleepingComputer ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and...

Water Energy Security
The Record from Recorded Future News ·

Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.

Kimsuky Laundry Bear Information Technology Technology News
The Hacker News ·

Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached...

Information Technology
Schneier on Security ·

Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using...

Information Technology Uncategorized face recognition
BleepingComputer ·

Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted...

Information Technology Security
Securelist ·

An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.

DNS Security technology
Unit 42 ·

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive...

Malware Threat Research
Security Latest ·

Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.

Information Technology Critical Manufacturing Security Security / Security News
Vulnerabilities – The Cyber Express ·

Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed...

Information Technology Communications Firewall Daily Vulnerabilities
www.theregister.com - Articles ·

Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem

Information Technology ai and ml
The Record from Recorded Future News ·

Finland stopped power transmissions with Russia at the start of the war in Ukraine, and two related telecom connections will stop at the end of this year, authorities said.

Kimsuky Laundry Bear Communications Information Technology Nation-state News
Alerts and advisories ·

VMware security advisory (AV26-763)

Information Technology
Security Latest ·

In a review triggered by OpenAI's Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party evaluations.

Information Technology Critical Manufacturing Business Business / Artificial Intelligence