IM
IronMonkey Threat Research
LIVE
|
Articles 28,316
|
CVEs 362,330
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 38 articles on Aug 20, 2026
The Hacker News ·

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation...

The Hacker News ·

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to...

The Hacker News ·

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to...

The Hacker News ·

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The...

www.theregister.com - Articles ·

Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget

security
The Hacker News ·

Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a...

Financial Services Information Technology
The Hacker News ·

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when...

Information Technology
The Hacker News ·

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to...

Information Technology
The Hacker News ·

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial...

Information Technology Financial Services
The Hacker News ·

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated...

Government Facilities Information Technology
www.theregister.com - Articles ·

Because apparently even ransomware gangs can't trust the people they do business with

cyber-crime
The Hacker News ·

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its...

RTM Financial Services Information Technology
Threats | CyberScoop ·

The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs...

Cybercrime Government
www.theregister.com - Articles ·

A spoonful of encryption helps the malware go down

Information Technology ai and ml
www.theregister.com - Articles ·

Stolen details range from contact information to household finances and withholding rates

Financial Services Government Facilities security
The Hacker News ·

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket...

Threat Intelligence ·

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate...

Threat Intelligence
Alerts and advisories ·

Cisco security advisory (AV26-834)

Check Point Research ·

Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation...

Information Technology Check Point Research Publications
CERT Polska ·

CERT Polska has received a report about 13 vulnerabilities (from CVE-2026-64960 to CVE-2026-64972) found in ATutor software.

CVE vulnerability
The Hacker News ·

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability,...

Information Technology
BleepingComputer ·

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

Security
Tenable Blog ·

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across...

BleepingComputer ·

AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to...

Security
Cisco Talos Blog ·

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis...

Information Technology Threat Spotlight AI
Cisco Talos Blog ·

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries...

Information Technology Government Facilities Threat Spotlight AI
Unit 42 ·

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted...

Information Technology Communications Malware Threat Research
SECURITY.COM ·

Symantec® CBX is the perfect marriage of Symantec and Carbon Black® technologies into a unified XDR platform

Information Technology Government Facilities
Schneier on Security ·

A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A...

Government Facilities Uncategorized cars
www.theregister.com - Articles ·

Fortunately, the company had a policy of checking source code on GitHub first

Information Technology security
Kaspersky ICS CERT EN (English) ·

In this quarter, the number of attacks on ICS aimed at causing physical damage significantly increased

Publications
BleepingComputer ·

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

Information Technology Security
BleepingComputer ·

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

Information Technology Government Facilities Security
BleepingComputer ·

A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]

Financial Services Information Technology Security Mobile
BleepingComputer ·

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]

Winter Vivern Cozy Bear Midnight Blizzard Information Technology Government Facilities Security
BleepingComputer ·

Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]

Information Technology Microsoft Gaming
www.theregister.com - Articles ·

'It is an active threat'

Energy Water security
The Hacker News ·

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at...

Information Technology Communications