IM
IronMonkey Threat Research
LIVE
|
Articles 30,637
|
CVEs 376,111
|
APT Groups 583
|
Tools 2,196
|
Updated recently
Today Yesterday All 28 articles on Sep 18, 2026
The Hacker News ·

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in...

Transparent Tribe Earth Karkaddan Government Facilities Information Technology
www.theregister.com - Articles ·

Agentic exploits for the win (again)

Information Technology security
www.theregister.com - Articles ·

WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets

Financial Services Information Technology security
www.theregister.com - Articles ·

AI, fake uniforms, and mock government offices help crooks sell the con

Financial Services Healthcare and Public Health cyber-crime
The Hacker News ·

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability,...

Threats | CyberScoop ·

The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software...

AI Cybersecurity
SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms. ·

North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.

Jade Sleet TraderTraitor Financial Services Information Technology DPRK macOS
The Hacker News ·

In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire....

The Hacker News ·

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a...

SECURITY.COM ·

Why adding nodes to your primary site hurts performance, and how to scale with secondary sites instead

Information Technology
The Hacker News ·

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family,...

Information Technology
Security Latest ·

TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.

Information Technology Security Security / Cyberattacks and Hacks
Alerts and advisories ·

Google security advisory (AV26-939)

Information Technology
Alerts and advisories ·

[Control Systems] Moxa security advisory (AV26-938)

Critical Manufacturing Energy
Threats | CyberScoop ·

The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. The post International security agencies warn...

WaterPlum Information Technology Government Facilities Cybercrime Geopolitics
Articles – Threat Beat ·

Ukrainian strikes that damage Russian energy facilities in the Arctic could disrupt Moscow’s growing liquefied natural gas (LNG) trade with the People’s Republic of China (PRC) and eliminate one...

Energy Government Facilities Insight
Articles – Threat Beat ·

The Trump administration is weighing a plan to establish a government-led incubator aimed at investing in cybersecurity research and spinning out startups focused on developing tools for the...

Government Facilities Information Technology News
Alerts and advisories ·

[Control systems] Advantech security advisory (AV26-937)

Critical Manufacturing Information Technology
The Hacker News ·

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The...

Information Technology Financial Services
Articles – Threat Beat ·

Two weeks after a swarm of AI agents broke out of containment at OpenAI to hack the company Hugging Face, the ChatGPT maker learned about another AI-powered intrusion — and this time it was the...

Information Technology News
Articles – Threat Beat ·

Foreign actors gained access to two small water utility systems in Colorado late last month, state officials confirmed, just weeks after hackers with suspected links to Iran had attempted to...

Water Government Facilities News
Alerts and advisories ·

Grafana security advisory (AV26-936)

Information Technology
Security Latest ·

After three months of daily anti-government protests—dubbed the Flamingo Revolution—the sudden mass suspension of Instagram accounts has led to fears of brigading against demonstrators.

Security content moderation
The Hacker News ·

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system...

Information Technology Financial Services
Schneier on Security ·

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping...

Uncategorized AI
Unit 42 ·

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The...

Information Technology Cloud Cybersecurity Research Threat Research
www.theregister.com - Articles ·

Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls

Information Technology Government Facilities security
www.theregister.com - Articles ·

Plugin4Shell attack affects all the major coding agents, researchers say

Information Technology security