A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated...
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of...
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET,...
Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to...
We are standing at the end of an era we never thought to mourn: the...
The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing...
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified...
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind...
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and...
President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move...
GitHub is moving to strengthen software supply chain security by updating “actions/checkout” to block pwn...
Every weapon begins as an extension of the hand that holds it. The spear lengthened...
Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver...
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript)...
OpenAI on Monday said it’s releasing an improved version of its GPT‑5.5‑Cyber model to trusted...
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat...
Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform...
A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request,...
Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of...
Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the...
Post Content...
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a...
It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned...
Canada’s spy service got a judge’s permission to reach into infected servers, home routers, and...
A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy...
A new report from INTERPOL has revealed a “dramatic increase” in cybercrime in Asia and...
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin...
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside...
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection...
Interested in getting in contact with us about our services? Perhaps you would like to know more about how we can help you specifically? Tell us more, and we will happily listen to and provide you with further information and a consultation.