See how poisoned OpenTelemetry telemetry manipulated an AI SRE agent into deploying a privileged Kubernetes container, escaping to an EKS host, and e…
AWS EKS forensics: data sources and investigation tooling 24/08/2026 CSIRT Investigating a compromise in Amazon EKS means piecing together evidence s…
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a s…
Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafte…
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated a…
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress t…
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violat…
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masqueradi…
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, …
A suspected Iran-linked cyberattack shut down a small UK power plant around the time that a series of digital intrusions disrupted American water uti…
GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting …
TCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a mem…
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users
Building a complete SharePoint exploit chain to get unauthenticated RCE via unsafe .NET type instantiation.
AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent …
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Se…
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power g…
Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not …
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. Th…
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and l…
Developer Matt Callaghan claims he caught Alibaba trying to track web users by playing sounds through browsers vulnerable to audio fingerprinting. Th…
A malware is being used to infect Android-based car systems, turning the devices into part of a botnet.
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in…
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server t…
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go ba…
In our previous analysis of the malicious RenPy campaigns, we identified a multi-stage loader deployed as part of the infection chain. Further threat…
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The po…
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimb…
Are you sick and tired of maintaining a password manager? Struggling with choosing the right one for you? Well, readers who live Down Under can get t…
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Expo…
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into a…
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the p…
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, M…
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web serve…
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while e…
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe be…