IM
IronMonkey Threat Research
LIVE
|
Articles 25,535
|
CVEs 338,702
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,503 articles — Page 103 of 851
Unit 42 ·

Unit 42 uncovers a "double agent" flaw in Google Cloud's Vertex AI, demonstrating how overprivileged AI agents can compromise cloud environments. The post Double Agents: Exposing Security Blind...

Information Technology Malware Threat Research
BleepingComputer ·

AI agent risk isn't equal, it scales with access to systems and level of autonomy. Token Security explains how CISOs should categorize agents and prioritize what to secure first. [...]

Information Technology Security
Cisco Talos Blog ·

A summary of the top ransomware trends from the Talos 2025 Year in Review, with a focus on identity, attacker tactics, and practical defenses.

Critical Manufacturing 2025YiR Year In Review
eCrime.ch Ransomware News | RSS ·

Cota Co., Ltd., a TSE Prime Market–listed company based in Kyoto Prefecture and active in the consumer and cosmetics-related field, reported a significant disruption to its internal systems...

Commercial Facilities
BleepingComputer ·

Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver remote access trojans to Linux, Windows, and macOS systems. [...]

Information Technology Security
//SCADAS.EC ·

I have shared my impressions of the CRA before in writing[1] and was surprised to hear that a Draft Guide for the CRA was issued for comment[2]. Taking a deep breath, I spent several days reading,...

Energy Critical Manufacturing General Topic
Tenable Blog ·

Stop the noise and scale your cloud security. Our latest updates introduce custom policy automation via Explorer, AWS ABAC support for true least privilege, and research-backed protection against...

Information Technology
WeLiveSecurity ·

The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan

Information Technology Video
Wiz Blog | RSS feed ·

A compromised axios maintainer account led to malicious npm releases that propagated across environments. Learn how to assess impact, detect compromise, and secure your development workflows.

Information Technology
BleepingComputer ·

​Microsoft has resolved a known issue that rendered the classic Outlook email client unusable for users who enabled the Microsoft Teams Meeting Add-in. [...]

Information Technology Microsoft
Have I Been Pwned latest breaches ·

In March 2026, the NSFW AI companion platform Cuties AI suffered a data breach that was subsequently published to a public hacking forum. The incident exposed 144k unique email addresses along...

Blogs on Information Technology, Network & Cybersecurity | Seqrite ·

Operation DualScript – A Multi-Stage PowerShell Malware Campaign Targeting Cryptocurrency and Financial Activity Introduction During our investigation, we identified a multi-stage malware...

Financial Services Information Technology Technical banking trojan
BleepingComputer ·

U.S. prosecutors have charged a Maryland man with stealing more than $53 million after hacking the Uranium Finance crypto exchange twice and laundering the proceeds through a cryptocurrency mixer. [...]

Financial Services Information Technology Security CryptoCurrency
BleepingComputer ·

The Dutch Ministry of Finance took some of its systems offline, including the digital portal for treasury banking, while investigating a cyberattack detected two weeks ago. [...]

Financial Services Government Facilities Security
BleepingComputer ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Thursday. [...]

Information Technology Government Facilities Security
Wiz Blog | RSS feed ·

How TeamPCP are leveraging stolen secrets from the recent supply chain attacks to compromise cloud environments

Information Technology
The Hacker News ·

A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new findings from Check Point. "A single...

Information Technology
The Hacker News ·

A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred to as DeepLoad. "It likely uses AI-assisted obfuscation...

Information Technology
The Register - Security ·

Check Point says outbound controls blocked web traffic but overlooked DNS OpenAI talks up data security for its AI services, yet Check Point says that ChatGPT allowed data to leak through a DNS...

Information Technology
The Hacker News ·

Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped...

TA551 Gold Cabin Monster Libra Communications Information Technology
The Hacker News ·

What is really slowing Tier 1 down: the threat itself or the process around it? In many SOCs, the biggest delays do not come from the threat alone. They come from fragmented workflows, manual...

BleepingComputer ·

Healthcare IT firm CareCloud has disclosed a data breach incident that exposed sensitive data and caused a network disruption lasting approximately eight hours. [...]

Healthcare and Public Health Information Technology Security Healthcare
The Register - Security ·

Also, EU probes Snapchat, RedLine suspect extradited, AstraZeneca leak claim surfaces, and more infosec in brief The cybercrime crew linked to the Trivy supply-chain attack has struck again, this...

Information Technology Financial Services
The Hacker News ·

Secrets sprawl isn't slowing down: in 2025, it accelerated faster than most security teams anticipated. GitGuardian's State of Secrets Sprawl 2026 report analyzed billions of commits across public...

Information Technology Government Facilities
BleepingComputer ·

A newly identified malicious implant named RoadK1ll is enabling threat actors to quietly move from a compromised host to other systems on the network. [...]

Information Technology Communications Security
Alerts and advisories ·

Docker security advisory (AV26–301)

Information Technology
Alerts and advisories ·

[Control systems] CISA ICS security advisories (AV26-297)

Critical Manufacturing Energy
Alerts and advisories ·

Red Hat security advisory (AV26-298)

Information Technology
Alerts and advisories ·

Hitachi security advisory (AV26-299)

Information Technology Critical Manufacturing
Alerts and advisories ·

Roundcube security advisory (AV26-300)

Information Technology